diff --git a/workplans/AUDIT-WP-0009-evidence-role-conformance.md b/workplans/AUDIT-WP-0009-evidence-role-conformance.md index f0e2208..6fde6a0 100644 --- a/workplans/AUDIT-WP-0009-evidence-role-conformance.md +++ b/workplans/AUDIT-WP-0009-evidence-role-conformance.md @@ -8,7 +8,7 @@ status: active owner: claude topic_slug: railiance created: "2026-08-29" -updated: "2026-08-29" +updated: "2026-09-11" depends_on: - AUDIT-WP-0007 state_hub_workstream_id: "46a96b03-bc08-53b5-9c93-4071adabf734" @@ -442,6 +442,25 @@ application, and live ingestion evidence. No secret was created and no production manifest applied. +### Factory sender deployment precondition — 2026-09-11 + +Native metadata still reports 1/1 Ready on image `c2fe39a0185b...`. The exact +image and a synthetic SenderRegistry probe in the native pod confirm that it +has no `evidence_kind` support. Current source supports the contract. The +source-complete T03 implementation has not reached this deployment; readiness +alone cannot admit a load-bearing sender. T09/T11 retain the compatible image +release, current scope/peer manifests and actual ingestion/retrieval acceptance. + +Platform RPF-WP-0035-T08 now prepares the separate sender custody records +CCR-2026-0021 (approval-engine) and CCR-2026-0022 (informed-decision), with +exact-path ESO projections and CAS-preserving first provision/resume. Its +receiver check refuses the current image before credential access. Seventeen +new tests, including eleven local OpenBao cases, and 53 existing credential-change +tests pass. Named owner reviews, compatible receiver release and target namespace +readiness remain prerequisites. No native sender credential or deployment changed. +See railiance-platform/docs/credential-lane-designs/factory-audit-senders-review.md +and its dated preparation evidence. Existing sender/source scopes are preserved. + ## Acceptance - No custody claim is returned unconditionally where `docs/integrity.md`