fix: report truthful compatibility outcomes and verify audit coverage
Some checks failed
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 14:59:33 +02:00
parent c0383c9c2b
commit 72f3513954
7 changed files with 246 additions and 16 deletions

View file

@ -56,9 +56,9 @@ A host composes `create_app(access_controller=AccessController(...))` with:
only after an operational-custody probe and explicit durable acceptance. Every allow must reach this sink before handler execution;
a failed sink blocks reads as well as writes. Authorization receipts say
`authorized`, not “operation completed.” Domain commit/outcome audit remains a
separate concern. Native durable mutations now have a
[transaction-linked outcome outbox](operation-outcome-audit.md); compatibility
and external mutations remain outside that slice.
separate concern. Native durable and implemented SQL compatibility mutations have a
[transaction-linked outcome outbox](operation-outcome-audit.md); arbitrary
embedded-host and external mutations remain outside that slice.
- The root's existing immutable issuer and subject, supplied after owner resolution.
No username, email, first-login promotion or generic role establishes root.