Record AUDIT-IN-0006: flex-auth sender intake, accepted with corrections
One sender per pin and wildcard tenants accepted; may_read corrected to false. The failure-path release in FLEX-DEC-2026-018 is ruled a completeness trade in substance, to be declared by a narrow separate field, with the section 9.6 question referred to gate-house. Registration deferred until the flex-auth outbox exists. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 151986@bnt-lap001 Assistant-Session: ccd02b6b-80ae-48e5-8cad-9c8f74d21a67
This commit is contained in:
parent
21e8ce9b72
commit
e227196f32
1 changed files with 57 additions and 0 deletions
|
|
@ -1,5 +1,62 @@
|
||||||
# Intake records
|
# Intake records
|
||||||
|
|
||||||
|
## AUDIT-IN-0006 — Register flex-auth's six decision-record pins as load-bearing senders
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
id: AUDIT-IN-0006
|
||||||
|
kind: intake
|
||||||
|
title: 'Register flex-auth decision-record senders, one per pin, and rule on the
|
||||||
|
failure-path release exception'
|
||||||
|
status: accepted
|
||||||
|
origin: cross-repo
|
||||||
|
origin_ref: FLEX-WP-0031-T02 / FLEX-DEC-2026-018 / AUDIT-IN-0005
|
||||||
|
priority: high
|
||||||
|
owner: audit-core
|
||||||
|
requested_by: flex-auth
|
||||||
|
description: >
|
||||||
|
flex-auth asks for the registration surface audit-core offered in
|
||||||
|
AUDIT-IN-0005: six senders, one per Helm pin (ops-warden, tenant-engine,
|
||||||
|
user-engine, secrets-engine, informed-decision-t03,
|
||||||
|
informed-decision-sitting), source flex-auth.<pin> exact, load-bearing,
|
||||||
|
tenants ["*"], secret_policy redact, per-class heartbeats for deny, redact,
|
||||||
|
not_applicable and audit_only at 86400s, allow by expected rate plus
|
||||||
|
reconciliation. It asks for a ruling on FLEX-DEC-2026-018, which releases
|
||||||
|
deny/redact/not_applicable without a durable record when the outbox commit
|
||||||
|
fails and counts them as released_uncommitted, and for the token lane.
|
||||||
|
created: '2026-09-23'
|
||||||
|
updated: '2026-09-24'
|
||||||
|
outcome: accepted-with-corrections-registration-deferred
|
||||||
|
resolution: '(1) One sender per pin: accepted, since each pin can reconcile only
|
||||||
|
what it committed. Correction: may_read false, not true. A writer counts its
|
||||||
|
own sources on /v1/reconciliation without may_read (AUDIT-WP-0009-T06);
|
||||||
|
may_read true with tenants ["*"] would give every pin a read of the whole
|
||||||
|
archive across tenants. (2) tenants ["*"]: accepted on the stated
|
||||||
|
justification; a deny for a tenant not yet created must not dead-letter.
|
||||||
|
(3) Classes and per-class heartbeats: accepted. allow should also carry an
|
||||||
|
emission_cadence declaration (info-tech-canon wire schema 0.1,
|
||||||
|
expected-rate) on each registration so its rate is evaluated (T05), not
|
||||||
|
only declared. (4) The failure-path release is a completeness trade in
|
||||||
|
substance: a load-bearing decision leaves without a committed record, which
|
||||||
|
section 9.6 atomicity forbids. audit-core will not prefer withholding, since
|
||||||
|
telling a decision point how to release decisions routes an authorization
|
||||||
|
choice through the audit fabric (SCOPE). completeness_trade keeps its
|
||||||
|
attributive meaning; a narrow, separately named declaration for
|
||||||
|
load-bearing sources will be added with the registration work, naming the
|
||||||
|
classes, the failure condition and released_uncommitted as its detection
|
||||||
|
surface. Whether section 9.6 permits it at all is the statute''s question
|
||||||
|
and is referred to gate-house; the registration claims no atomicity for
|
||||||
|
those classes until gate-house rules. (5) Envelope: correct as proposed.
|
||||||
|
Heartbeats also need non-empty subject, correlation_id and data. Redaction
|
||||||
|
matches key names containing password/secret/token/credential/private_key;
|
||||||
|
the current decision_envelope schema has none, but a future one would be
|
||||||
|
stored redacted. (6) Token lane: the audit-core attended sender mint into
|
||||||
|
platform/data/workloads/audit-core/senders via railiance-platform
|
||||||
|
openbao-attended-exec.py, as for tenant-engine (AUDIT-WP-0010-T02).
|
||||||
|
Registration entries are deferred until the flex-auth outbox exists
|
||||||
|
(FLEX-WP-0031-T03), at flex-auth''s own request.'
|
||||||
|
recorded_in: intakes/intakes.md
|
||||||
|
```
|
||||||
|
|
||||||
## AUDIT-IN-0005 — Which repository is the §4 source of evidence for the decision record
|
## AUDIT-IN-0005 — Which repository is the §4 source of evidence for the decision record
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue