Record AUDIT-IN-0006: flex-auth sender intake, accepted with corrections
One sender per pin and wildcard tenants accepted; may_read corrected to false. The failure-path release in FLEX-DEC-2026-018 is ruled a completeness trade in substance, to be declared by a narrow separate field, with the section 9.6 question referred to gate-house. Registration deferred until the flex-auth outbox exists. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 151986@bnt-lap001 Assistant-Session: ccd02b6b-80ae-48e5-8cad-9c8f74d21a67
This commit is contained in:
parent
21e8ce9b72
commit
e227196f32
1 changed files with 57 additions and 0 deletions
|
|
@ -1,5 +1,62 @@
|
|||
# Intake records
|
||||
|
||||
## AUDIT-IN-0006 — Register flex-auth's six decision-record pins as load-bearing senders
|
||||
|
||||
```yaml
|
||||
id: AUDIT-IN-0006
|
||||
kind: intake
|
||||
title: 'Register flex-auth decision-record senders, one per pin, and rule on the
|
||||
failure-path release exception'
|
||||
status: accepted
|
||||
origin: cross-repo
|
||||
origin_ref: FLEX-WP-0031-T02 / FLEX-DEC-2026-018 / AUDIT-IN-0005
|
||||
priority: high
|
||||
owner: audit-core
|
||||
requested_by: flex-auth
|
||||
description: >
|
||||
flex-auth asks for the registration surface audit-core offered in
|
||||
AUDIT-IN-0005: six senders, one per Helm pin (ops-warden, tenant-engine,
|
||||
user-engine, secrets-engine, informed-decision-t03,
|
||||
informed-decision-sitting), source flex-auth.<pin> exact, load-bearing,
|
||||
tenants ["*"], secret_policy redact, per-class heartbeats for deny, redact,
|
||||
not_applicable and audit_only at 86400s, allow by expected rate plus
|
||||
reconciliation. It asks for a ruling on FLEX-DEC-2026-018, which releases
|
||||
deny/redact/not_applicable without a durable record when the outbox commit
|
||||
fails and counts them as released_uncommitted, and for the token lane.
|
||||
created: '2026-09-23'
|
||||
updated: '2026-09-24'
|
||||
outcome: accepted-with-corrections-registration-deferred
|
||||
resolution: '(1) One sender per pin: accepted, since each pin can reconcile only
|
||||
what it committed. Correction: may_read false, not true. A writer counts its
|
||||
own sources on /v1/reconciliation without may_read (AUDIT-WP-0009-T06);
|
||||
may_read true with tenants ["*"] would give every pin a read of the whole
|
||||
archive across tenants. (2) tenants ["*"]: accepted on the stated
|
||||
justification; a deny for a tenant not yet created must not dead-letter.
|
||||
(3) Classes and per-class heartbeats: accepted. allow should also carry an
|
||||
emission_cadence declaration (info-tech-canon wire schema 0.1,
|
||||
expected-rate) on each registration so its rate is evaluated (T05), not
|
||||
only declared. (4) The failure-path release is a completeness trade in
|
||||
substance: a load-bearing decision leaves without a committed record, which
|
||||
section 9.6 atomicity forbids. audit-core will not prefer withholding, since
|
||||
telling a decision point how to release decisions routes an authorization
|
||||
choice through the audit fabric (SCOPE). completeness_trade keeps its
|
||||
attributive meaning; a narrow, separately named declaration for
|
||||
load-bearing sources will be added with the registration work, naming the
|
||||
classes, the failure condition and released_uncommitted as its detection
|
||||
surface. Whether section 9.6 permits it at all is the statute''s question
|
||||
and is referred to gate-house; the registration claims no atomicity for
|
||||
those classes until gate-house rules. (5) Envelope: correct as proposed.
|
||||
Heartbeats also need non-empty subject, correlation_id and data. Redaction
|
||||
matches key names containing password/secret/token/credential/private_key;
|
||||
the current decision_envelope schema has none, but a future one would be
|
||||
stored redacted. (6) Token lane: the audit-core attended sender mint into
|
||||
platform/data/workloads/audit-core/senders via railiance-platform
|
||||
openbao-attended-exec.py, as for tenant-engine (AUDIT-WP-0010-T02).
|
||||
Registration entries are deferred until the flex-auth outbox exists
|
||||
(FLEX-WP-0031-T03), at flex-auth''s own request.'
|
||||
recorded_in: intakes/intakes.md
|
||||
```
|
||||
|
||||
## AUDIT-IN-0005 — Which repository is the §4 source of evidence for the decision record
|
||||
|
||||
```yaml
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue