flex-auth/examples/qonto-assistant/protected_system_manifest.yaml
tegwick ae295824bd
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Register qonto-assistant as a protected system (finance.qonto.read)
QONTO-WP-0004-T04. Modeled directly on examples/tenant-engine/: one
resource type (finance-snapshot), one action (finance.qonto.read),
two registered subjects (an agent-harness session identity and the
founder's human identity), and a Rego policy gating on
resource.system + action + subject.type + tenant match. Tenant
capability-role/plan liveness (VEN/CUS) is deliberately NOT encoded
here -- that's qonto-assistant's separate tenant-engine live-lookup
check, per this package's own scope note.

Verified: flex-auth test-policy (6 rego tests + 6 fixtures, all pass),
load-registry, and CLI check for both an allow and a deny case. Also
verified end-to-end over real HTTP: a live flex-auth serve loaded with
this exact registry+policy, hit by qonto-assistant's actual
FlexAuthCheckClient (not a mock) -- allow for tenant:friendly:binky,
deny (wrong_tenant) for a mismatched tenant.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:19:26 +02:00

37 lines
1.2 KiB
YAML

id: qonto-assistant
name: Qonto Governed Assistant
resource_types:
- name: finance-snapshot
scope_level: Resource
planes:
- Data
- Audit
metadata:
description: >-
Read-only Qonto finance capability surface (org summary,
transactions, CostRunRate hints). No spend/transfer/card/write
capability is ever registered here -- those are hard-denied inside
qonto-assistant's own policy kernel and never reach flex-auth.
actions:
- name: finance.qonto.read
capabilities:
- View
- Audit
planes:
- Data
- Audit
exposure_modes:
- Masked
metadata:
required_context: []
description: >-
Coarse "may this actor use qonto-assistant's read surface at all"
gate. Tenant capability-role/plan liveness (VEN/CUS, ADR-0014) is a
separate check against tenant-engine's live-lookup endpoint, not
encoded in this policy -- conflating the two would authorize the
wrong thing (see tenant-engine's own policy_package.md note).
caring_profiles:
- caring-0.4.0-rc2
metadata:
flex_auth_contract: protected-system-v0
boundary_contract: qonto-assistant/docs/SecurityPractice.md