risk-nexus/findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md
tegwick aa0a85b893 Apply due defaults: escalate RISK-F-0011 stall, settle C-31 as noise
RISK-F-0011: KG-WP-0005-T03 still waits on a deployed capture; medium grade
stands, stall recorded, escalated to the-custodian under trigger 5.
RISK-WP-0001: C-31 documented as expected noise. RISK-F-0008 acceptance
review recorded clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 08:13:56 +02:00

173 lines
8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
id: RISK-F-0011
type: finding
title: "qonto-assistant audit.deny stream completeness is not established"
status: open
owner: risk-nexus
reported_by: kings-guard
reported_via: gate-house
routed_by: gate-house
date_reported: "2026-09-01"
date_filed: "2026-09-02"
system: qonto-assistant
environment: production
fix_owner: qonto-assistant
fix_tracking: QONTO-WP-0005 / KG-WP-0005-T03
closure_condition: "authorized deployed-instance capture accepted by kings-guard: heartbeat timing, sequence continuity and same-instance reconciliation"
verification: RISK-V-0003
# Graded by risk-nexus 2026-09-02 — docs/rulings/2026-09-02-qonto-deny-stream.md
severity: medium
severity_at_production: medium
impact: I2
likelihood: L3
fidelity_modifier: false
production_rescore: false
disclosure: public
publication: pending-handover
publication_id: risk-f-0011-qonto-audit-deny-stream-completeness
publication_path: "findings/qonto-audit-deny-stream-completeness/v1/index.html"
publication_subtitle: "A live deny was observed on qonto-assistant, but nothing yet lets anyone claim the load-bearing deny stream is complete."
revision: "graded-1"
last_reviewed: "2026-09-02"
review_interval: 6m
escalation: pending
escalation_trigger: 5
escalation_status: sent
escalation_sent: "2026-09-22"
last_checked: "2026-09-22T06:13:33Z"
next_check: "2026-09-22T06:13:33Z"
cadence: instant
clean_streak: 0
graded_by: risk-nexus
ruling: RISK-RULING-2026-09-02-A
checked_by: "worsch"
---
# RISK-F-0011 — qonto-assistant audit.deny stream completeness is not established
## What is true, as reported
King's Guard observed real `qonto-assistant` allow and deny events emitted by
`audit.AuditLogger` through `CapabilityService`. One deny (`list_transactions`
over MCP, `arg_constraint`) arrived with record richness 90 and preserved
origin linkage. Gate House accepted that mapping and recorded the qonto lane
as staffed for observation.
The same return says the `audit.deny` class is load-bearing, and that its
**stream completeness is unknown**:
- no heartbeat or emission-cadence declaration is published;
- no reconciliation view was supplied;
- richness 90 describes the received record, not the stream;
- no claim is made that every deny was emitted or observed.
This is not evidence that an event was suppressed. The reporter assigned no
severity and asked this register to intake, grade, and route.
Safe evidence named by Gate House: kings-guard revision `9daea96`; source
return `23480b81-bc34-4df4-92cc-840fbc8514fd`; Gate House disposition
`no_change` at commit `feff576` and
`gate-house/docs/conformance/2026-09-02-kings-guard-qonto-live-observation.md`.
The owner route `3b9c26a1-ba1a-4189-b439-edd61683aed5` was unread at intake.
## How it was found
Live observation, not a self-assessment. King's Guard completed
`KG-WP-0003-T06/T07` against the real qonto-assistant lane. Gate House reviewed
the return under `GH-WP-0001-T06` and routed the implementation residual here
on 2026-09-01 (message `53645a75-0215-4261-a700-f7aedf09e7e8`).
## What a current-source check adds
The local lockout does **not** consume the audit stream. `DenyEscalationTracker`
is in-process state on the decision path (`CapabilityService` calls
`record_deny` / `check` directly; `AuditLogger.emit` is a parallel record).
A dropped audit line would not, on today's source, disable qonto-assistant's
own Fast Local Loop.
What the stream is load-bearing *for* is estate observation. King's Guard
already consumes it. Without a cadence declaration or a reconciliation view,
that observation can report a received deny and cannot vouch that every deny
was emitted.
