Close the remaining PDP obligations: mechanical layer declaration check, registry-snapshot digest in provenance, explicit allow TTL, per-input-class freshness deadlines, and the published decision-record contract. Document the canonical request digest as the §6.4.2 replay test. Assistant: grok Assistant-Session: 01a06256-fb71-7102-b3a9-27e6734257d0 |
||
|---|---|---|
| .. | ||
| access_descriptor.yaml | ||
| action_authorization.json | ||
| audit_event.json | ||
| batch_check_request.yaml | ||
| check_request.yaml | ||
| decision_envelope.json | ||
| exposure_event.json | ||
| inherited_relationships.yaml | ||
| policy_fixture.yaml | ||
| policy_package.md | ||
| policy_package.yaml | ||
| project_resource_manifest.yaml | ||
| README.md | ||
| redact_policy_package.md | ||
| registry_snapshot.json | ||
| relationship_fact.yaml | ||
| subject_manifest.yaml | ||
| team_subject_manifest.yaml | ||
CARING examples
Small fixtures for the executable CARING 0.4.0-RC2 profile used by
FLEX-WP-0002.
These are intentionally compact. They prove that the canonical descriptor,
request, decision, registry, audit, and Rego-in-Markdown policy package
shapes can round-trip through pkg/api and internal/policy.
The set includes local subjects, groups, teams, project resources, inherited relationship facts, exposure events, allow/deny fixtures, and a redact-with-obligation policy package.