the-custodian/research
codex e03c280f40 research: close the two gaps — erasure mechanism and noisy-neighbour evidence
Both findings change a level definition in draft-3, so neither is decoration.

R4 had no mechanism. As drafted it meant erasure completes by waiting out a
horizon somebody else's retention set, which is honest and useless as proof.
Crypto-shredding is the established answer: encrypt per entity, destroy the
key, leave the immutable backup unreadable. DPAs have accepted it where
physical deletion is disproportionate; the EDPB has not formally endorsed it,
and R4 should say that rather than imply a clean yes.

The finding underneath it is that shredding granularity is bounded by the key
boundary. Per-consumer shred of logical exports is close - the age lane and
OpenBao already exist. Per-consumer shred of physical backups is not available,
for the same reason retention is not per-consumer. And per-TENANT shred needs
the application to encrypt under a tenant key before writing, which makes the
top of the retention ladder an enforcement-plane capability. That is a third
coupling the ADR does not record.

Also flagged: crypto-shredding an audit trail destroys the evidence audit-core
exists to hold. A naive R4-everywhere target would instruct it to do exactly
that. A question for audit-core, not an answer this framework should give.

The noisy-neighbour artifact asserted something unachievable - that one
consumer saturating its allowance does not breach another's. Azure's first line
of solution text is that the risk cannot be completely avoided. An artifact
that can only fail, or that passes by being run gently, is an overclaim dressed
as evidence. Replaced with characterisation: a recorded baseline, a saturation
run, proof the controls bind, and the measured degradation written down.

That research also reframes the connection ceiling. Seven consumers each
politely inside a 14-connection allowance still exhaust the instance, which is
the aggregate noisy-neighbour shape - so the number in the scaling section is
not a capacity statistic, it is the bound.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 14:37:02 +02:00
..
2026-07-19-work-orchestration-best-practices.md research: work orchestration reconciliation — fleet survey, best practices, architecture draft 2026-07-19 15:21:08 +02:00
2026-07-19-work-orchestration-infrastructure-survey.md research: work orchestration reconciliation — fleet survey, best practices, architecture draft 2026-07-19 15:21:08 +02:00
2026-08-17-adr008-gap-research-erasure-and-noisy-neighbour.md research: close the two gaps — erasure mechanism and noisy-neighbour evidence 2026-08-17 14:37:02 +02:00
2026-08-17-adr008-multi-tenancy-research-index.md research: record the structure-not-tooling stance and the retention design 2026-08-17 14:20:33 +02:00
2026-08-17-adr008-plane-a-authorization.md research: external survey of multi-tenancy practice, one digest per ADR-008 plane 2026-08-17 13:00:02 +02:00
2026-08-17-adr008-plane-e-enforcement.md research: verify pgrls directly; add maturity caveat before recommending adoption 2026-08-17 13:07:41 +02:00
2026-08-17-adr008-plane-i-identity.md research: external survey of multi-tenancy practice, one digest per ADR-008 plane 2026-08-17 13:00:02 +02:00
2026-08-17-adr008-plane-p-placement.md research: external survey of multi-tenancy practice, one digest per ADR-008 plane 2026-08-17 13:00:02 +02:00
WorkOrchestrationArchitectureDraft.md WorkOrchestrationArchitectureDraft v0.2: founder review resolves all 7 open questions 2026-07-20 01:48:15 +02:00