flex-auth/docs/evidence
tegwick 3081067325
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 1m24s
State tenant-engine's tenant relation in the write-api package, v3.
tenant-engine named the relation in TEN-DEC-2026-002: `tenant` is the target
tenant record and always equals `resource.id`; the write API is cross-tenant
by design and `tenant.guardrail.read` does not differ. v2 carried no tenant
rule and a constant fixture tenant, so the deliberate scope and an omitted
rule were indistinguishable.

tenant-engine.write-api.mutate v3 (FLEX-DEC-2026-016):
- allowed requires tenant_is_target; a mismatch or absent tenant is denied
  tenant_not_target (object.get, so an absent key names the right cause).
- the cross-tenant scope is stated in the package and quantified by
  test_tenant_never_changes_effect over every action, three subjects and
  four tenants, with guards against passing by denying everything.
- fixtures rotate tenant across four tenants; five cross-tenant allows and
  two tenant_not_target denies added (42 fixtures, 33 tests, all pass).
- user-engine's tenant:platform exclusion is named as a fixed-record rule,
  not a subject/tenant relation, and tested separately.

Closes FLEX-WP-0022 (T01, T02 done). Also records TEN-IN-0004 and
SECRETS-IN-0002 on FLEX-WP-0020 and acknowledges the GH-DEC-2026-017
replies on FLEX-WP-0030-T04.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 07:39:57 +02:00
..
2026-09-11-user-portal-tenant-policy.md deploy: promote verified portal onboarding policy 2026-09-11 21:07:48 +02:00
2026-09-14-openrouter-live-pdp.json Resolve OpenRouter native contract and promote secrets-engine PDP 2026-09-14 00:54:56 +02:00
2026-09-14-t03-native-review-policy.json Admit exact T03 human review mandate with caller-bound policy 2026-09-14 02:47:31 +02:00
2026-09-14-t03-review-policy.json Admit exact T03 human review mandate with caller-bound policy 2026-09-14 02:47:31 +02:00
2026-09-15-repository-rename-baseline.md Prepare the access-engine repository coordinate without applying the rename. 2026-09-15 23:38:48 +02:00
2026-09-15-repository-rename-handoffs.md State tenant-engine's tenant relation in the write-api package, v3. 2026-09-21 07:39:57 +02:00
2026-09-15-sitting-approval-creates.json Compile compact sitting review package without widening T03. 2026-09-15 22:45:46 +02:00
2026-09-15-sitting-native-review-policy.json Admit the compact sitting review package on a dedicated pin. 2026-09-15 22:50:24 +02:00
2026-09-15-sitting-review-policy.json Compile compact sitting review package without widening T03. 2026-09-15 22:45:46 +02:00
2026-09-16-t03-renewal-policy-checks.json Admit T03 version-two reviews while preserving current sitting records 2026-09-16 01:08:56 +02:00
2026-09-21-layer-declaration-survey-after-ghdec017.json Apply gate-house's section 11 rulings: four-token validator, emission guarantee, resource.system. 2026-09-21 06:35:30 +02:00
2026-09-21-layer-declaration-survey.json Make the B1 survey a command, which immediately falsified B1. 2026-09-21 01:24:15 +02:00
security-zone-admission-2026-08-22.md feat(policy): adopt security zone stances 2026-08-22 15:17:13 +02:00