Founder disposition (GOVERN @ estate): approve A11 r2 and A12 r3.
Section 11 review returned with two findings: the load-bearing branch
carries no completeness non-claim, and A10's dash marks both 'not a
source' and 'unassessed'.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 151986@bnt-lap001
Assistant-Session: ccd02b6b-80ae-48e5-8cad-9c8f74d21a67
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 151986@bnt-lap001
Assistant-Session: ccd02b6b-80ae-48e5-8cad-9c8f74d21a67
Updated by fix-consistency on 2026-09-22:
- update .custodian-brief.md for audit-core
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 151986@bnt-lap001
Assistant-Session: ccd02b6b-80ae-48e5-8cad-9c8f74d21a67
The contract T05 waited on is published: info-tech-canon
emission-cadence wire schema 0.1, contract digest b08b4d95fc4b0bd3.
A source-owned declaration now travels as emission_cadence on the
sender registration; expected-rate entries raise below_declared_cadence
on /v1/stream-findings from the same counts /v1/reconciliation returns.
heartbeat-or-reconciliation entries are validated and left to T04/T06.
Records the observer evaluation of net-kingdom's local-identity
declaration: structurally clean, not operationally evaluated, one
heartbeat event_class mapping incompatibility.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 151986@bnt-lap001
Assistant-Session: ccd02b6b-80ae-48e5-8cad-9c8f74d21a67
A12 r2 reaches every key and value of the declaration, so the _v0.7
inside the standard: path is a standard version. The path is now
canon/standards/security-layer-model. Comments and schema_version are
not reached and are left as they were.
The conformance test now fails on a version anywhere in either form of
the declaration, including a versioned standard: path and
companion_version, and carries a self-test that it catches those forms.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Remove standard_version from layer.yaml and INTENT.md frontmatter (A12),
mark layer.yaml derived from INTENT.md (A11), and add tests asserting the
derived markers, the absence of a standard version, and agreement of the
two forms after an ASCII case fold over the closed four-token vocabulary
(A9). Layer values are left as spelled: INTENT.md Engine, layer.yaml engine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for audit-core
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
AUDIT-IN-0005. flex-auth produces the decision record, declares no §11
emission guarantee, and declined to take the reading that moves the
obligation to audit-core. audit-core declines it too, on its own authority:
class, cadence and detection surface are properties of emitting; audit-core
cannot detect non-production; the obligations already sit on each sender
registration; archive-as-source would make §11's check vacuous; and no
access-engine sender is registered at all.
Binds audit-core, does not rule §11 — gate-house still owns that, so
flex-auth's G2 stays open.
Reflexive half: audit-core's own chain-head attestation emission is now
declared in layer.yaml rather than only in docs/integrity.md prose, and
asserted against the CronJob and the contract by test.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-15:
- update .custodian-brief.md for audit-core
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
T1 accepted 202 then 401 after drop; production T0 still 202 for
approval-engine and informed-decision. No live factory token replaced.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
T09/T11 remaining gate: a formerly valid T1 is 401 after drop, while
the production T0 still 202. Does not replace live factory tokens.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Updated by fix-consistency on 2026-09-15:
- update .custodian-brief.md for audit-core
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
A labeled Job in tenant-engine posted 202 then duplicate 200.
Chain intact (60 events). AUDIT-IN-0002 promoted. Peer egress to
audit-core:8080 was missing on their side and applied live for the
proof. No token values recorded.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Updated by fix-consistency on 2026-09-15:
- update .custodian-brief.md for audit-core
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Registry version 9 includes tenant-engine with a token. ExternalSecret
synced and the receiver is Ready. Evidence is metadata only; no secret
values. Producer file projection remains tenant-engine's for live 202.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Public bao.coulomb.social was retracted today and now presents
Traefik's default certificate. Login must use http://127.0.0.1:18200
via openbao-attended-exec.py, matching the sitting-requester path.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
warden access runs OIDC from the caller environment. Putting BAO_ADDR
only on the child env argv leaves bao login talking to the wrong
address, which fails before command handoff.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
AUDIT-WP-0010-T02. Contained platform-admin login writes tenant-engine
into the OpenBao senders registry with CAS, force-syncs the
ExternalSecret, and recreates the receiver so it re-reads identities.
No token value is printed; metadata evidence only.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Updated by fix-consistency on 2026-09-15:
- update .custodian-brief.md for audit-core
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Updated by fix-consistency on 2026-09-15:
- update .custodian-brief.md for audit-core
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Apply the separate attestor identity, named-ConfigMap RBAC, attest
egress and daily CronJob. Bootstrap an empty chain-head ConfigMap
only because it was absent; drop the placeholder from the apply path
so a later apply cannot overwrite a live head. One-shot job published
a 59-event attestation; mounted readback and receiver write-denial
passed. Offsite copy stays the operator path.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Attended orphan-token remint succeeded. ClusterSecretStore needed a
force-sync to drop the cached 403. ExternalSecrets synced, the mounted
lease rotated, and /readyz returned 200 in 6ms. No secret values.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Warden fails closed on any child stdout or stderr, even on success.
The previous helper echoed status and prompted for BAO_TOKEN after
the login envelope had already unset it. Use the contained
.vault-token helper, write Kubernetes Secret from a file, and persist
only metadata evidence.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Updated by fix-consistency on 2026-09-14:
- update .custodian-brief.md for audit-core
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
The 768h orphan token in external-secrets/openbao-audit-core-eso-token
expired at 2026-09-14T10:23Z and ClusterSecretStore lookup-self is 403,
so ESO cannot mint database/creds/audit-core-runtime. Recreate the
Kubernetes Secret without last-applied-configuration so the token is
not stored in annotation metadata.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
RollingUpdate maxSurge cannot schedule a second 50m pod on a node
packed to 99% CPU requests. Recreate replaces in place; the Service
already has no ready endpoints.
Image sha256:ec15f63d… is commit bc3d80f. Local release check passed
against disposable Postgres. No schema migration. Live Ready still
depends on a fresh runtime lease from ESO/OpenBao.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
/readyz walked the hash chain and opened pooled connections with no
libpq connect_timeout, so a 2s kubelet probe never saw a response and
the pod stayed unready. Informed Decision accept is blocked on that.
Probe health() only, under a 1.5s budget, publish last-known
tamper_evidence, and fail TCP handshake in 1s. Integrity stays on
/v1/integrity.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
Set flavor on open workplans from origin/prose/status. Copy existing
depends_on aliases only. Do not promote residuals.
Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267