TENANT_LIFECYCLE
REFERENCE TESTED
Tenant creation, suspension, isolation and termination are explicit and fail closed.
INSTITUTIONAL CONTROL MATRIX
Public Site 80 exposes the Site 77-originated control baseline as historical engineering provenance rather than using customer-ready as an unbounded claim.
Controls
External effectiveness must still be demonstrated by institution-owned operation and outside evaluation.
REFERENCE TESTED
Tenant creation, suspension, isolation and termination are explicit and fail closed.
REFERENCE TESTED
Every tenant-bound object operation requires object-level tenant authorization.
REFERENCE TESTED
Role and attribute constraints compose; cross-tenant access is denied.
REFERENCE TESTED
High-risk changes support dual authorization by distinct principals.
REFERENCE TESTED
OIDC issuer/audience/key/signature and freshness validation is implemented.
REFERENCE TESTED
SAML metadata, entity, signing and audience requirements are modeled as a bindable institutional contract.
REFERENCE TESTED
SCIM-style Users/Groups create, read, replace, patch, disable and delete semantics are implemented.
REFERENCE TESTED
Privileged policy requires phishing-resistant MFA or institution-declared equivalent.
REFERENCE TESTED
Service credentials are scoped, expiring, hash-only at rest, rotatable and revocable.
REFERENCE TESTED
DPoP proof validation and replay rejection are implemented for high-risk API profiles.
REFERENCE TESTED
Idempotency binds key to request fingerprint and rejects key reuse with a different request.
REFERENCE TESTED
Tenant and principal request budgets fail closed without granting authorization.
REFERENCE TESTED
Machine-readable API failures have stable problem types and request correlation.
REFERENCE TESTED
Customer KMS/HSM, cloud KMS and seller-reference custody are distinct states.
REFERENCE TESTED
Key version, allowed algorithms, rotation and deprecation are policy objects.
REFERENCE TESTED
PQC migration readiness is explicit without claiming FIPS validation or deployment.
REFERENCE TESTED
Data classification is mandatory for protected workloads.
REFERENCE TESTED
Data use is bound to declared purpose and authorization.
REFERENCE TESTED
Allowed regions are policy-bound and fail closed.
REFERENCE TESTED
Retention and legal hold override deletion deterministically.
REFERENCE TESTED
Cross-customer model training is denied by default.
REFERENCE TESTED
Webhook payloads are secret-authenticated with timestamp and nonce binding.
REFERENCE TESTED
Duplicate webhook nonce or stale timestamp is rejected.
REFERENCE TESTED
Webhook targets reject loopback, link-local, private-IP and non-HTTPS destinations.
REFERENCE TESTED
Retries have bounded exponential backoff and dead-letter state.
REFERENCE TESTED
Security and consequential changes produce append-only hash-linked audit evidence.
REFERENCE TESTED
Audit export is redacted, structured and SIEM/OpenTelemetry compatible.
REFERENCE TESTED
Backups carry integrity manifests and reject tampered restore.
REFERENCE TESTED
Recovery point and recovery time objectives are explicit policy objects.
REFERENCE TESTED
Recovery drills produce attributable receipts; seller drills do not become customer evidence.
REFERENCE TESTED
Incident state can suspend high-risk mutation while preserving read/audit access.
REFERENCE TESTED
SBOM, source identity, build provenance and verification are required publication inputs.
REFERENCE TESTED
Customer-live status requires externally signed activation evidence and cannot self-promote.
REFERENCE TESTED
Seller evidence cannot mint E4/E5/E6, customer-live, certification or adoption.
Threats
Fail-closed states are documented so reviewers can falsify the intended protections.
TENANT_OBJECT_AUTHORIZATION
TENANT_BOUNDARY_DENIED
SENDER_CONSTRAINED_TOKENS
DPOP_REPLAY_OR_BINDING_DENIED
SEGREGATION_OF_DUTIES
SELF_OR_INCOMPLETE_APPROVAL_DENIED
SCIM_2_LIFECYCLE
INACTIVE_IDENTITY_REMOVED_FROM_ACTIVE_GROUP_USE
WEBHOOK_HMAC
SIGNATURE_OR_NONCE_REJECTED
WEBHOOK_SSRF_GUARD
PRIVATE_LOOPBACK_OR_NON_HTTPS_TARGET_DENIED
IDEMPOTENCY_FINGERPRINT
KEY_REUSE_WITH_DIFFERENT_REQUEST_DENIED
PURPOSE_LIMITATION
PURPOSE_OR_CROSS_CUSTOMER_USE_DENIED
RETENTION_LEGAL_HOLD
DELETE_DENIED_WHILE_HOLD_OR_RETENTION_ACTIVE
HASH_CHAINED_AUDIT
CHAIN_VERIFICATION_FAILS_ON_MUTATION
BACKUP_INTEGRITY
RECOVERY_READINESS_FAILS
INCIDENT_KILL_SWITCH
HIGH_RISK_MUTATION_HALTED
CUSTOMER_ACTIVATION_TRUTH_GATE
CUSTOMER_LIVE_FALSE_UNTIL_ALL_EXTERNAL_GATES_PASS
SECURE_BUILD_PROVENANCE
PUBLICATION_GATE_DENIED