Declare the tenancy posture vector (AUDIT-WP-0008-T01).
Written against draft-7, which landed after the task was drafted and moved the target. Decision 5.4 fixes the location at tenancy.yaml in the repo root rather than docs/, and fixes the schema: current, target, reviewed, gap, placement_exceptions, service_class, per-path detail, provider block. Declares I1 A2 E1 P1 R1. E is quoted at 1 although T04 put the E2 mechanism on both paths, because §13.2 states a passing CI run is not E2 evidence -- the artifact is adversarial, compares separate tenant contexts and carries a review date. Our cross-tenant tests are mechanical, so under §13.1 the level is not claimable until T05. The mechanism is recorded in paths.E and the reason in gap.E. Claiming E2 off unit tests would be the overclaim §6 prohibits, and refusing that reasoning is what found the read-path defect. R stays at 1: R2 needs backupRetentionDays in rapp-postgres's consumer file, requested in T02 and not ours to declare. Two additions draft-7 forced. A credentials gap under Decision 9.2 -- our own finding, adopted as a rule, and it binds us: ingest credentials are static long-lived bearer tokens, declared as a stated gap rather than a silent exclusion. And a provides block under Decision 5.5, declaring what a sender can reach through this service: E2 now, E3 pending ADR-0003, E4 and R4 unreachable. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
e1402b3033
commit
a2d84bdd9b
5 changed files with 205 additions and 15 deletions
|
|
@ -161,6 +161,28 @@ avoid.
|
|||
|
||||
Sent under §20.2 — the framework is validated by whether it can describe us.
|
||||
|
||||
> **Outcome, 2026-08-17: all five were adopted in draft-7**, alongside reviews
|
||||
> from `railiance-platform` and `flex-auth`. Finding 1 became **Decision 5.2**
|
||||
> (declare per path, quote the minimum), finding 2 became **13.1a** (the floor
|
||||
> needs a reason, not an artifact), finding 3 became **Decision 9.2**
|
||||
> (consumer-facing credentials are named in), finding 4 became **Decision 4.5.3**
|
||||
> (key destruction is not sufficient alone; the confirmation-oracle defect is
|
||||
> recorded as general, with audit-core exempted from R4), and the §5 worked
|
||||
> example now reads `I1 A2 E1 P1 R1` self-reported. Draft-7 also added
|
||||
> **Decision 5.4**, which relocates the vector to `tenancy.yaml` in the repo
|
||||
> root — see T01.
|
||||
>
|
||||
> Two of these now bind us rather than only the framework: 9.2 makes our static
|
||||
> ingest tokens a declarable gap, and 5.5 requires a provider block. Both are in
|
||||
> `tenancy.yaml`. T06 is therefore reduced to confirming receipt and correcting
|
||||
> the one line draft-7 still has stale about us (E, once T05 lands).
|
||||
>
|
||||
> Draft-7's own status section still carries "Every correction so far was found
|
||||
> by research or by relocation, not by review" and "Reviewed by nobody yet",
|
||||
> three paragraphs below a list of eleven review-driven changes. Stale lines,
|
||||
> worth flagging in T06 — a document about not overclaiming should not
|
||||
> under-report its own review history.
|
||||
|
||||
1. **The E ladder cannot express asymmetric enforcement.** Our write path is E2
|
||||
and our read path is E1. §4.3 assumes one level per service. This will recur
|
||||
estate-wide, since most services enforce harder on write than on read, and
|
||||
|
|
@ -246,23 +268,44 @@ both would be concealment, and §6 would be right to call it that.
|
|||
|
||||
```task
|
||||
id: AUDIT-WP-0008-T01
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "65f3109a-fa98-459a-9e59-d7ac211bd2bc"
|
||||
```
|
||||
Publish the posture vector in the repo per Decision 5.1 — `docs/tenancy-posture.yaml`.
|
||||
**Runs after T04.** Declares `current: I1 A2 E2 P1 R2`, `target: I1 A2 E3 P1 R2`,
|
||||
reviewed date, and a gap note per axis. Include the per-path E breakdown
|
||||
(`write: 2, read: 2`) alongside the vector, per finding 1. The E gap names RLS
|
||||
with its 2027-03-31 date; the R gap names `data.archive` with its 2026-12-31
|
||||
review. If T04 has not landed when this is published, declare `E1` and say why —
|
||||
the vector describes what is true on the day it is written, never what is
|
||||
expected. Cross-link from `SCOPE.md` and `docs/interface-card.yaml`.
|
||||
Publish the posture vector. **Rewritten against draft-7**, which landed after
|
||||
this task was written and moved the target: Decision 5.4 fixes the location at
|
||||
**`tenancy.yaml` in the repo root**, not `docs/tenancy-posture.yaml`, and fixes
|
||||
the schema — `current`, `target`, `reviewed`, `gap`, `placement_exceptions`,
|
||||
`service_class`, per-path detail (5.2), and a provider block (5.5). Delivered at
|
||||
that path and in that shape. Cross-linked from `SCOPE.md` and
|
||||
`docs/interface-card.yaml`.
|
||||
|
||||
Fold in the R1 → R2 move: explicit `backupRetentionDays: 30` requested of
|
||||
`rapp-postgres` for `consumers/audit-core.yaml` (that file is theirs, so this is
|
||||
a request, not an edit), and the erasure horizon rendered in the operator
|
||||
surface alongside `recoverable_days`.
|
||||
**Declared `I1 A2 E1 P1 R1`, and E is quoted at 1 on purpose.** T04 put the E2
|
||||
mechanism on both paths, but §13.2 says a passing CI run is not E2 evidence:
|
||||
the E2 artifact is adversarial, compares separate tenant contexts, and carries a
|
||||
review date rather than a green build. Our cross-tenant tests are mechanical.
|
||||
Under §13.1 the level is therefore not claimable until T05 produces the artifact,
|
||||
so the vector declares 1 with the mechanism recorded in `paths.E` and the reason
|
||||
in `gap.E`. Claiming E2 off unit tests would be the overclaim §6 prohibits —
|
||||
and refusing exactly that kind of reasoning is what found the read-path defect
|
||||
in the first place.
|
||||
|
||||
R stays at 1: R2 needs `backupRetentionDays: 30` in
|
||||
`rapp-postgres/consumers/audit-core.yaml`, requested in T02. That file is
|
||||
theirs, so R2 is not ours to declare unilaterally. The erasure horizon is
|
||||
already published on `/readyz` as `recoverable_days`.
|
||||
|
||||
Two additions draft-7 forced that the original task did not anticipate:
|
||||
|
||||
- **A `credentials` gap under Decision 9.2.** Our own finding was adopted as a
|
||||
rule, and it binds us: ingest credentials are static long-lived bearer tokens.
|
||||
Declared as a stated gap with no dated remedy rather than a silent exclusion.
|
||||
Asking for the rule and then exempting ourselves from it was not available.
|
||||
- **A `provides` block under Decision 5.5.** audit-core provisions
|
||||
`operations.audit`, so it declares what it makes *reachable* for a sender's
|
||||
trail — E2 now, E3 pending ADR-0003, **E4 and R4 unreachable**. A sender
|
||||
needing a structural cross-tenant guarantee cannot get it here and should be
|
||||
told so rather than sold E2 in E4's language (§11.4).
|
||||
|
||||
```task
|
||||
id: AUDIT-WP-0008-T02
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue