# Source-owned declaration for the qonto-assistant structured audit stream. # The semantic shape follows the Taxonomy draft in # kings-guard/specs/EmissionCadenceDeclaration.md. This repository owns the # concrete emission claim even while the fleet-wide schema remains a draft. audit_emission_cadence: schema_version: "0.1" source: qonto-assistant stream_id: qonto-assistant.audit transport: structured-stdout instance_boundary: process ordering: instance_field: stream_instance_id sequence_field: stream_sequence sequence_starts_at: 1 gap: finding reset: permitted-only-when-stream_instance_id-changes event_classes: audit.allow: evidence_class: attributive completeness_claimed: false audit.deny: evidence_class: load-bearing form: heartbeat-or-reconciliation rate_monitoring: forbidden completeness_claimed: true audit.heartbeat: evidence_class: load-bearing role: positive-liveness-and-reconciliation-claim heartbeat: event_class: audit.heartbeat interval: PT24H interval_config: QONTO_AUDIT_HEARTBEAT_INTERVAL_SECONDS default_interval_seconds: 86400 lifecycle: startup: required periodic_while_process_active: required shutdown: best-effort quiet_assertion: nothing-to-report active_instance_missing: finding scale_to_zero_semantics: > No periodic heartbeat is promised while no process instance exists. Observers track each stream_instance_id from its startup heartbeat until a shutdown heartbeat or expiry after a missing active-instance cadence. reconciliation: source_counts_field: source_transition_counts window_counts_field: window_transition_counts counted_classes: - audit.allow - audit.deny snapshot_endpoint: /v1/audit/reconciliation compare_observed: > Count received request events by event_class and stream_instance_id, then compare them with the heartbeat source counts and stream sequence. divergence: finding undrained_local: lag-not-divergence persistence: process-local event_context: identity_binding_field: identity_binding egress_destination_field: egress_destination qonto_egress_destination: qonto-thirdparty-api