Skip to content

Production security-audit composition and external custody #351

Description

@samovers

Parent Tracking Epic: #167

Status

Tracking Epic. Parked and blocked. Created by the proportional-workflow tracker migration to separate production-composition follow-ups from #192's bounded pre-tenant audit implementation outcome.

This epic owns no implementation pull request and grants no provider, credential, deployment, or production authority.

Outcome

Make the security-audit capability eligible for a later production composition only through separately reviewable capabilities with explicit custody, provider, and deployment evidence.

Why this is separate from #192

The accepted #192 closure record classifies production provider/clock/secret-custody evidence, protected export delivery, and source/execution-root governance as follow-ups rather than #192 closure Blockers. Keeping them in #192 would make its closure depend on work expressly excluded from that issue.

Capability map

  1. Capture authenticated, controlled provider evidence for the observer-root resource forms. Design history is preserved in closed-unmerged PR docs: govern observer-root provider evidence capture #323.
  2. Bind accepted observer-root deny resources to exact policy attachment points using that provider evidence. Design history is preserved in closed-unmerged PR [Phase A] Bind observer-root deny resources to policy attachments #322 and remains blocked by capability 1.
  3. Prove production clock, timer, route, provider, and secret-custody composition.
  4. Define protected export-output custody and delivery.
  5. Complete remaining execution-root and source-capability governance needed for deployment claims.

Each capability must receive its own Delivery issue only when its prerequisites are real. Each Delivery issue must own one complete vertical-slice PR; Phase-A-only publication PRs are not delivery units.

Boundaries

No provider call, fixture provisioning, organization or IAM mutation, credential issuance, production data access, database authority, export delivery, deployment, release, current-compliance claim, #192 closure change, or waiver is authorized here.

Historical designs and reviews may inform later Phase A work, but no approval or evidence transfers automatically to replacement work.

What is next: keep this epic parked until a concrete production requirement and its external prerequisites exist, then activate only the first coherent Delivery child.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    blockedCannot proceed until a named prerequisite or authority is satisfied.parkedDeliberately deferred; not currently actionable.tracking-epicProgramme containing multiple independently reviewable capabilities; owns no implementation PR.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions