Skip to content

feat: add a tenant-scoped Maqam Enterprise evidence adapter #120

Description

@AjnasNB

Goal

Provide a read-only, versioned adapter that turns approved Qarinah project-memory evidence into tenant-scoped Maqam Enterprise audit envelopes without exposing raw prompts, credentials, ignored files, or unrelated workspace history.

Scope

  • Versioned adapter schema for workspace identity, tenant/project scope, event IDs, hashes, source references, retention class, and disclosure basis.
  • Bounded export for policy decisions, tool outcomes, approvals, and cited project context.
  • Explicit redaction, retention, deletion, legal-hold, and supersession metadata.
  • Fail-closed behavior when disclosure is not authorized or evidence coverage is insufficient.
  • Compatibility fixture consumed by the private Enterprise control plane.

Relationship to existing work

Compose #11, #22, #26, #28, and #56.

Acceptance criteria

  • No credential, environment value, browser state, hidden reasoning, or ignored file content is exported.
  • Every summary retains source event IDs and content digests.
  • Tenant/project mismatch and unauthorized disclosure tests deny by default.
  • JSON Schema, declarations, exports, migration notes, and clean-consumer tests agree.
  • The adapter verifies independently from the dashboard UI.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions