audit-core/WORK-RECORDS.md
tegwick 58a106aa4d
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Implement AUDIT-WP-0008 T03, T06, T07, T08.
T08 fixes two defects in our own declaration. provider.R.available quoted a
30-day horizon audit-core does not solely control: at P1 the erasure horizon is
the instance maximum across co-residents, so a co-resident declaring longer
extends what a sender's records remain recoverable for, silently. Decision 4.5.4
names this for tiers; it applies to a provider quoting a number too, and the
provider block now says so. And user-engine, the only consumer, was notified
under Decision 6.1 -- what we declared, that E4 and R4 are unreachable here, and
that the retention number is a floor rather than a ceiling.

T03 writes docs/erasure-and-audit.md: the fact/payload split, why shreddability
is not retrofittable onto a chain committing to cleartext, and why the retained
hash is a confirmation oracle over low-entropy audit records. The framework half
was already resolved as Decision 4.5.3, so what remains is our own position. The
legal basis for retaining audit facts is routed to risk-nexus, open and visible.

T06 closes the review loop with net-kingdom: five findings adopted, declaration
validates clean, and the E line will go stale on an upgrade that Decision 6.1
deliberately does not require anyone to announce.

T07 enumerates the seven dependencies on the accept path and specifies five
recovery scenarios with integrity as a pass condition. It settled one thing: V2
is not reachable from P1 as built, since platform-pg runs instances 1 and
Decision 4.6.1 makes V the minimum across synchronous providers. V1 is the
ceiling here, not the next step. The exercise needs a live window.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 15:24:55 +02:00

5 KiB

Work Records — audit-core

Generated by statehub fix-consistency (CUST-WP-0061-T04, work-record stage 3). Do not edit by hand — edit the source file/block listed for each record and re-run fix-consistency to refresh this index. Archived workplans are omitted; closed decisions/intakes/engagements stay listed so recently-resolved work is still visible. [auto]

Kind ID Status Lane Source
workplan AUDIT-WP-0001 finished workplans/AUDIT-WP-0001-statehub-bootstrap.md
workplan AUDIT-WP-0002 finished workplans/AUDIT-WP-0002-pluggable-audit-backend.md
workplan AUDIT-WP-0003 finished workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
workplan AUDIT-WP-0004 finished workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
workplan AUDIT-WP-0005 finished workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
workplan AUDIT-WP-0006 finished workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
workplan AUDIT-WP-0007 finished workplans/AUDIT-WP-0007-integrity-verification.md
workplan AUDIT-WP-0008 ready workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0001-T01 done workplans/AUDIT-WP-0001-statehub-bootstrap.md
task AUDIT-WP-0001-T02 done workplans/AUDIT-WP-0001-statehub-bootstrap.md
task AUDIT-WP-0001-T03 done workplans/AUDIT-WP-0001-statehub-bootstrap.md
task AUDIT-WP-0002-T01 done workplans/AUDIT-WP-0002-pluggable-audit-backend.md
task AUDIT-WP-0003-T01 done workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
task AUDIT-WP-0003-T02 done workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
task AUDIT-WP-0003-T03 cancel workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
task AUDIT-WP-0003-T04 cancel workplans/AUDIT-WP-0003-user-engine-event-ingestion-service.md
task AUDIT-WP-0004-T01 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T02 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T03 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T04 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T05 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T06 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0004-T07 done workplans/AUDIT-WP-0004-receiver-correctness-and-hardening.md
task AUDIT-WP-0005-T01 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T02 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T03 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T04 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T05 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0005-T06 done workplans/AUDIT-WP-0005-postgres-store-and-production-deployment.md
task AUDIT-WP-0006-T01 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0006-T02 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0006-T03 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0006-T04 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0006-T05 done workplans/AUDIT-WP-0006-honest-custody-and-canon-join.md
task AUDIT-WP-0007-T01 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0007-T02 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0007-T03 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0007-T04 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0007-T05 done workplans/AUDIT-WP-0007-integrity-verification.md
task AUDIT-WP-0008-T01 done workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T02 done workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T03 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T05 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T06 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T07 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md
task AUDIT-WP-0008-T08 todo workplans/AUDIT-WP-0008-tenancy-posture-alignment.md