The framework moved from draft-5 to draft-8 while this workplan ran. No finding was reversed, but three things changed underneath it: R moved to 2 once rapp-postgres declared the window, a sixth axis V (availability) appeared, and the implemented-versus-evidenced distinction became a schema field. T03 reduces: the confirmation-oracle finding landed as Decision 4.5.3 and question 11 is marked framework-resolved, so no amendment remains -- only our own position document. The legal question routes to risk-nexus rather than the-custodian, per §19.11 and policy-nexus INTENT. T06 reduces to confirmation: all five findings were adopted and the two stale status lines it was going to flag are already fixed. T07 is new. V1 needs critical dependencies enumerated, restart recovery exercised and recovery time measured. The 2026-08-16 reboot walk observed ~40s of unreadiness but is not an exercise and does not enumerate the dependency set. T08 is new and covers two defects in our own declaration. provider.R.available quotes a 30-day horizon we do not solely control -- at P1 the horizon is the instance maximum across co-residents. And under Decision 6.1, user-engine was never told what we declared, which makes the declaration drift rather than a completed change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1.7 KiB
1.7 KiB
SCOPE
This file was generated by
statehub register. Refine it as the repository boundaries become clearer.
One-liner
Reliable multi-tenant auto setup audit capability.
Core Idea
audit-core exists to provide the capability described in INTENT.md.
In Scope
- Maintain the repository's primary implementation.
- Keep docs, tests, and operational metadata current.
- Operational audit custody (
operations.audit) and its declared recovery bound.
Out of Scope
- Own unrelated adjacent systems.
- Make irreversible operational decisions without human approval.
- Procuring or operating S3 / Barman / WAL.
- Booked cost or a second usage stream for
platform:audit-storage. - A
rapp.yamlin this repo (schema requiresrapp-*). - Public ingest.
Current State
- Status: production
- Production receiver on railiance01 (
namespace audit-core), Postgres operational custody onplatform-pg, senderuser-engine. - Recovery is the platform
data.backupwindow (30 days). Live/readyzreportscustody_class=operational,tamper_evidence=true,recoverable_days=30(imagesha256:7febc28e…). - Hash chain verified on 30 live events
(
docs/evidence/chain-head-20260816.json). - ITC-CAP case:
data/capability/audit-core-operational.jsonat D4.data.archiveis an unmet requirement. - Tenancy posture:
tenancy.yaml(NetKingdom Tenancy Posture v0.1 draft-8, Decision 5.4). DeclaredI1 A2 E1 P1 R1, targetE3andR2. E is quoted at 1 although the E2 mechanism is in place on both paths — the §13 E2 artifact is adversarial and does not exist yet (AUDIT-WP-0008-T05).
Getting Oriented
- Start with: INTENT.md
- Agent instructions: AGENTS.md
- Workplans: workplans/