From d623f239d35ba04221686fc8631af83a41e01975 Mon Sep 17 00:00:00 2001 From: repo-manager Date: Fri, 28 Aug 2026 22:35:09 +0200 Subject: [PATCH] repo.work.create_intake AUDIT-IN-0001 correlation_id: 4b03b802-e66f-4e69-9593-ed9abfc1d7c8 reason: Propose approval evidence ownership under layer model v0.3 source: repo-manager Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- intakes/intakes.md | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) create mode 100644 intakes/intakes.md diff --git a/intakes/intakes.md b/intakes/intakes.md new file mode 100644 index 0000000..7db4949 --- /dev/null +++ b/intakes/intakes.md @@ -0,0 +1,34 @@ +# Intake records + +## AUDIT-IN-0001 — Proposed: audit-core takes the approval evidence half (security layer model v0.3 §9.4) + +```yaml +id: AUDIT-IN-0001 +kind: intake +title: 'Proposed: audit-core takes the approval evidence half (security layer model + v0.3 §9.4)' +status: open +origin: cross-repo +origin_ref: net-kingdom security-layer-model_v0.3 §9.4 +priority: medium +owner: audit-core +requested_by: gate-house +description: 'gate-house proposes that audit-core own the tamper-evident record of + approvals: issuance, use, supersession, and revocation emitted as audit events. + Rationale: principle 6 (signed or hash-chained manifests to prove a record set was + not changed, omitted, or truncated) is exactly what authenticated approval entries + need forensically, and audit-core independence is the property Canon core rule 13 + wants — audit evidence protected from the actor being audited. What is NOT proposed: + the operative approval state. approval-engine owns the durable object, atomic supersession, + single consumption, and revocation, because those need mutable in-path current-state + semantics and audit-core operational custody is append-only Postgres by design; + coupling decision-time approval reads to the audit fabric would also make an audit + outage an authorization outage. Note audit-core INTENT lists policy decision making + as out of scope — this proposal respects that: approval evidence is a record of + what happened, never the authoritative answer to whether an approval is still valid. + Requested: assent, revision, or rejection. If audit-core would rather not carry + approval events as a distinct source, say so and gate-house will record the evidence + half as unowned rather than assume it.' +created: '2026-08-28T20:35:09.148892Z' +updated: '2026-08-28T20:35:09.148892Z' +```