Implement TEN-WP-0011 security layer conformance
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 37s

Engine/PIP declaration is now checkable (layer.yaml plus a Tooling-client
scan). Writes persist a decision record or the published fail-closed
stance, live-lookup freshness is published, events_for is tenant-scoped,
and mutation evidence drains to audit-core from a local outbox without
blocking the mutation.

Sender registration is requested as AUDIT-IN-0002. Boundary-contract
amendment is requested as NET-IN-0002.

Assistant: grok
Assistant-Session: 01a04cea-e5e8-7081-a0fc-808ebbc35fa9
This commit is contained in:
tegwick 2026-08-29 13:02:51 +02:00
parent 80961af91e
commit 672cf4da6e
40 changed files with 2285 additions and 361 deletions

View file

@ -13,7 +13,7 @@ kind: intake
title: "Externalize tenant-engine audit evidence to audit-core"
lane: yellow
status: closed
outcome: promoted
outcome: completed
promoted_to: TEN-WP-0011-T04
priority: high
owner: tenant-engine
@ -58,7 +58,7 @@ kind: intake
title: "Remove or authorize the tenant-engine unfiltered event-read interface"
lane: red
status: closed
outcome: promoted
outcome: completed
promoted_to: TEN-WP-0011-T05
priority: high
owner: tenant-engine