audit-core raised the intake with a drafted five-task plan and invited us to promote it verbatim or revise. Adopted close to verbatim, plus a sixth task for the consumption ordering contract flex-auth raised in the same round. The omission gap is not accepted for approvals. v0.5 §9.6 distinguishes load-bearing evidence from attributive; approvals are load-bearing, so emission atomicity is required and the outbox must be local. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
90 lines
2.9 KiB
Markdown
90 lines
2.9 KiB
Markdown
---
|
|
id: GH-WP-0002
|
|
type: workplan
|
|
title: "Approval evidence integrity"
|
|
domain: infotech
|
|
repo: gate-house
|
|
status: active
|
|
origin: GH-IN-0001
|
|
---
|
|
|
|
# Approval evidence integrity
|
|
|
|
Promoted from `GH-IN-0001`, raised by `audit-core` with a drafted five-task
|
|
plan. It escalates correction 2 of the `AUDIT-IN-0001` assent from a caveat in a
|
|
reply to tracked work, because it must land before `approval-engine` is built
|
|
rather than after.
|
|
|
|
**The gap.** A hash chain proves accepted records were not altered or truncated.
|
|
It proves nothing about an event never emitted. Every `approval-engine` event
|
|
class degrades gracefully under omission except one: a suppressed **revocation**
|
|
leaves the chain intact, the attestation matching, and the record showing an
|
|
approval that was never revoked. The evidence half would look sound and not be.
|
|
|
|
Doctrine now at `net-kingdom/canon/standards/security-layer-model_v0.5.md` §9.6.
|
|
|
|
```task
|
|
id: GH-WP-0002-T01
|
|
status: done
|
|
priority: high
|
|
```
|
|
|
|
Amend §9.4 so it does not rest on `audit-core`'s principle 6 omission claim.
|
|
Done in v0.4; §9.6 generalizes it estate-wide and v0.5 adds the load-bearing
|
|
versus attributive distinction.
|
|
|
|
```task
|
|
id: GH-WP-0002-T02
|
|
status: progress
|
|
priority: high
|
|
```
|
|
|
|
Specify the transactional-outbox contract for `approval-engine`: same
|
|
transaction as the object mutation, queue local to the engine, at-least-once
|
|
into the outbox since `audit-core` dedupes on event id and a replay does not
|
|
fork the chain. Boundary and locality are in `approval-engine/INTENT.md` and
|
|
§9.4; the wire contract is not yet written.
|
|
|
|
```task
|
|
id: GH-WP-0002-T03
|
|
status: todo
|
|
priority: high
|
|
```
|
|
|
|
Decide the revocation failure mode explicitly: fail closed, or proceed with a
|
|
detectable gap. Both are defensible; undecided is not, and an implementation
|
|
accident is the worst outcome. Note v0.5's local-outbox rule narrows this
|
|
considerably — fail-closed now triggers only when the engine's own store is
|
|
down — but the ruling is still owed.
|
|
|
|
```task
|
|
id: GH-WP-0002-T04
|
|
status: todo
|
|
priority: medium
|
|
```
|
|
|
|
Give the gap a detection surface: outbox depth and age, or reconciliation of
|
|
`approval-engine` object counts against `audit-core` event counts per class.
|
|
Today nothing would surface a silent loss. Relate to §9.6's silence-as-signal
|
|
rule, which `kings-guard` offered to implement at its own layer.
|
|
|
|
```task
|
|
id: GH-WP-0002-T05
|
|
status: todo
|
|
priority: medium
|
|
```
|
|
|
|
Add a §11 conformance check so the next engine catalogued as an evidence source
|
|
declares its emission guarantee rather than reintroducing this silently.
|
|
|
|
```task
|
|
id: GH-WP-0002-T06
|
|
status: todo
|
|
priority: high
|
|
```
|
|
|
|
Settle the consumption ordering contract between `approval-engine` and
|
|
`access-engine` — who signals consumed, at what point relative to the decision,
|
|
and the handling of an allow never consumed, a double consumption by racing
|
|
callers, and consumption after a failed action. Raised by `flex-auth`; required
|
|
before `FLEX-WP-0017` T05. Recorded unresolved in `approval-engine/INTENT.md`.
|