docs(AUDIT-WP-0008): advance E2 evidence coordination
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a025c2-407a-7a32-b40a-f37a52f03f62
This commit is contained in:
tegwick 2026-08-21 23:59:09 +02:00
parent d0790524e2
commit 91d6462efb

View file

@ -8,7 +8,7 @@ status: active
owner: claude owner: claude
topic_slug: railiance topic_slug: railiance
created: "2026-08-17" created: "2026-08-17"
updated: "2026-08-17" updated: "2026-08-21"
depends_on: depends_on:
- AUDIT-WP-0007 - AUDIT-WP-0007
state_hub_workstream_id: "84c01552-4c65-45fd-bf6c-7daab0ecc9b6" state_hub_workstream_id: "84c01552-4c65-45fd-bf6c-7daab0ecc9b6"
@ -374,7 +374,7 @@ and the operator runbook. Raises E to 2 on both paths; update T01's declaration.
```task ```task
id: AUDIT-WP-0008-T05 id: AUDIT-WP-0008-T05
status: wait status: progress
priority: medium priority: medium
state_hub_task_id: "30b56b30-e7eb-4873-aa7c-f4a3bf2fcb24" state_hub_task_id: "30b56b30-e7eb-4873-aa7c-f4a3bf2fcb24"
``` ```
@ -384,6 +384,21 @@ identity bound to tenant A demonstrably cannot read tenant B. Coordinate with
to write and theirs to review. Record the review cadence as the exposure window to write and theirs to review. Record the review cadence as the exposure window
per §19.3. per §19.3.
Progress 2026-08-21: Whitehat's operating rules, attacker model, calibrated
differential harness, and `audit-core` probe pack now exist at commit `beab2a0`.
Audit-core reviewed the three-route pack and sent target-owner readiness packet
`6f2ae598-06bd-4089-a5fd-9de31688a733`. It fixes the synthetic-only scope,
excludes operator routes, caps the run at one concurrent request and ten per
minute, and requires two temporary read-enabled identities each scoped to one
fixture tenant. The production `user-engine` identity remains unchanged and is
not a test credential.
This is progress, not evidence and not live authorization. Whitehat still owes
a complete dated engagement and executable identity adapter; the operator must
approve that target/window, after which audit-core supplies the formal
post-approval owner acknowledgement. T05 becomes `done` only when the sanitized
target report exists and has been routed to `risk-nexus`.
```task ```task
id: AUDIT-WP-0008-T06 id: AUDIT-WP-0008-T06
status: done status: done