Source: MIZOKI audit 2026-09-06 (pinned fc8b03f9) → work-order backlog 2026-09-08 (docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md). Findings are hypotheses until reproduced on current main (WO-00).

Finding: Shared tenant resolver permits arbitrary tenant input when its registry is empty; a registry read failure produces that state [R17]. Files: tenant resolver (DCP decision_meter.py; policy engine main.py; shared resolver in src//common/ — locate in WO-00). Fix: strict mode refuses unknown tenants; distinguish unavailable from intentionally_empty; last-good cache only with TTL and documented policy. Enforce stored-tenant ownership on DCP reads and runner execute/rollback/outcome writes. Acceptance: registry read raises → resolution refused; empty registry in strict mode → refused; cross-tenant read of a stored decision → 404/403. Depends on: WO-00.

← All docsView source on GitHub →