Skip to content

[CT-804] Audit and replay historical action legality #98

Description

@flyingrobots

ADR-THINK-001 · Delivery plan · Complete issue catalog

Milestone: ADR-THINK-001 P8 — Action bridge and production cutover

Feature: F8.2 — Revocation, compensation, audit, and cutover

Outcome

An auditor can reproduce why an action was lawful at its evidence frontier and separately evaluate it under current evidence and policy without conflating the two judgments.

User stories

  • As a auditor, I want a complete causal chain from source through authorization to effect and aftermath, so that I can distinguish lawful-at-the-time execution from later-discovered harm.
  • As a Think user, I want a current reevaluation that leaves the historical record intact, so that the system can acknowledge a changed mind without gaslighting me about the past.

Deliverables

  • Historical action audit query and typed replay plan.
  • Causal trace across captures, observations, attempts, claims, relations, authority, answer, authorization, execution, and later outcomes.
  • Current-policy and current-evidence reevaluation mode with explicit comparison.
  • Erasable audit payloads and durable structural audit witness.

Acceptance criteria

  • Historical replay uses only evidence, policy, judgments, and receipts available at the action frontier.
  • Current reevaluation is labeled as a new reading and authority question.
  • The audit distinguishes authorization legality, execution conformance, external outcome, later revocation, compensation, and incident.
  • Erased source content remains unavailable while the minimal causal structure and tombstones remain auditable.

Test plan

Contract and unit

  • Audit tests cover historical/current modes, every causal layer, temporal clocks, erasure, and comparison output.

Integration and acceptance

  • The simulated action suite replays lawful, denied, failed, revoked, compensated, and incident cases.

Failure and recovery

  • Future leakage, latest-policy substitution, missing receipt, broken causal link, unauthorized view, and erased-payload reconstruction fail.

Resource and performance

  • Trace traversal streams bounded references and rejects cycles or fan-out above the declared budget.

Security, privacy, and erasure

  • Audit access controls, redaction, payload grants, signer verification, and erasure survive adversarial fixtures.

Build-time resources

Resource Exclusivity mode Scope
historical-action-auditor exclusive Replay, comparison, and structural witness implementation.
action-audit-query-schema exclusive Typed historical/current audit requirements.
action-trace-partitions partitioned Disjoint authorization and causal-frontier traces.
canonical-mind-and-action-history shared Read-only causal inputs at selected frontiers.
audit-payload-vault exclusive Erasable report and quotation payload grants.
  • exclusive: Only one active slice may mutate or lease the named resource.
  • partitioned: Concurrent writes are lawful only in disjoint partitions named by each slice.
  • shared: Concurrent read-only use is lawful; this slice does not mutate the resource.

Dependencies

ADR traceability

  • Implementation gates: None directly
  • Constitutional invariants: I3, I5, I6, I9, I10, I17
  • ADR acceptance criteria: AC5, AC13, AC14, AC19, AC28, AC30, AC32, AC35

Non-goals

  • Do not judge historical legality with evidence that did not yet exist unless current reevaluation is explicitly requested.
  • Do not recover erased content to make an audit more narratively complete.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions