Close FLEX-WP-0029 second edition; correct cadence.yaml; block human/external-gated workplans
FLEX-WP-0029: publish the second stance-register edition across five rows (a third scope axis, not a converging two — tenant-engine scopes on engine-reachability, not security-zone), record Finding 1 as resolved by gate-house doctrine rather than by either side, and note Finding 3 as still open in secrets-engine's file. First edition marked superseded, not amended. SCOPE.md's G3 gap closed accordingly. FLEX-WP-0031: correct cadence.yaml to declare one heartbeat per rare load-bearing class instead of a single combined class (tests pass unchanged). Acknowledged audit-core's AUDIT-IN-0006 reply on T02 and recorded its corrections; the remaining work (drain, reconciliation, PVC rollout, G2 closure) stays wait/blocked pending the founder's attended OpenBao mint and gate-house's atomicity ruling, so the workplan moves to blocked. FLEX-WP-0027: marked blocked — the sole remaining task needs the operator's own signed-in account, an irreducible human action. FLEX-WP-0020: recorded net-kingdom's T04 update (NK-WP-0039-T02 done, runtime.yaml digests current) and replied with no objection to their ADR-0015 values-pointer proposal for the drifted runtime.yaml reference. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 250108@bnt-lap001 Assistant-Session: bab3d5bd-b0bb-42d0-bf80-94ed6fc2b08a
This commit is contained in:
parent
f208c1da06
commit
92981698d8
8 changed files with 264 additions and 21 deletions
25
cadence.yaml
25
cadence.yaml
|
|
@ -49,10 +49,27 @@ state: declared-not-yet-emitting
|
|||
gap: G2 # docs/conformance/security-layer-conformance.md
|
||||
|
||||
heartbeat:
|
||||
class: flex-auth.decision.heartbeat
|
||||
interval: 24h
|
||||
assertion: nothing-to-report
|
||||
missing: finding
|
||||
# Per rare load-bearing class (FLEX-WP-0031-T05), not one combined class: a
|
||||
# single heartbeat can go quiet on one suppressed class while the others
|
||||
# keep reporting, and rate monitoring is forbidden on all four for the same
|
||||
# reason. Each entry names the class it asserts nothing-to-report for.
|
||||
classes:
|
||||
- class: flex-auth.decision.deny
|
||||
interval: 24h
|
||||
assertion: nothing-to-report
|
||||
missing: finding
|
||||
- class: flex-auth.decision.redact
|
||||
interval: 24h
|
||||
assertion: nothing-to-report
|
||||
missing: finding
|
||||
- class: flex-auth.decision.not_applicable
|
||||
interval: 24h
|
||||
assertion: nothing-to-report
|
||||
missing: finding
|
||||
- class: flex-auth.decision.audit_only
|
||||
interval: 24h
|
||||
assertion: nothing-to-report
|
||||
missing: finding
|
||||
|
||||
reconciliation:
|
||||
# Declared for EVERY class, including the volume one. Rate monitoring can see
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue