docs(canon): advance audit-core posture to evidenced E2
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
This commit is contained in:
parent
104d5c684c
commit
3491c294a2
2 changed files with 41 additions and 5 deletions
|
|
@ -6,11 +6,11 @@ domain: netkingdom
|
||||||
status: proposed
|
status: proposed
|
||||||
version: "0.1"
|
version: "0.1"
|
||||||
created: "2026-08-17"
|
created: "2026-08-17"
|
||||||
updated: "2026-08-22"
|
updated: "2026-08-23"
|
||||||
scope: multi-tenancy-security-framework
|
scope: multi-tenancy-security-framework
|
||||||
revision: "draft-12"
|
revision: "draft-13"
|
||||||
owner: net-kingdom
|
owner: net-kingdom
|
||||||
last_reviewed: "2026-08-22"
|
last_reviewed: "2026-08-23"
|
||||||
review_interval: 6m
|
review_interval: 6m
|
||||||
declaration_schema: canon/schemas/tenancy-posture_v0.1.schema.json
|
declaration_schema: canon/schemas/tenancy-posture_v0.1.schema.json
|
||||||
adr:
|
adr:
|
||||||
|
|
@ -28,7 +28,7 @@ related:
|
||||||
|
|
||||||
## Status
|
## Status
|
||||||
|
|
||||||
**Proposed, draft-12; ratification-ready.** Relocated from
|
**Proposed, draft-13; ratification-ready.** Relocated from
|
||||||
`the-custodian/canon/architecture` on
|
`the-custodian/canon/architecture` on
|
||||||
2026-08-17: multi-tenancy is part of the IT-security framework NetKingdom
|
2026-08-17: multi-tenancy is part of the IT-security framework NetKingdom
|
||||||
provides, so this framework belongs in NetKingdom canon beside the IAM Profile
|
provides, so this framework belongs in NetKingdom canon beside the IAM Profile
|
||||||
|
|
@ -82,6 +82,11 @@ and the tenant-engine boundary contract, not in the work-factory canon.
|
||||||
declare locally. Native actions, actors, lanes, patterns, and resources are
|
declare locally. Native actions, actors, lanes, patterns, and resources are
|
||||||
explicitly `not-applicable`, while omitted or unresolved workload references
|
explicitly `not-applicable`, while omitted or unresolved workload references
|
||||||
remain `unknown` (Decision 5.6.2).
|
remain `unknown` (Decision 5.6.2).
|
||||||
|
- **draft-13** advances the `audit-core` worked example from E1 to E2 after
|
||||||
|
bounded adversarial run `WH-ENG-20260822-AUDIT-E2-03` supplied the artifact
|
||||||
|
required by §13.2. The claim remains explicitly bounded and freshness-dated:
|
||||||
|
the attempted cross-tenant attacks did not work; this is not a universal
|
||||||
|
isolation proof.
|
||||||
|
|
||||||
**Reviewed by all six. The score:** six repos found three live defects in their
|
**Reviewed by all six. The score:** six repos found three live defects in their
|
||||||
own code by reading the ladders — `tenant-engine`'s unfiltered
|
own code by reading the ladders — `tenant-engine`'s unfiltered
|
||||||
|
|
@ -774,7 +779,7 @@ consistently:
|
||||||
| Service | Current | Notes |
|
| Service | Current | Notes |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| `tenant-engine` | `I1 A0 E1 P n/a R0 V0` | Acting identity is caller-supplied; unauthorised read paths set the A minimum; E2-shaped child-table controls are not evidenced; SQLite is outside P; no erasure or availability evidence. This corrects draft-7, which quoted A2/E2 despite its own minimum/evidence rules. |
|
| `tenant-engine` | `I1 A0 E1 P n/a R0 V0` | Acting identity is caller-supplied; unauthorised read paths set the A minimum; E2-shaped child-table controls are not evidenced; SQLite is outside P; no erasure or availability evidence. This corrects draft-7, which quoted A2/E2 despite its own minimum/evidence rules. |
|
||||||
| `audit-core` | `I1 A2 E1 P1 R2 V0` | E2 is implemented on both paths but awaits the adversarial artifact, so current remains E1. Its 30-day retention and erasure horizon are now declared and published. |
|
| `audit-core` | `I1 A2 E2 P1 R2 V0` | Bounded adversarial run `WH-ENG-20260822-AUDIT-E2-03` passed all three calibrated cross-tenant probes over ten operations, so E2 is evidenced as of 2026-08-22. This establishes only that the attempted attacks did not work. The 24-hour facility baseline requires review or replacement by `2026-08-23T22:10:25Z`. Its 30-day retention and erasure horizon remain declared and published. |
|
||||||
| `flex-auth` | `I1 A0 E1 P n/a R n/a V0` | Enables A3 for consumers. `/v1/check` authenticates no caller; E2 is implemented but not evidenced. |
|
| `flex-auth` | `I1 A0 E1 P n/a R n/a V0` | Enables A3 for consumers. `/v1/check` authenticates no caller; E2 is implemented but not evidenced. |
|
||||||
| `platform-pg` (provider) | `I0 A0 E0 P n/a R2 V1` | Provides P1; backup/restore and single-node recovery are evidenced. Provides no tenant boundary by itself. |
|
| `platform-pg` (provider) | `I0 A0 E0 P n/a R2 V1` | Provides P1; backup/restore and single-node recovery are evidenced. Provides no tenant boundary by itself. |
|
||||||
| `apps-pg` (provider) | `I0 A0 E0 P n/a R0 V0` | Zeros are structural, except R0/V0 are live gaps: no backup and no recovery evidence. |
|
| `apps-pg` (provider) | `I0 A0 E0 P n/a R0 V0` | Zeros are structural, except R0/V0 are live gaps: no backup and no recovery evidence. |
|
||||||
|
|
|
||||||
31
workplans/ADHOC-2026-08-23.md
Normal file
31
workplans/ADHOC-2026-08-23.md
Normal file
|
|
@ -0,0 +1,31 @@
|
||||||
|
---
|
||||||
|
id: ADHOC-2026-08-23
|
||||||
|
type: workplan
|
||||||
|
title: "Ad Hoc Tasks — 2026-08-23"
|
||||||
|
domain: infotech
|
||||||
|
repo: net-kingdom
|
||||||
|
status: finished
|
||||||
|
owner: codex
|
||||||
|
topic_slug: netkingdom
|
||||||
|
created: "2026-08-23"
|
||||||
|
updated: "2026-08-23"
|
||||||
|
---
|
||||||
|
|
||||||
|
# Ad Hoc Tasks — 2026-08-23
|
||||||
|
|
||||||
|
## Advance the canonical audit-core E level after adversarial evidence
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: ADHOC-2026-08-23-T01
|
||||||
|
status: done
|
||||||
|
priority: high
|
||||||
|
```
|
||||||
|
|
||||||
|
Updated the Tenancy Posture §5 worked example from `E1` to `E2` after
|
||||||
|
audit-core published bounded adversarial evidence for both tenant-filtered
|
||||||
|
paths. The canon text names run `WH-ENG-20260822-AUDIT-E2-03`, preserves the
|
||||||
|
claim's limited meaning, and records the facility freshness review deadline of
|
||||||
|
`2026-08-23T22:10:25Z` rather than presenting the result as timeless proof.
|
||||||
|
|
||||||
|
Verification validates audit-core's declaration against the canonical schema,
|
||||||
|
runs the tenancy-posture unit suite, and checks the repository diff.
|
||||||
Loading…
Add table
Add a link
Reference in a new issue