audit-core/docs
codex 40fc7d694c
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Answer flex-auth B3: the emitter is the section 4 source, not the archive
AUDIT-IN-0005. flex-auth produces the decision record, declares no §11
emission guarantee, and declined to take the reading that moves the
obligation to audit-core. audit-core declines it too, on its own authority:
class, cadence and detection surface are properties of emitting; audit-core
cannot detect non-production; the obligations already sit on each sender
registration; archive-as-source would make §11's check vacuous; and no
access-engine sender is registered at all.

Binds audit-core, does not rule §11 — gate-house still owns that, so
flex-auth's G2 stays open.

Reflexive half: audit-core's own chain-head attestation emission is now
declared in layer.yaml rather than only in docs/integrity.md prose, and
asserted against the CronJob and the contract by test.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:09:47 +02:00
..
evidence Record overlap-then-drop bearer revocation for T09 and T11 2026-09-15 22:32:29 +02:00
approval-engine-source-registration.md docs: record native audit sender delivery and reload 2026-09-11 10:32:20 +02:00
audit-backend-contract.md AUDIT-WP-0009-T01 — derive tamper_evidence from live attestation state 2026-09-06 20:34:22 +02:00
availability-recovery.md Implement AUDIT-WP-0008 T03, T06, T07, T08. 2026-08-18 15:24:55 +02:00
erasure-and-audit.md Implement AUDIT-WP-0008 T03, T06, T07, T08. 2026-08-18 15:24:55 +02:00
event-envelope.md AUDIT-WP-0010 T01/T03/T04 — admit tenant-engine, and the envelope does not match 2026-09-10 16:34:45 +02:00
informed-decision-source-registration.md docs: record native audit sender delivery and reload 2026-09-11 10:32:20 +02:00
integrity.md Bound /readyz so kubelet probes cannot hang the Service 2026-09-14 22:13:55 +02:00
interface-card.yaml Refine AUDIT-WP-0008 open tasks against draft-8. 2026-08-18 15:20:58 +02:00
operator-runbook.md Bound /readyz so kubelet probes cannot hang the Service 2026-09-14 22:13:55 +02:00
recovery-synthetic-load-driver.md feat(AUDIT-WP-0008): add T02 synthetic load driver 2026-08-22 16:46:31 +02:00
section-4-source-of-evidence.md Answer flex-auth B3: the emitter is the section 4 source, not the archive 2026-09-21 02:09:47 +02:00
senders.example.json AUDIT-WP-0009-T03/T09 — evidence_kind, and approval-engine's registration inputs 2026-09-06 22:31:37 +02:00
stream-completeness.md AUDIT-WP-0009 T04/T06/T07 — heartbeats, reconciliation, and a home for findings 2026-09-10 16:43:26 +02:00
tenant-engine-source-registration.md AUDIT-WP-0010 T01/T03/T04 — admit tenant-engine, and the envelope does not match 2026-09-10 16:34:45 +02:00