Verified the three published hashes reproduce byte for byte before promoting anything, then moved the schema, canonicalizer and vectors into governed assets. history/20260909-initial-exploration/ is untouched and stays the provenance record. - schemas/, informed_decision/, tests/vectors/ populated; the reference canonicalizer's ad-hoc __main__ block replaced by a real `python -m informed_decision` entry point. - tests/test_canonicalize.py — 20 tests, all green. Published vectors, all four isolation properties, canonical-form round-trip, key sorting, and a provenance test asserting the governed fixtures have not drifted from history/. - docs/specs/EvidenceModel.md — the two hashes, the split and why it exists, the four isolation properties, the presentation record, the bundle, and the relationship to audit-core. - pyproject.toml, Makefile. One test of mine was wrong on first run: it scanned for ", " to assert no insignificant whitespace, which fires on prose inside a brief. Replaced with a canonical round-trip comparison, which is the property actually meant. The canonicalizer was correct. EvidenceModel leads with what the model does NOT claim — no proof of comprehension, no proof of reading (deliberately, since the alternative is surveillance), no survival of a compromised surface, and audit-core's inherited bound that a hash chain cannot prove a record was never sent. T06 stays progress: the SCOPE.md rewrite is gated on the T02 ruling. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR Assistant: claude-code Assistant-Model: opus Assistant-Process: 1565372@bnt-lap001 Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
73 lines
2 KiB
JSON
73 lines
2 KiB
JSON
{
|
|
"memo_id": "01K4LOGIN00000000000000001",
|
|
"memo_version": 1,
|
|
"question": "Log into Payroll-Prod as Bernd Worsch in tenant ACME?",
|
|
"requested_act": "login",
|
|
"binding_level": "organizational",
|
|
"brief": "You are entering Payroll-Prod. Sessions are recorded. Privileges at the gate are identity-scoped, not hat-scoped.",
|
|
"locale": "en",
|
|
"ui_release": "informed-decision@0.4.0",
|
|
"packet": [],
|
|
"highlights": [],
|
|
"binding": {
|
|
"principal": {
|
|
"id": "01K4PERSONBERND00000000001",
|
|
"kind": "person",
|
|
"display_name": "Bernd Worsch",
|
|
"role": "employee",
|
|
"identifiers": [
|
|
{ "scheme": "email", "value": "bernd.worsch@example.com" },
|
|
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd" }
|
|
]
|
|
},
|
|
"available_identities": [
|
|
{
|
|
"id": "01K4PERSONBERND00000000001",
|
|
"kind": "person",
|
|
"display_name": "Bernd Worsch",
|
|
"identifiers": [
|
|
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd" }
|
|
]
|
|
},
|
|
{
|
|
"id": "01K4PERSONBERNDADMIN000001",
|
|
"kind": "person",
|
|
"display_name": "Bernd Worsch (break-glass)",
|
|
"identifiers": [
|
|
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd-bg" }
|
|
]
|
|
}
|
|
],
|
|
"target": {
|
|
"kind": "tenant",
|
|
"id": "tenant:acme",
|
|
"label": "ACME Corp",
|
|
"environment": "prod",
|
|
"requires_new_bind": true
|
|
},
|
|
"available_bind_scopes": [
|
|
{
|
|
"kind": "tenant",
|
|
"id": "tenant:acme",
|
|
"label": "ACME Corp",
|
|
"environment": "prod",
|
|
"requires_new_bind": true
|
|
},
|
|
{
|
|
"kind": "tenant",
|
|
"id": "tenant:beta",
|
|
"label": "Beta GmbH",
|
|
"environment": "prod",
|
|
"requires_new_bind": true
|
|
}
|
|
],
|
|
"granted_at_bind": {
|
|
"roles": ["authenticated"],
|
|
"permissions": ["session.create"]
|
|
},
|
|
"terms": {
|
|
"monitoring": true,
|
|
"consent_code": "LOGIN-PROD-2026"
|
|
}
|
|
}
|
|
}
|