Meantime polish while live E2 waits on a new trial. Example receipts carry handles only. admit-plane --receipt is tested. Aborts can be queued without being target assurance. Assistant: grok Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb |
||
|---|---|---|
| .. | ||
| receipts | ||
| runtime | ||
| 2026-08-21-audit-core-e2.json | ||
| 2026-08-21-e2-proposals.md | ||
| 2026-08-21-tenant-engine-e2.json | ||
| 2026-08-22-audit-core-e2-02.json | ||
| 2026-08-22-audit-core-e2-02.md | ||
| 2026-08-22-audit-core-e2.json | ||
| 2026-08-22-audit-core-e2.md | ||
| 2026-08-22-plane-provision.md | ||
| README.md | ||
| template.json | ||
Engagement records
Copy template.json to a dated, target-specific record and have both the
operator and target owner approve it before a live run. The runner validates
the record at execution time and fails closed when it is incomplete, expired,
outside its window, too permissive, or mismatched to the requested technique
or route.
An engagement record contains authorization metadata only. Never put a token, password, database URL, secret path value, or real tenant identifier here.
Live admission also requires a matching file in targets/ and a plane lease
from whitehat admit-plane. WH-ENG-20260821-AUDIT-E2 and
WH-ENG-20260821-TENANT-E2 are cancelled and must not be reused. The pod
manifest under runtime/ is bound to a cancelled ID and must not be applied.
WH-ENG-20260822-AUDIT-E2-01 expired unused. WH-ENG-20260822-AUDIT-E2-02
aborted after projection because admit-plane had no receipt adapter; zero
packets. Neither identifier may be reused. Live admission requires
--receipt of a value-safe custody projection.