repo.work.create_intake AUDIT-IN-0001
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

correlation_id: 4b03b802-e66f-4e69-9593-ed9abfc1d7c8
reason: Propose approval evidence ownership under layer model v0.3
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
repo-manager 2026-08-28 22:35:09 +02:00
parent 943b8856d2
commit d623f239d3

34
intakes/intakes.md Normal file
View file

@ -0,0 +1,34 @@
# Intake records
## AUDIT-IN-0001 — Proposed: audit-core takes the approval evidence half (security layer model v0.3 §9.4)
```yaml
id: AUDIT-IN-0001
kind: intake
title: 'Proposed: audit-core takes the approval evidence half (security layer model
v0.3 §9.4)'
status: open
origin: cross-repo
origin_ref: net-kingdom security-layer-model_v0.3 §9.4
priority: medium
owner: audit-core
requested_by: gate-house
description: 'gate-house proposes that audit-core own the tamper-evident record of
approvals: issuance, use, supersession, and revocation emitted as audit events.
Rationale: principle 6 (signed or hash-chained manifests to prove a record set was
not changed, omitted, or truncated) is exactly what authenticated approval entries
need forensically, and audit-core independence is the property Canon core rule 13
wants — audit evidence protected from the actor being audited. What is NOT proposed:
the operative approval state. approval-engine owns the durable object, atomic supersession,
single consumption, and revocation, because those need mutable in-path current-state
semantics and audit-core operational custody is append-only Postgres by design;
coupling decision-time approval reads to the audit fabric would also make an audit
outage an authorization outage. Note audit-core INTENT lists policy decision making
as out of scope — this proposal respects that: approval evidence is a record of
what happened, never the authoritative answer to whether an approval is still valid.
Requested: assent, revision, or rejection. If audit-core would rather not carry
approval events as a distinct source, say so and gate-house will record the evidence
half as unowned rather than assume it.'
created: '2026-08-28T20:35:09.148892Z'
updated: '2026-08-28T20:35:09.148892Z'
```