--- id: GH-WP-0002 type: workplan title: "Approval evidence integrity" domain: infotech repo: gate-house status: active origin: GH-IN-0001 state_hub_workstream_id: "393d46ad-4f8c-5578-b63d-91cb0e8b9502" --- # Approval evidence integrity Promoted from `GH-IN-0001`, raised by `audit-core` with a drafted five-task plan. It escalates correction 2 of the `AUDIT-IN-0001` assent from a caveat in a reply to tracked work, because it must land before `approval-engine` is built rather than after. **The gap.** A hash chain proves accepted records were not altered or truncated. It proves nothing about an event never emitted. Every `approval-engine` event class degrades gracefully under omission except one: a suppressed **revocation** leaves the chain intact, the attestation matching, and the record showing an approval that was never revoked. The evidence half would look sound and not be. Doctrine now at `net-kingdom/canon/standards/security-layer-model_v0.5.md` §9.6. ```task id: GH-WP-0002-T01 status: done priority: high state_hub_task_id: "538f0417-2d71-578c-8cf3-e7077fa410af" ``` Amend §9.4 so it does not rest on `audit-core`'s principle 6 omission claim. Done in v0.4; §9.6 generalizes it estate-wide and v0.5 adds the load-bearing versus attributive distinction. ```task id: GH-WP-0002-T02 status: progress priority: high state_hub_task_id: "73a8feb0-02bd-5191-bdfd-82bcc42c6756" ``` Specify the transactional-outbox contract for `approval-engine`: same transaction as the object mutation, queue local to the engine, at-least-once into the outbox since `audit-core` dedupes on event id and a replay does not fork the chain. Boundary and locality are in `approval-engine/INTENT.md` and §9.4; the wire contract is not yet written. ```task id: GH-WP-0002-T03 status: todo priority: high state_hub_task_id: "1fc8fd3c-7af4-50e7-a07c-f45016f8b1f3" ``` Decide the revocation failure mode explicitly: fail closed, or proceed with a detectable gap. Both are defensible; undecided is not, and an implementation accident is the worst outcome. Note v0.5's local-outbox rule narrows this considerably — fail-closed now triggers only when the engine's own store is down — but the ruling is still owed. ```task id: GH-WP-0002-T04 status: todo priority: medium state_hub_task_id: "3d62dbf9-786e-58c1-bd87-fb43658ca865" ``` Give the gap a detection surface: outbox depth and age, or reconciliation of `approval-engine` object counts against `audit-core` event counts per class. Today nothing would surface a silent loss. Relate to §9.6's silence-as-signal rule, which `kings-guard` offered to implement at its own layer. ```task id: GH-WP-0002-T05 status: todo priority: medium state_hub_task_id: "2a2a73ea-2778-59d2-94ef-7a70a22bb169" ``` Add a §11 conformance check so the next engine catalogued as an evidence source declares its emission guarantee rather than reintroducing this silently. ```task id: GH-WP-0002-T06 status: todo priority: high state_hub_task_id: "250cb9b3-713d-5607-ad1b-225e339693bf" ``` Settle the consumption ordering contract between `approval-engine` and `access-engine` — who signals consumed, at what point relative to the decision, and the handling of an allow never consumed, a double consumption by racing callers, and consumption after a failed action. Raised by `flex-auth`; required before `FLEX-WP-0017` T05. Recorded unresolved in `approval-engine/INTENT.md`.