Answer flex-auth B3: the emitter is the section 4 source, not the archive
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

AUDIT-IN-0005. flex-auth produces the decision record, declares no §11
emission guarantee, and declined to take the reading that moves the
obligation to audit-core. audit-core declines it too, on its own authority:
class, cadence and detection surface are properties of emitting; audit-core
cannot detect non-production; the obligations already sit on each sender
registration; archive-as-source would make §11's check vacuous; and no
access-engine sender is registered at all.

Binds audit-core, does not rule §11 — gate-house still owns that, so
flex-auth's G2 stays open.

Reflexive half: audit-core's own chain-head attestation emission is now
declared in layer.yaml rather than only in docs/integrity.md prose, and
asserted against the CronJob and the contract by test.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
codex 2026-09-21 02:09:47 +02:00
parent 5dc70afe64
commit 40fc7d694c
5 changed files with 338 additions and 1 deletions

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: claude
topic_slug: railiance
created: "2026-08-29"
updated: "2026-09-15"
updated: "2026-09-21"
depends_on:
- AUDIT-WP-0007
state_hub_workstream_id: "46a96b03-bc08-53b5-9c93-4071adabf734"
@ -672,3 +672,38 @@ Service/domain-transaction/human and factory runtime/spend admission remain
separate; factory attempts and paid model calls remain zero.
Receipt: [native readback](../docs/evidence/2026-09-11-factory-native-readback.json).
## Answer flex-auth's B3: which repository is the §4 source of evidence
```task
id: AUDIT-WP-0009-T13
status: done
priority: high
```
`AUDIT-IN-0005`. flex-auth (access-engine) produces the decision record,
declares no §11 emission guarantee, and raised B3 / G2 rather than take the
reading that puts the obligation on audit-core. Answered 2026-09-21:
**audit-core is not the source; the emitter is.** Class, cadence and detection
surface are properties of emitting, audit-core cannot detect non-production
(`AUDIT-IN-0003`, `GH-DEC-2026-014` limit 3), the obligations already sit on
each sender registration, archive-as-source would make §11's check vacuous, and
no `access-engine` sender is registered — the record never reaches this custody.
Ruling: `docs/section-4-source-of-evidence.md`. It binds audit-core and does not
rule §11; gate-house still owns that, so **G2 stays open** on flex-auth's list.
Reflexive half, taken rather than avoided: audit-core's own chain-head
attestation had its class, cadence and detection surface stated only in
`docs/integrity.md` prose. Now declared in `layer.yaml` under
`emission_guarantee` — load-bearing, rare, rate monitoring forbidden, daily
`17 3 * * *`, 168h freshness window degrading `tamper_evidence` to `False` with
the reason recorded — and asserted against the CronJob and the contract by
`tests/test_layer_conformance.py`, so the declaration cannot drift from what is
deployed.
Not done here: the INTENT.md `Engine` versus layer.yaml `engine` split
(flex-auth's corrected B1). Precedence and case-sensitivity are gate-house's to
rule, and aligning on a guess would be authoring a declaration §11 says only
this repository may author.