Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
60 lines
1.7 KiB
YAML
60 lines
1.7 KiB
YAML
schema_version: "0.1"
|
|
framework: netkingdom-tenancy-posture
|
|
service: example-security-api
|
|
role: tenant-api
|
|
responsible_repo: net-kingdom
|
|
|
|
workload_identity:
|
|
name: example-security-api
|
|
kind: application
|
|
responsible_repo: net-kingdom
|
|
identity_bindings:
|
|
- scheme: iam-profile
|
|
authority: key-cape
|
|
subject: example-security-api
|
|
principal_type: service
|
|
environment: reference
|
|
|
|
tenancy:
|
|
current: {I: 1, A: 2, E: 2, P: 0, R: 1, V: 0}
|
|
implemented: {E: 3}
|
|
target: {I: 2, A: 3, E: 3, P: 1, R: 2, V: 1}
|
|
reviewed: "2026-08-01"
|
|
review_due: "2026-08-31"
|
|
service_class: interactive
|
|
reason:
|
|
I: Request identity is not verified in this reference fixture.
|
|
P: Reference fixture has no provisioned datastore.
|
|
R: Platform default retention applies.
|
|
V: No availability exercise exists.
|
|
gap:
|
|
R: Publish and evidence an explicit erasure horizon.
|
|
|
|
zones:
|
|
standard: security-zones_v0.1
|
|
membership: z1-operational
|
|
responsible_party: team:platform-security
|
|
justification: Reference workload with bounded internal data.
|
|
context:
|
|
maturity: M1
|
|
criticality: medium
|
|
data_classification: internal
|
|
evidence:
|
|
- ref: docs/evidence/reference-zone.md
|
|
supports: [M1, reference]
|
|
reviewed: "2026-08-01"
|
|
review_due: "2026-08-25"
|
|
|
|
evidence:
|
|
A2: docs/evidence/reference-authorization.md
|
|
E2: docs/evidence/reference-adversarial-e2.md
|
|
|
|
evidence_freshness:
|
|
E2:
|
|
kind: adversarial
|
|
observed_at: "2026-08-20T12:00:00Z"
|
|
valid_until: "2026-08-22T12:00:00Z"
|
|
responsible_repo: net-kingdom
|
|
scope: Two bounded cross-tenant read probes against the reference fixture.
|
|
remediation: Repeat the bounded E2 probes and replace the evidence metadata.
|
|
source_revision: reference@0000000
|