the-custodian/canon/architecture
codex c4f22a5e55 ADR-008 draft-4: apply the eight amendments the gap research forced
R4 now has a mechanism. It splits into horizon-elapsed (wait out a window
somebody else's retention set - available to all, proves little) and
key-destroyed (encrypt per entity, destroy the key, immediate). A service must
name which route it uses.

The regulatory position is stated rather than implied: DPAs have accepted key
destruction as erasure where physical deletion is disproportionate, under
conditions, and the EDPB has not formally endorsed it. Section 11.4 now says a
service may make that claim but not in language implying a regulator blessed
it. Overclaiming here would be worse than anywhere else in the document.

Third coupling recorded: shredding a single tenant's data needs the application
to encrypt under a per-tenant key before writing, so the top of the retention
ladder is an enforcement-plane capability. Reaching R4 is not a retention
project.

The noisy-neighbour artifact was replaced. It had required proof that a
saturating consumer does not breach another's allowance, which shared
infrastructure cannot provide - an artifact that can only fail, or passes by
being run gently, is an overclaim in the costume of evidence. It now measures:
baseline, saturation run, proof the controls bind, recorded degradation.
Generalised as decision 13.4.

The connection ceiling is reframed. Seven consumers each politely inside a
14-connection allowance still exhaust the instance, so the number is the
aggregate noisy-neighbour bound, and our per-consumer governance guards the
other shape entirely.

Also: quota transparency as a disclosure obligation (10.2) - a consumer
learning its statement timeout by hitting it in production is our failure, not
theirs; and two new open questions - crypto-shredding an audit trail destroys
what audit-core exists to hold, and we have no QoS vocabulary despite a
latency-critical consumer sharing an instance with a batch one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 14:49:00 +02:00
..
adr-001-workplans-as-repo-artefacts.md feat(terminology): prose sweep tool and custodian workplan cleanup (CUST-WP-0055 T04) 2026-07-08 16:35:37 +02:00
adr-002-custodian-agent-runtime-design.md feat(CUST-WP-0001): implement Custodian Agent Runtime bootstrap 2026-03-12 22:36:24 +01:00
adr-003-materialized-derived-state.md docs(adr): ADR-003 — Materialized Derived State with Fingerprint Invalidation 2026-03-20 01:54:21 +01:00
adr-004-connectivity-first-network-posture.md ADR and Runbook artefacts 2026-03-27 00:16:09 +01:00
adr-005-cross-repo-workplans-project-repos.md docs(canon): define prj- project repository flavor 2026-08-09 17:24:07 +02:00
adr-006-canon-federation-concept-ownership.md docs(canon): ADR-006 accepted — R7 places evidence pair in dedicated itc-evid 2026-08-17 10:03:15 +02:00
adr-007-workplan-identity-and-repo-worker-topology.md docs(canon): renumber ADR-008/009 -> ADR-010/011 after ID collision 2026-08-17 13:04:04 +02:00
adr-008-multi-tenancy-model.md ADR-008 draft-4: apply the eight amendments the gap research forced 2026-08-17 14:49:00 +02:00
adr-010-hub-authority-and-local-cache-model.md docs(canon): renumber ADR-008/009 -> ADR-010/011 after ID collision 2026-08-17 13:04:04 +02:00
adr-011-federated-namespaces-and-reconciliation-limits.md docs(canon): renumber ADR-008/009 -> ADR-010/011 after ID collision 2026-08-17 13:04:04 +02:00