flex-auth/workplans/FLEX-WP-0031-decision-record-emission.md
tegwick 80ffe729d4
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s
Build and Publish Container Image / build-and-push (push) Successful in 1m11s
Apply gate-house's section 11 rulings: four-token validator, emission guarantee, resource.system.
GH-DEC-2026-017: the validator admitted {Staff, Engine, Tooling}, built from
section 4's catalog rows, and rejected Taxonomy, which section 3.1 defines.
railiance-master was conforming; the validator was the divergent artifact.
Now four tokens, ASCII case folded, section 4's spelling canonical, INTENT.md
governing while form disagreements are still reported, and every run states
its scope (section 11 binds section 4; volunteers are not non-conformances).
Also fixes the survey silently dropping audit-core's layer.yaml by decoding
peers into flex-auth's own struct.

GH-DEC-2026-018: flex-auth is a section 4 source of evidence. G2 closes as a
question and reopens as a dated gap (review 2026-10-19). cadence.yaml
publishes the per-event-class inventory: deny, redact, not_applicable and
audit_only rare load-bearing (heartbeat and reconciliation, rate forbidden);
allow volume load-bearing (expected-rate and reconciliation). INTENT.md
declares source_of_evidence and names it; tests assert both. Delivery is
FLEX-WP-0031.

FLEX-DEC-2026-015: resource.system follows the runtime, not the repository,
answering ops-warden's WARDEN-IN-0003.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 06:35:30 +02:00

3.1 KiB

id type title domain repo status flavor owner topic_slug planning_priority planning_order related_workplans created updated
FLEX-WP-0031 workplan The decision record has a declared emission guarantee and nothing that delivers it infotech flex-auth ready implementation claude netkingdom P1 310
FLEX-WP-0030
FLEX-WP-0019
2026-09-21 2026-09-21

FLEX-WP-0031 — Deliver the decision-record emission guarantee

GH-DEC-2026-018 ruled that flex-auth is the §4 source of evidence for the decision record, and that it is not conforming on §11 until it declares and delivers a per-event-class emission guarantee. The declaration is published (cadence.yaml, FLEX-WP-0030-T07). Nothing emits: the decision record reaches consumers only in the /v1/check response, no sender named flex-auth or access-engine is registered with audit-core, and there is no outbox, heartbeat or reconciliation count. This plan closes declared gap G2 (docs/conformance/security-layer-conformance.md, review 2026-10-19).

Bound, stated up front so no argument rests on more: heartbeat and reconciliation detect loss, outage, drain failure and accident. Neither detects a compromised flex-auth suppressing a record and its own count together.

1. Decide emission atomicity

id: FLEX-WP-0031-T01
status: todo
priority: high

GH-DEC-2026-018 left open whether decision-record emission must be atomic with the decision (§9.4), pending the class inventory. It exists now. Decide whether a rare load-bearing decision (deny) may be returned before its record is committed to the outbox, and record the answer as a FLEX-DEC. Gate: decided, with the latency cost stated.

2. Register flex-auth as an audit-core sender

id: FLEX-WP-0031-T02
status: todo
priority: high

Open an intake with audit-core (worked examples AUDIT-IN-0002, AUDIT-IN-0003): sender registration, evidence_kind, heartbeat_classes per class exactly as cadence.yaml publishes them, and a token lane routed via warden route find. audit-core has said it accepts the classification as supplied and will not infer it. Gate: sender registered; no secret in any file.

3. Transactional outbox, heartbeat and reconciliation counts

id: FLEX-WP-0031-T03
status: todo
priority: high

Emit one event per decision into a local outbox, drained to audit-core POST /v1/events; a daily flex-auth.decision.heartbeat; committed counts per class exposed for GET /v1/reconciliation; lag bound per cadence.yaml. Gate: cadence.yaml validates under the net-kingdom emission-cadence profile checker with the inventory supplied as --rare-load-bearing/--load-bearing assertions; tests assert the declared classes equal the DecisionEffect vocabulary so a new effect cannot ship unclassified.

4. Close G2

id: FLEX-WP-0031-T04
status: todo
priority: medium

Change cadence.yaml state to emitting, move G2 out of the gap table with the evidence, and tell gate-house, audit-core and kings-guard. Gate: a silence finding is observed on a deliberately withheld heartbeat in a non-production run.