diff --git a/intakes/intakes.md b/intakes/intakes.md index dbc0bf0..f31be7e 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -1,5 +1,62 @@ # Intake records +## AUDIT-IN-0006 — Register flex-auth's six decision-record pins as load-bearing senders + +```yaml +id: AUDIT-IN-0006 +kind: intake +title: 'Register flex-auth decision-record senders, one per pin, and rule on the + failure-path release exception' +status: accepted +origin: cross-repo +origin_ref: FLEX-WP-0031-T02 / FLEX-DEC-2026-018 / AUDIT-IN-0005 +priority: high +owner: audit-core +requested_by: flex-auth +description: > + flex-auth asks for the registration surface audit-core offered in + AUDIT-IN-0005: six senders, one per Helm pin (ops-warden, tenant-engine, + user-engine, secrets-engine, informed-decision-t03, + informed-decision-sitting), source flex-auth. exact, load-bearing, + tenants ["*"], secret_policy redact, per-class heartbeats for deny, redact, + not_applicable and audit_only at 86400s, allow by expected rate plus + reconciliation. It asks for a ruling on FLEX-DEC-2026-018, which releases + deny/redact/not_applicable without a durable record when the outbox commit + fails and counts them as released_uncommitted, and for the token lane. +created: '2026-09-23' +updated: '2026-09-24' +outcome: accepted-with-corrections-registration-deferred +resolution: '(1) One sender per pin: accepted, since each pin can reconcile only + what it committed. Correction: may_read false, not true. A writer counts its + own sources on /v1/reconciliation without may_read (AUDIT-WP-0009-T06); + may_read true with tenants ["*"] would give every pin a read of the whole + archive across tenants. (2) tenants ["*"]: accepted on the stated + justification; a deny for a tenant not yet created must not dead-letter. + (3) Classes and per-class heartbeats: accepted. allow should also carry an + emission_cadence declaration (info-tech-canon wire schema 0.1, + expected-rate) on each registration so its rate is evaluated (T05), not + only declared. (4) The failure-path release is a completeness trade in + substance: a load-bearing decision leaves without a committed record, which + section 9.6 atomicity forbids. audit-core will not prefer withholding, since + telling a decision point how to release decisions routes an authorization + choice through the audit fabric (SCOPE). completeness_trade keeps its + attributive meaning; a narrow, separately named declaration for + load-bearing sources will be added with the registration work, naming the + classes, the failure condition and released_uncommitted as its detection + surface. Whether section 9.6 permits it at all is the statute''s question + and is referred to gate-house; the registration claims no atomicity for + those classes until gate-house rules. (5) Envelope: correct as proposed. + Heartbeats also need non-empty subject, correlation_id and data. Redaction + matches key names containing password/secret/token/credential/private_key; + the current decision_envelope schema has none, but a future one would be + stored redacted. (6) Token lane: the audit-core attended sender mint into + platform/data/workloads/audit-core/senders via railiance-platform + openbao-attended-exec.py, as for tenant-engine (AUDIT-WP-0010-T02). + Registration entries are deferred until the flex-auth outbox exists + (FLEX-WP-0031-T03), at flex-auth''s own request.' +recorded_in: intakes/intakes.md +``` + ## AUDIT-IN-0005 — Which repository is the §4 source of evidence for the decision record ```yaml