audit-core/SCOPE.md
tegwick 4d5d989344
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Refine AUDIT-WP-0008 open tasks against draft-8.
The framework moved from draft-5 to draft-8 while this workplan ran. No finding
was reversed, but three things changed underneath it: R moved to 2 once
rapp-postgres declared the window, a sixth axis V (availability) appeared, and
the implemented-versus-evidenced distinction became a schema field.

T03 reduces: the confirmation-oracle finding landed as Decision 4.5.3 and
question 11 is marked framework-resolved, so no amendment remains -- only our
own position document. The legal question routes to risk-nexus rather than
the-custodian, per §19.11 and policy-nexus INTENT.

T06 reduces to confirmation: all five findings were adopted and the two stale
status lines it was going to flag are already fixed.

T07 is new. V1 needs critical dependencies enumerated, restart recovery
exercised and recovery time measured. The 2026-08-16 reboot walk observed ~40s
of unreadiness but is not an exercise and does not enumerate the dependency set.

T08 is new and covers two defects in our own declaration. provider.R.available
quotes a 30-day horizon we do not solely control -- at P1 the horizon is the
instance maximum across co-residents. And under Decision 6.1, user-engine was
never told what we declared, which makes the declaration drift rather than a
completed change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 15:20:58 +02:00

1.7 KiB

SCOPE

This file was generated by statehub register. Refine it as the repository boundaries become clearer.

One-liner

Reliable multi-tenant auto setup audit capability.

Core Idea

audit-core exists to provide the capability described in INTENT.md.

In Scope

  • Maintain the repository's primary implementation.
  • Keep docs, tests, and operational metadata current.
  • Operational audit custody (operations.audit) and its declared recovery bound.

Out of Scope

  • Own unrelated adjacent systems.
  • Make irreversible operational decisions without human approval.
  • Procuring or operating S3 / Barman / WAL.
  • Booked cost or a second usage stream for platform:audit-storage.
  • A rapp.yaml in this repo (schema requires rapp-*).
  • Public ingest.

Current State

  • Status: production
  • Production receiver on railiance01 (namespace audit-core), Postgres operational custody on platform-pg, sender user-engine.
  • Recovery is the platform data.backup window (30 days). Live /readyz reports custody_class=operational, tamper_evidence=true, recoverable_days=30 (image sha256:7febc28e…).
  • Hash chain verified on 30 live events (docs/evidence/chain-head-20260816.json).
  • ITC-CAP case: data/capability/audit-core-operational.json at D4. data.archive is an unmet requirement.
  • Tenancy posture: tenancy.yaml (NetKingdom Tenancy Posture v0.1 draft-8, Decision 5.4). Declared I1 A2 E1 P1 R1, target E3 and R2. E is quoted at 1 although the E2 mechanism is in place on both paths — the §13 E2 artifact is adversarial and does not exist yet (AUDIT-WP-0008-T05).

Getting Oriented

  • Start with: INTENT.md
  • Agent instructions: AGENTS.md
  • Workplans: workplans/