feat: deliver approved factory audit sender custody
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
fe1b1c5fe2
commit
44314cad37
7 changed files with 411 additions and 8 deletions
|
|
@ -3,7 +3,7 @@ kind: credential-change-request
|
|||
schema_version: 1
|
||||
request_type: workload-kv-read
|
||||
title: approval-engine load-bearing audit sender custody and delivery
|
||||
status: approved
|
||||
status: applied
|
||||
created: '2026-09-11'
|
||||
updated: '2026-09-11'
|
||||
requester:
|
||||
|
|
@ -107,6 +107,19 @@ verification:
|
|||
blindly rotates or deletes.
|
||||
- Record native positive/negative evidence before declaring verified or active.
|
||||
Custody alone does not admit UI, human approval or factory execution.
|
||||
evidence:
|
||||
- at: '2026-09-11T07:32:51+00:00'
|
||||
actor: codex via attended user platform-admin
|
||||
kind: factory_audit_initial_custody
|
||||
result: passed
|
||||
details:
|
||||
- Both independently generated sender credentials persisted at version 1 with
|
||||
exact request provenance. Shared registry CAS advanced from version 7 to 8;
|
||||
existing senders and registry fields preserved.
|
||||
- 'Attended retry completed with exit 0 and confirmed self-revocation. Receipt:
|
||||
docs/evidence/2026-09-11-factory-audit-sender-seed.json.'
|
||||
- 'Status applied: native ESO delivery, scope verification, receiver reload and
|
||||
producer acceptance remain.'
|
||||
lifecycle:
|
||||
deactivate: Stop the exact producer; remove only its admitted token from the registry
|
||||
using CAS and reload/verify receiver refusal. Then detach its reader policy and
|
||||
|
|
|
|||
|
|
@ -3,7 +3,7 @@ kind: credential-change-request
|
|||
schema_version: 1
|
||||
request_type: workload-kv-read
|
||||
title: informed-decision load-bearing audit sender custody and delivery
|
||||
status: approved
|
||||
status: applied
|
||||
created: '2026-09-11'
|
||||
updated: '2026-09-11'
|
||||
requester:
|
||||
|
|
@ -108,6 +108,19 @@ verification:
|
|||
blindly rotates or deletes.
|
||||
- Record native positive/negative evidence before declaring verified or active.
|
||||
Custody alone does not admit UI, human approval or factory execution.
|
||||
evidence:
|
||||
- at: '2026-09-11T07:32:51+00:00'
|
||||
actor: codex via attended user platform-admin
|
||||
kind: factory_audit_initial_custody
|
||||
result: passed
|
||||
details:
|
||||
- Both independently generated sender credentials persisted at version 1 with
|
||||
exact request provenance. Shared registry CAS advanced from version 7 to 8;
|
||||
existing senders and registry fields preserved.
|
||||
- 'Attended retry completed with exit 0 and confirmed self-revocation. Receipt:
|
||||
docs/evidence/2026-09-11-factory-audit-sender-seed.json.'
|
||||
- 'Status applied: native ESO delivery, scope verification, receiver reload and
|
||||
producer acceptance remain.'
|
||||
lifecycle:
|
||||
deactivate: Stop the exact producer; remove only its admitted token from the registry
|
||||
using CAS and reload/verify receiver refusal. Then detach its reader policy and
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue