diff --git a/docs/evidence/security-zone-adoption-2026-08-22.md b/docs/evidence/security-zone-adoption-2026-08-22.md index 14684bc..183ae3f 100644 --- a/docs/evidence/security-zone-adoption-2026-08-22.md +++ b/docs/evidence/security-zone-adoption-2026-08-22.md @@ -27,11 +27,11 @@ `decision:f3f7c88f9585582a`. Only token length and a truncated fingerprint were emitted. -The operator's persistent `warden.yaml` still contains the two retired keys. -The live proof used a temporary migrated copy; no operator configuration was -overwritten. Until those lines are removed, the new loader rejects that file -with an explicit migration error rather than silently selecting a second -policy source. +The operator's `warden.yaml` was migrated from the two retired keys to the +compiled `zone_registry_path`. The live proof was then repeated successfully +against that real configuration. The new loader continues to reject either +retired key with an explicit migration error rather than silently selecting a +second policy source. The exception-lifecycle evidence in `docs/exception-lifecycle-2026-08-22.md` establishes that expiry is evaluated