whitehat-security/engagements
tegwick 92f23e690b Record clean security workplan cutoff
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0260c-4067-7052-9647-ad000d576e38
2026-08-22 00:24:00 +02:00
..
runtime Add exact audit E2 probe pod 2026-08-22 00:11:06 +02:00
2026-08-21-audit-core-e2.json Record clean security workplan cutoff 2026-08-22 00:24:00 +02:00
2026-08-21-e2-proposals.md Correct audit engagement and idempotent fixture setup 2026-08-22 00:05:15 +02:00
2026-08-21-tenant-engine-e2.json Record clean security workplan cutoff 2026-08-22 00:24:00 +02:00
README.md Build authorization-gated tenancy evidence harness 2026-08-21 23:53:27 +02:00
template.json Build authorization-gated tenancy evidence harness 2026-08-21 23:53:27 +02:00

Engagement records

Copy template.json to a dated, target-specific record and have both the operator and target owner approve it before a live run. The runner validates the record at execution time and fails closed when it is incomplete, expired, outside its window, too permissive, or mismatched to the requested technique or route.

An engagement record contains authorization metadata only. Never put a token, password, database URL, secret path value, or real tenant identifier here.