2026-08-21 23:59:29 +02:00
{
"engagement_id" : "WH-ENG-20260821-TENANT-E2" ,
2026-08-22 00:24:00 +02:00
"status" : "cancelled" ,
"cancelled_at" : "2026-08-21T22:18:03Z" ,
"cancellation_reason" : "Session cutoff: E2 attacker-model applicability and target-owner acknowledgement remained unresolved. Zero target requests were sent." ,
2026-08-21 23:59:29 +02:00
"authorization_id" : "operator-session-2026-08-21-e2-approval" ,
"authorizer" : "repository operator and infrastructure owner" ,
"approved_at" : "2026-08-21T21:56:00Z" ,
"expires_at" : "2026-08-21T22:35:00Z" ,
"target" : "http://tenant-engine.tenant-engine.svc.cluster.local:8090" ,
"target_owner" : "tenant-engine / infrastructure operator" ,
2026-08-22 00:11:50 +02:00
"target_owner_acknowledged_at" : null ,
2026-08-22 00:24:00 +02:00
"target_owner_acknowledgement_status" : "not obtained before cancellation; E2 attacker-model applicability remains unresolved" ,
2026-08-21 23:59:29 +02:00
"environment" : "production" ,
"production_approval" : "Explicit user approval of engagements/2026-08-21-e2-proposals.md in the coordinating session" ,
"namespace" : "tenant-engine" ,
"source" : "dedicated pod user-engine/whitehat-e2-tenant, labelled and attributed with this engagement id" ,
2026-08-22 00:04:02 +02:00
"control_plane_scope" : [
"GET apps/v1 deployment tenant-engine/tenant-engine for target revision only" ,
"GET v1 service tenant-engine/tenant-engine for target identity only" ,
"CREATE/GET/DELETE v1 pod user-engine/whitehat-e2-tenant only" ,
"GET pod log user-engine/whitehat-e2-tenant only"
] ,
2026-08-21 23:59:29 +02:00
"routes" : [
"GET /health" ,
"POST /tenants" ,
"GET /tenants/{tenant_id}" ,
"GET /tenants/{tenant_id}/roles" ,
"GET /tenants/{tenant_id}/roles/live" ,
"GET /tenants/{tenant_id}/guardrails" ,
"POST /tenants/{tenant_id}/roles/grant" ,
"POST /tenants/{tenant_id}/roles/revoke" ,
"POST /tenants/{tenant_id}/plan" ,
"PATCH /tenants/{tenant_id}" ,
"POST /tenants/{tenant_id}/retire" ,
"POST /tenants/{tenant_id}/reactivate" ,
"POST /tenants/{tenant_id}/grouping" ,
"PUT /tenants/{tenant_id}/guardrails/{limit_key}" ,
"DELETE /tenants/{tenant_id}/guardrails/{limit_key}"
] ,
"fixture_ids" : [
"whitehat-e2-a-20260821" , "tenant:trial:whitehat-e2-a-20260821" ,
"whitehat-e2-b-20260821" , "tenant:trial:whitehat-e2-b-20260821" ,
"whitehat-e2-absent-20260821"
] ,
"credential_lane" : "projected Kubernetes service identity from the existing user-engine ingress class; no credential value retained" ,
"credential_role" : "ordinary user-engine caller with target-owner-confirmed flex-auth policy" ,
"credential_max_ttl_seconds" : 900 ,
"techniques" : [ "e2-differential" ] ,
"prohibited_techniques" : [
"discovery" , "direct-database-access" , "saturation" , "large-payload" ,
2026-08-22 00:04:02 +02:00
"real-data-collection" , "adjacent-service-follow-up" ,
"any control-plane operation outside control_plane_scope"
2026-08-21 23:59:29 +02:00
] ,
"rate_limit_per_minute" : 10 ,
"max_concurrency" : 1 ,
"maximum_requests" : 60 ,
"window_start" : "2026-08-21T22:20:00Z" ,
"window_end" : "2026-08-21T22:35:00Z" ,
"operator_contact" : "repository operator in coordinating session" ,
"abort_contact" : "repository operator in coordinating session" ,
"abort_thresholds" : {
"p95_latency_ms" : 500 ,
"probe_attributable_5xx" : 1 ,
"unexpected_or_non_fixture_data" : 1 ,
"missing_attribution" : 1
} ,
"posture_claim" : "implemented E2; currently evidenced E1" ,
"attacker_model" : "E2-authenticated-tenant-a" ,
"finding_destination" : "risk-nexus"
}