Close INFD-IN-0001; design the independent evidence path; track both blockers
Housekeeping the ruling left behind, plus the one piece of blocked work that was substantially ours to move. INFD-IN-0001 closed with its resolution recorded, matching approval-engine's IN-0002 form. It was still open after GH-DEC-2026-012 answered it. INFD-IN-0003 and docs/evidence-path-design.md take up O-02, which was sitting in the blueprint as "mechanism unchosen". Read independence and the local transactional outbox are settled and not in question. The real question is what travels, and it is sharper for us than for approval-engine because a presentation record carries the brief and packet material actually shown to a human. Three candidates with costs; proposal is commitment-only for Stage 1 — hashes, principal, timestamps, acks, co-referenced approval id — which discharges limit 3 and removes our ability to alter the record, while leaving us able to erase the content. That residual is declared alongside the existing compromised-surface one rather than papered over. Deliberately not proposing the full binding document unilaterally: it would put commercial and personal material into the audit fabric under retention and export entitlements designed for audit events. That is a meaningful change in what audit-core holds and is its owner's to accept, not ours to assume. The third option, a separate evidence store, is refused here because that store has no owner and inventing one routes around the §16 decision against stronger archival custody. Cadence declared and its form argued rather than copied: approval-engine's heartbeat answer suits genuinely low-volume classes, but ours are mixed — presentations are one per render, while dispositions and stance applications are low-volume and are the security-relevant ones. Reconciliation per class as primary, heartbeat for the low-volume classes. Depends on AUDIT-WP-0009 T04/T06; declared, not claimed operating. INFD-IN-0002 files the tenant blocker as a tracked record rather than leaving it in message threads and a blueprint footnote. T07 and T08 now name their blocking intakes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR Assistant: claude-code Assistant-Model: opus Assistant-Process: 1565372@bnt-lap001 Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
parent
d50f480075
commit
024946e9da
5 changed files with 336 additions and 9 deletions
|
|
@ -131,10 +131,19 @@ Consequences, binding on implementation:
|
|||
4. **Atomicity covers accident, not compromise.** It does not close the residual
|
||||
in `layer.yaml`, and must never be described as doing so.
|
||||
|
||||
Open for implementation: whether the independent path is `audit-core` pull,
|
||||
a separately-credentialed push, or a third party drain. **T08 must not ship
|
||||
without one chosen**, because "we will add the independent path later" is how
|
||||
limit 3 quietly becomes limit 3-in-principle.
|
||||
**Cadence is owed**, because `layer.yaml` declares presentation evidence
|
||||
load-bearing (§9.6). The form differs from `approval-engine`'s: their classes are
|
||||
genuinely low-volume, so a heartbeat is the answer. Ours are mixed —
|
||||
presentations are high-volume (one per render), while dispositions and stance
|
||||
applications are low-volume and are the security-relevant ones. Proposed:
|
||||
reconciliation per class as the primary form, plus a heartbeat for the
|
||||
low-volume classes, since a quiet month of dispositions is indistinguishable
|
||||
from suppression by rate alone. Depends on `AUDIT-WP-0009` T04/T06; declared,
|
||||
not claimed operating.
|
||||
|
||||
What travels is the open question — see `docs/evidence-path-design.md` and O-02.
|
||||
**T08 must not ship without it chosen**, because "we will add the independent
|
||||
path later" is how limit 3 quietly becomes limit 3-in-principle.
|
||||
|
||||
---
|
||||
|
||||
|
|
@ -236,8 +245,15 @@ condition that it holds *only* because registrations are static and
|
|||
deployment-owned should be written into the contract, not left as reasoning in a
|
||||
message.
|
||||
|
||||
**O-02 — The independent evidence path.** Its mechanism is unchosen. Must be
|
||||
resolved before T08 ships.
|
||||
**O-02 — The independent evidence path.** Design and decision request written:
|
||||
`docs/evidence-path-design.md`, filed as `INFD-IN-0003`. Read independence and
|
||||
the local transactional outbox are settled; the open question is **what
|
||||
travels**, because a presentation record carries the brief and packet material
|
||||
actually shown to a human. Proposal is commitment-only (hashes, principal,
|
||||
timestamps, acks, co-referenced approval id) for Stage 1, with the erasure
|
||||
residual declared rather than papered over. Awaiting `audit-core` on the payload
|
||||
and the sender registration, and `gate-house` only if the content question is
|
||||
doctrine. Must be resolved before T08 ships.
|
||||
|
||||
**O-03 — Requester identity for an engine-originated memo.** `approval-engine`
|
||||
does not model a requester. Likely the approval's `principal`; needs confirming
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue