whitehat-security/engagements/README.md
tegwick 3295b715c5 Record the audit-core E2-03 target pass and close T03/T07
Land the sanitized WH-ENG-20260822-AUDIT-E2-03 report, mark the
engagement completed and terminal, and close the applicable E2 harness
and risk-nexus delivery tasks. flex-auth stays pending; tenant-engine
stays not_applicable.

Assistant: grok
Assistant-Session: 01a02670-3345-76f2-a014-70fde8e2a2bb
2026-08-23 00:42:31 +02:00

1.1 KiB

Engagement records

Copy template.json to a dated, target-specific record and have both the operator and target owner approve it before a live run. The runner validates the record at execution time and fails closed when it is incomplete, expired, outside its window, too permissive, or mismatched to the requested technique or route.

An engagement record contains authorization metadata only. Never put a token, password, database URL, secret path value, or real tenant identifier here.

Live admission also requires a matching file in targets/ and a plane lease from whitehat admit-plane. WH-ENG-20260821-AUDIT-E2 and WH-ENG-20260821-TENANT-E2 are cancelled and must not be reused. The pod manifest under runtime/ is bound to a cancelled ID and must not be applied.

WH-ENG-20260822-AUDIT-E2-01 expired unused. WH-ENG-20260822-AUDIT-E2-02 aborted after projection because admit-plane had no receipt adapter; zero packets. WH-ENG-20260822-AUDIT-E2-03 completed as a bounded target pass. Those identifiers may not be reused. Live admission requires --receipt, --contract, and --broker-receipt of WP-0025 documents.