repo.work.create_intake AUDIT-IN-0001
correlation_id: 4b03b802-e66f-4e69-9593-ed9abfc1d7c8 reason: Propose approval evidence ownership under layer model v0.3 source: repo-manager Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
parent
943b8856d2
commit
d623f239d3
1 changed files with 34 additions and 0 deletions
34
intakes/intakes.md
Normal file
34
intakes/intakes.md
Normal file
|
|
@ -0,0 +1,34 @@
|
||||||
|
# Intake records
|
||||||
|
|
||||||
|
## AUDIT-IN-0001 — Proposed: audit-core takes the approval evidence half (security layer model v0.3 §9.4)
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
id: AUDIT-IN-0001
|
||||||
|
kind: intake
|
||||||
|
title: 'Proposed: audit-core takes the approval evidence half (security layer model
|
||||||
|
v0.3 §9.4)'
|
||||||
|
status: open
|
||||||
|
origin: cross-repo
|
||||||
|
origin_ref: net-kingdom security-layer-model_v0.3 §9.4
|
||||||
|
priority: medium
|
||||||
|
owner: audit-core
|
||||||
|
requested_by: gate-house
|
||||||
|
description: 'gate-house proposes that audit-core own the tamper-evident record of
|
||||||
|
approvals: issuance, use, supersession, and revocation emitted as audit events.
|
||||||
|
Rationale: principle 6 (signed or hash-chained manifests to prove a record set was
|
||||||
|
not changed, omitted, or truncated) is exactly what authenticated approval entries
|
||||||
|
need forensically, and audit-core independence is the property Canon core rule 13
|
||||||
|
wants — audit evidence protected from the actor being audited. What is NOT proposed:
|
||||||
|
the operative approval state. approval-engine owns the durable object, atomic supersession,
|
||||||
|
single consumption, and revocation, because those need mutable in-path current-state
|
||||||
|
semantics and audit-core operational custody is append-only Postgres by design;
|
||||||
|
coupling decision-time approval reads to the audit fabric would also make an audit
|
||||||
|
outage an authorization outage. Note audit-core INTENT lists policy decision making
|
||||||
|
as out of scope — this proposal respects that: approval evidence is a record of
|
||||||
|
what happened, never the authoritative answer to whether an approval is still valid.
|
||||||
|
Requested: assent, revision, or rejection. If audit-core would rather not carry
|
||||||
|
approval events as a distinct source, say so and gate-house will record the evidence
|
||||||
|
half as unowned rather than assume it.'
|
||||||
|
created: '2026-08-28T20:35:09.148892Z'
|
||||||
|
updated: '2026-08-28T20:35:09.148892Z'
|
||||||
|
```
|
||||||
Loading…
Add table
Add a link
Reference in a new issue