Skip to content

Implement Context Builder provenance, redaction and audit handoff #82

Description

@andrewperis

Parent epic: #5

Summary

Implement Context Builder provenance, redaction and audit handoff for Context Builder v1.

Ownership and dependencies

Scope and deliverables

  • Record build/correlation IDs, builder/policy versions, approved input identities, selection/omission/budget outcomes, timing and package result identities.
  • Separate restricted operational evidence from public-safe projections. Public records use approved opaque attestations rather than private paths, commits, object locations or hashes.
  • Define pluggable local/test audit sinks with bounded delivery and explicit failure semantics; required policy audit failures must not silently authorize delivery.
  • Link preparation evidence to eventual exact-instance use authorization without allowing the builder to impersonate an approving authority.

Acceptance criteria

  • Success, denial, no-match, budget failure, expiry and sink failure are traceable without body leakage.
  • Public projection tests prohibit non-public identifiers, fingerprints, credentials and diagnostic excerpts.
  • Identity/correlation fields link to package and later Prompt SDK execution without changing released provenance semantics.
  • A synthetic attestation/verifier demonstrates the public/private boundary without requiring a production signing service.

Implementation guardrails

Follow Constitution v1.0.0 at a9cc8a503aa30e17820edc62ac95f7cbe10e0564 and repository boundaries. Add focused tests with implementation; the suite task consolidates rather than postpones testing. Public issues, fixtures and docs use synthetic/already-public material only. Approved private inputs stay behind explicit secure artifact boundaries. No direct Lore checkout, silent declassification, self-approval or canon promotion.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions