Sweep risk inbox and reconcile findings

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
This commit is contained in:
tegwick 2026-09-01 02:41:32 +02:00
parent d65aaf7484
commit 7f1424dbcf
12 changed files with 363 additions and 96 deletions

View file

@ -2,7 +2,8 @@
id: RISK-F-0007
type: finding
title: "No consumer's tenant boundary is verified anywhere"
status: accepted
status: fixed
owner: risk-nexus
reported_by: net-kingdom
reported_via: risk-nexus
routed_by: risk-nexus
@ -20,10 +21,16 @@ impact: I3
likelihood: L3
fidelity_modifier: false
production_rescore: true
disclosure: embargoed
embargo_condition: "a verification exists for at least one consumer boundary"
embargo_since: "2026-08-19"
embargo_review: "2026-09-18"
disclosure: public
publication: pending-handover
publication_id: risk-f-0007-unverified-tenant-boundaries
publication_path: "findings/unverified-tenant-boundaries/v1/index.html"
publication_subtitle: "No consumer tenant boundary had ever been verified; three independent consumers now carry negative boundary evidence."
revision: "fixed-1"
last_reviewed: "2026-09-01"
review_interval: 6m
embargo_lifted: "2026-08-22 — Audit Core completed a bounded adversarial E2 tenant-isolation run; additional Tenant and User Engine tests corroborate the control class"
embargo_was_since: "2026-08-19"
escalation: answered
escalation_trigger: 4
escalation_status: assigned
@ -34,20 +41,14 @@ accepted_by: the-custodian
accepted_on: "2026-08-19"
accepted_until: "production transition (hard expiry, not a date)"
decision: "pragmatic default before production — carried unverified; verification of a named consumer boundary on request"
last_checked: "2026-08-21T07:32:10Z"
next_check: "2026-08-21T08:32:10Z"
cadence: 1h
clean_streak: 1
waiting_on:
- who: user-engine
what: "does anything verify that a caller for tenant A cannot reach tenant B (RISK-V-0002)"
since: "2026-08-20"
would_change: "likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not"
default: "the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated"
default_at: "2026-09-03"
date_fixed: "2026-08-22"
last_checked: "2026-09-01T00:32:44Z"
next_check: "2026-09-01T00:32:44Z"
cadence: instant
clean_streak: 0
graded_by: risk-nexus
ruling: RISK-RULING-2026-08-19-B
checked_by: "risk-nexus"
checked_by: "codex/risk-nexus"
---
# RISK-F-0007 — nothing checks that tenants stay apart
@ -184,3 +185,19 @@ assumption that asking works.
Grade unchanged. Nothing about the boundary itself has moved.
- **2026-08-20** — not clean: On-request verification walked for the first time: RISK-V-0002 asks user-engine. Cadence instant → instant; checked again immediately.
- **2026-08-21** — clean check: no answer yet from user-engine; nothing about the boundary moved. Cadence instant → 1h (1 clean in a row); next check 2026-08-21 08:32Z.
## Closure — 2026-09-01: the zero-verification claim is no longer true
The embargo and the finding were deliberately phrased around one observable
condition: a verification existing for at least one consumer boundary. Audit
Core now has stronger evidence than that minimum—a bounded adversarial
production E2 run—and its current focused suite passes 60 tests. Tenant Engine's
dedicated scoped-event suite passes 3 tests, and User Engine's current
multi-tenancy, access-profile, and integrated-scenario suites pass 18 tests.
This does not assert that every consumer boundary is correct. It closes the
precise estate-wide absence this finding recorded; any consumer-specific gap is
filed separately. The unanswered User Engine wait is replaced by direct current
evidence, status moves from accepted to `fixed`, and the embargo lifts.
- **2026-09-01** — not clean: three consumer boundaries now carry current negative evidence, including one production E2 artifact; status fixed and embargo lifted. Cadence 1h → instant; checked again immediately.