No heartbeat, emission-cadence, or reconciliation artefact was found in
qonto-assistant at filing. `fix_tracking` is unset.
Taxonomy ownership of an emission-cadence declaration (net-kingdom /
info-tech-canon) is a separate residual. This record does not wait on it:
depth-one, and one routing exchange has not yet failed. Silence there does not
change qonto-assistant's obligation to declare what it emits, or this grade.
## Suggested direction
Suggestion, owned by `qonto-assistant`:
1. Publish a heartbeat or emission-cadence declaration for `audit.deny`.
2. Supply a reconciliation view an observer can use to test completeness.
3. Open fix tracking, or reject the obligation in writing so observation stays
explicitly incomplete.
Risk Nexus owns severity, disclosure, escalation, and review cadence.
## Register ruling — 2026-09-02
`medium` (`I2` × `L3`), public, no escalation.
**`I2`: one system's observation of one deny class.** A missed audit.deny
does not, on the facts established, authorize a Qonto action or disable the
in-process lockout. It leaves estate observation unable to treat the stream as
complete. That is confined to the qonto-assistant lane.
**`L3`: the gap is the current state of a stream the working set already
consumes.** King's Guard reached the stream with no additional step and still
could not complete the claim. This is not `L4`: suppression is not established,
and the band is scored on the missing completeness evidence, not on an
unobserved drop. It is not `L2`: waiting for a special foothold would describe
the wrong defect.
**No fidelity modifier.** The observer reported completeness as unknown. A
later claim that the stream is complete without a cadence or reconciliation
view would be the lying-control state; that is not today's headline.
**Disclosure `public`.** Reading this does not shorten a path to a defect. It
is a missing completeness claim, published as one. Handover to `policy-nexus`
is `pending-handover`.
**No escalation.** No real-person data exposure, no new outside obligation, no
new spend, no failed ownership exchange, and no fourteen-day stall. The dated
wait makes that last statement expire.
Reasoning: `docs/rulings/2026-09-02-qonto-deny-stream.md`.
## Source remediation reconciled — 2026-09-05
The missing-source statements above describe intake, not the current checkout.
QONTO-WP-0005 is finished: cadence, heartbeat lifecycle, instance/sequence fields
and an identity-checked reconciliation view now exist. King's Guard's local
source-path checks are recorded complete, but KG-WP-0005-T03 waits for an
authorized deployed capture. Notice `c6442eef-34fc-46a7-9639-10f2cd6120fc`
explicitly requests independent deployed-stream acceptance before closure.
[RISK-V-0003](../docs/verifications/2026-09-05-open-findings-source-review.md)
records the inspected evidence and bounded acceptance requirements. Status
remains open, medium, public, no escalation: deployed completeness is still
unknown, with no evidence of suppression or an authorization bypass. The
2026-09-16 default is retained, now describing the actual remaining obligation.
## Default applied and escalated — 2026-09-22
qonto-assistant did not supply the deployed-instance capture by 2026-09-16.
KG-WP-0005-T03 is still `wait`; its 2026-09-21 change was a hub-id writeback,
not evidence. The default applies: the medium grade stands, the missing
deployed acceptance is recorded as a stalled remediation, and observation stays
staffed with completeness pending. The finding has sat at `instant` since
2026-09-05, more than fourteen days, so escalation trigger 5 fires. The
escalation went to the-custodian today and asks who authorizes and runs the
deployed capture. Default if unanswered by 2026-09-29: raise once more, then
record the stall as accepted by silence. The grade does not change.
## Reviews
- **2026-09-02** — graded from the Gate House intake, the named conformance review, and a current-source check of qonto-assistant. Local lockout is in-process; the emitted deny stream still has no cadence or reconciliation view. Cadence starts at instant.
- **2026-09-05** — not clean: Reviewed owner notice, cadence/logger/endpoint and KG-WP-0005; source remediation exists, deployed-instance acceptance remains pending under KG-WP-0005-T03. See RISK-V-0003. Cadence instant → instant; checked again immediately.
- **2026-09-22** — not clean: Default applied: KG-WP-0005-T03 still wait, no deployed capture; stall recorded; escalated to the-custodian under trigger 5 Cadence instant → instant; checked again immediately.