Table of contents
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
OpenSpec 103 — Forge identity lifecycle audit
Status: proposed
Version: 0.1.0
Session: Ting/Jostoph#103
Epics: Ting/Ting#60, Jostoph#84
Proposal
Jostoph independently ingests and correlates lifecycle evidence across OpenBao, Vedanta, Kanidm, the adapter, and Forgejo. It reports missing, contradictory, pending, and drifted state without identity authority and without credential values.
Design
The formal package is under openspec/changes/forge-identity-lifecycle-audit. The complete source package is pinned in references/canonical/ with the common manifest. OpenSpec 61 remains governing.
This package amends the older #70/#84 vocabulary: Vedanta is a private effector in this lifecycle, not the ruling authority. Jostoph observes and joins evidence; it does not mint, revoke, activate, or infer success.
Tasks
- #104 — define the canonical lifecycle audit envelope.
- #106 — authenticate, validate, and durably append lifecycle events.
- #107 — materialize the lifecycle correlation view.
- #108 — prove replay, duplicate, restart, and quarantine behavior.
- #105 — detect canonical lifecycle drift C01–C08.
- #109 — render production acceptance and old-path exit readiness.
Specification Delta
The delta adds an independent evidence chain keyed by grant, lease, operation, token and resource event; preserves per-layer outcomes; forbids bearer values; detects every canonical drift class; and requires all production acceptance facts rather than a nearby success. The six leaves form one Session because the resulting contract, implementation, and evidence fit one PR review—not because of a fixed leaf-count rule.