Record E2 target applicability constraints

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0260c-4067-7052-9647-ad000d576e38
This commit is contained in:
tegwick 2026-08-22 00:08:23 +02:00
parent cf696f09d5
commit db6b14f764
2 changed files with 56 additions and 0 deletions

View file

@ -151,6 +151,15 @@ route inventories live in `probe-packs/tenant-engine-e2.json` and
`probe-packs/audit-core-e2.json`. The two target runs remain gated on complete
engagement records, owner acknowledgements and executable identity adapters.
Production engagements were operator-approved on 2026-08-21 and committed in
`engagements/`. Audit-core accepted the route/identity shape and reviewed the
adapter; its first review caught a missing idempotency header before traffic,
which is corrected and regression-tested. `docs/target-applicability.md`
records a separate issue: tenant-engine currently exposes no authenticated
tenant-A identity with no tenant-B authority, so its E2 applicability is
pending owner confirmation rather than being faked with its all-tenant service
operator or an unauthenticated actor.
### T04 — Prove the probes fail
```task