diff --git a/docs/evidence/2026-09-15-tenant-engine-sender-mint.json b/docs/evidence/2026-09-15-tenant-engine-sender-mint.json new file mode 100644 index 0000000..e6256f5 --- /dev/null +++ b/docs/evidence/2026-09-15-tenant-engine-sender-mint.json @@ -0,0 +1,18 @@ +{ + "step": "done", + "observed_at": "2026-09-15T20:03:55+00:00", + "sender": "tenant-engine", + "registry": "platform/workloads/audit-core/senders", + "credential_values_emitted": false, + "senders": [ + "user-engine", + "operator", + "approval-engine", + "informed-decision", + "tenant-engine" + ], + "has_tenant_engine_tokens": true, + "receiver_ready": true, + "minted": true, + "registry_version": 9 +} diff --git a/workplans/AUDIT-WP-0010-tenant-engine-sender-admission.md b/workplans/AUDIT-WP-0010-tenant-engine-sender-admission.md index 461991e..eea985d 100644 --- a/workplans/AUDIT-WP-0010-tenant-engine-sender-admission.md +++ b/workplans/AUDIT-WP-0010-tenant-engine-sender-admission.md @@ -9,7 +9,7 @@ flavor: implementation owner: claude topic_slug: railiance created: "2026-08-29" -updated: "2026-08-29" +updated: "2026-09-15" depends_on: - AUDIT-WP-0005 state_hub_workstream_id: "54655357-74da-5f7f-8fa6-647d4c969f21" @@ -72,10 +72,20 @@ value in Git — projected only, per the established lane. ```task id: AUDIT-WP-0010-T02 -status: todo +status: done priority: high state_hub_task_id: "13855bd9-4ff4-5e8c-ab98-d5ff45103d22" ``` +Done 2026-09-15. Attended `platform-admin` mint via the operator tunnel +`http://127.0.0.1:18200` (public `bao.coulomb.social` retracted). CAS write +to `platform/workloads/audit-core/senders` version 9 added `tenant-engine` +with one token; ExternalSecret `SecretSynced`; receiver recreated and 1/1 +Ready. Field presence verified without disclosure: senders +`user-engine`, `operator`, `approval-engine`, `informed-decision`, +`tenant-engine` (has_tokens true). No value in Git, State Hub, or chat. +Receipt: `docs/evidence/2026-09-15-tenant-engine-sender-mint.json`. +Producer mount `TENANT_ENGINE_AUDIT_CORE_TOKEN_FILE` remains tenant-engine's +to project for T05 live 202. Provide the token lane. Coordinate the projected credential with the owning credential operator through the `ops-warden` route, matching the custody pattern already used for `user-engine`. Verify field presence without disclosure. Do not