feat: deliver approved factory audit sender custody
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-11 09:38:27 +02:00
parent fe1b1c5fe2
commit 44314cad37
7 changed files with 411 additions and 8 deletions

View file

@ -3,7 +3,7 @@ kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: approval-engine load-bearing audit sender custody and delivery
status: approved
status: applied
created: '2026-09-11'
updated: '2026-09-11'
requester:
@ -107,6 +107,19 @@ verification:
blindly rotates or deletes.
- Record native positive/negative evidence before declaring verified or active.
Custody alone does not admit UI, human approval or factory execution.
evidence:
- at: '2026-09-11T07:32:51+00:00'
actor: codex via attended user platform-admin
kind: factory_audit_initial_custody
result: passed
details:
- Both independently generated sender credentials persisted at version 1 with
exact request provenance. Shared registry CAS advanced from version 7 to 8;
existing senders and registry fields preserved.
- 'Attended retry completed with exit 0 and confirmed self-revocation. Receipt:
docs/evidence/2026-09-11-factory-audit-sender-seed.json.'
- 'Status applied: native ESO delivery, scope verification, receiver reload and
producer acceptance remain.'
lifecycle:
deactivate: Stop the exact producer; remove only its admitted token from the registry
using CAS and reload/verify receiver refusal. Then detach its reader policy and

View file

@ -3,7 +3,7 @@ kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: informed-decision load-bearing audit sender custody and delivery
status: approved
status: applied
created: '2026-09-11'
updated: '2026-09-11'
requester:
@ -108,6 +108,19 @@ verification:
blindly rotates or deletes.
- Record native positive/negative evidence before declaring verified or active.
Custody alone does not admit UI, human approval or factory execution.
evidence:
- at: '2026-09-11T07:32:51+00:00'
actor: codex via attended user platform-admin
kind: factory_audit_initial_custody
result: passed
details:
- Both independently generated sender credentials persisted at version 1 with
exact request provenance. Shared registry CAS advanced from version 7 to 8;
existing senders and registry fields preserved.
- 'Attended retry completed with exit 0 and confirmed self-revocation. Receipt:
docs/evidence/2026-09-11-factory-audit-sender-seed.json.'
- 'Status applied: native ESO delivery, scope verification, receiver reload and
producer acceptance remain.'
lifecycle:
deactivate: Stop the exact producer; remove only its admitted token from the registry
using CAS and reload/verify receiver refusal. Then detach its reader policy and