diff --git a/intakes/intakes.md b/intakes/intakes.md index 29ca3b5..9bfd744 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -31,6 +31,7 @@ description: > envelope needs a field this engine is not sending. created: '2026-08-29' updated: '2026-08-29' +state_hub_intake_id: "01a04d8f-b1c1-746a-8007-15221ebf0a48" ``` ## AUDIT-IN-0001 — Proposed: audit-core takes the approval evidence half (security layer model v0.3 §9.4) @@ -85,4 +86,5 @@ resolution: 'Assent. The split is right: approval-engine owns the operative stat Also raised: audit-core declared no layer, contrary to §11 — now declared Engine layer, explicitly not a decision point.' recorded_in: history/2026-08-28-approval-evidence-assent.md +state_hub_intake_id: "01a04d8f-be67-75ed-a221-d50f99dbb78e" ``` diff --git a/workplans/AUDIT-WP-0009-evidence-role-conformance.md b/workplans/AUDIT-WP-0009-evidence-role-conformance.md index 48f5736..c9971fc 100644 --- a/workplans/AUDIT-WP-0009-evidence-role-conformance.md +++ b/workplans/AUDIT-WP-0009-evidence-role-conformance.md @@ -11,6 +11,7 @@ created: "2026-08-29" updated: "2026-08-29" depends_on: - AUDIT-WP-0007 +state_hub_workstream_id: "46a96b03-bc08-53b5-9c93-4071adabf734" --- # AUDIT-WP-0009 — Evidence-role conformance under Security Layer Model v0.7 @@ -58,6 +59,7 @@ Fixed by the statute; not deferred, not ours: id: AUDIT-WP-0009-T01 status: todo priority: high +state_hub_task_id: "f545b0e4-8c99-5186-affd-ce9a41209ed7" ``` Make `tamper_evidence` conditional on live attestation state. Derive the flag rather than hard-coding it: the backend reports `True` only when a chain-head @@ -71,6 +73,7 @@ today are documented but unenforced. id: AUDIT-WP-0009-T02 status: todo priority: high +state_hub_task_id: "6de9945f-4dd1-57dd-898a-f59c35b1df6c" ``` Schedule chain-head attestation so the precondition T01 enforces is normally met. `attest-chain` exists and is operator-run; `deploy/` has no job. Add one, @@ -83,6 +86,7 @@ and proves nothing. Record the cadence in `docs/integrity.md`. id: AUDIT-WP-0009-T03 status: todo priority: high +state_hub_task_id: "acae6085-ada7-51b2-8dc0-4abac7f7e7b3" ``` Represent the §9.6 evidence kind per source. Add `evidence_kind` (`load-bearing` | `attributive`) to `SenderIdentity` and the sender registration @@ -96,6 +100,7 @@ for T04–T06. id: AUDIT-WP-0009-T04 status: todo priority: high +state_hub_task_id: "f36470af-4019-54b2-96d7-e049d867c7db" ``` Heartbeat ingestion and missing-heartbeat findings. The required form for low-volume load-bearing classes, and the only control covering adversarial @@ -109,6 +114,7 @@ itself go missing, which rate monitoring can never produce. id: AUDIT-WP-0009-T05 status: wait priority: medium +state_hub_task_id: "382575ca-1801-5a32-a93d-90a8b9c8adbf" ``` Accept and evaluate a declared emission cadence per source, and raise a finding when the stream falls below it. **Waiting on** the §17 emission-cadence @@ -121,6 +127,7 @@ alternatives. id: AUDIT-WP-0009-T06 status: todo priority: medium +state_hub_task_id: "0a8d6eed-75dd-5aaa-bf86-60be9dadca03" ``` Reconciliation surface: per-source, per-class event counts over a bounded window, readable by the source itself, so an emitter can compare audit-core's @@ -133,6 +140,7 @@ scoping, and no payloads in a counts response. id: AUDIT-WP-0009-T07 status: todo priority: medium +state_hub_task_id: "f572dfeb-0d1b-58d6-be83-405125189028" ``` Give stream-completeness findings a home. `/v1/dead-letters` and `/v1/secret-findings` exist; a cadence miss (T05) and a missing heartbeat (T04) @@ -145,6 +153,7 @@ than adding a new shape. id: AUDIT-WP-0009-T08 status: todo priority: medium +state_hub_task_id: "f7b513ee-af48-5c5a-a34e-3e9922d29b76" ``` Assert the §9.4 approval-validity prohibition with a negative test. It is currently honoured by absence, which is not the estate's idiom: §6.4 obligation @@ -156,6 +165,7 @@ is worth asserting in `tests/`. id: AUDIT-WP-0009-T09 status: todo priority: low +state_hub_task_id: "fd4a4ac3-e525-57c1-9179-e0fcd0226913" ``` Register `approval-engine` as a distinct source under §9.4 and `AUDIT-IN-0001`: sender registration, the four event classes (issuance, use, supersession, @@ -168,6 +178,7 @@ events arriving. Not blocking: `approval-engine` is not yet emitting. id: AUDIT-WP-0009-T10 status: todo priority: low +state_hub_task_id: "ac3464fd-3df9-51a1-b1f4-3bf3c60e4265" ``` Make the §5 conformance check total. `layer.yaml` declares `tooling_contacts: []`, true under §5 as written — audit-core is an Engine and