Record operator approval of the two factory audit sender lanes
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-11 06:47:35 +02:00
parent 0adc5b0e49
commit 5cc325b744
6 changed files with 155 additions and 106 deletions

View file

@ -1,11 +1,13 @@
# Factory audit senders: concrete custody review
CCR-2026-0021 and CCR-2026-0022 are **proposed**. RPF-WP-0035-T08 owns the
platform work; AUDIT-WP-0009-T09/T11 retain receiver admission. This packet
requires the named platform operator, Audit Core owner and each producer owner
to approve its request before native credential mutation.
CCR-2026-0021 and CCR-2026-0022 are **approved** by the user on 2026-09-11,
replying "good, go on" to the explicit question naming the platform operator,
Audit Core owner, and each producer owner. The source review comments and the
two existing State Hub decisions record that approval. RPF-WP-0035-T08 owns
platform execution; AUDIT-WP-0009-T09/T11 retain receiver admission. Approval
alone does not mark custody delivered or either producer admitted.
## Scope to approve
## Approved scope
| Request | Producer / exact source | OpenBao path | Producer Secret / key |
| --- | --- | --- | --- |
@ -24,7 +26,7 @@ log in to the reader role (15-minute session). Neither producer can read the
full sender registry or its sibling's token. The coding-agent boundary gains
exact denies on the two new data/metadata paths; existing rules are preserved.
The approved first-provision operation would generate two independent values
The approved first-provision operation generates two independent values
in the attended platform process, store them with CAS=0, and append the exact
identities to `platform/workloads/audit-core/senders` with compare-and-set on
its observed KV version. That process necessarily reads the existing registry