Task · GCI-0025

Verify what traces:read and profiles:read actually permit, with an isolated mint-and-delete probe

Status
Parked
Priority
medium
Labels
security, capabilities
Updated
2026-09-11

Description

GCI-0023 documented every declared reader scope’s breadth except two. traces:read and profiles:read are recorded in CAPABILITIES.md as explicitly unverified, with the necessary probe named rather than a narrow boundary asserted. This task runs that probe.

Authorised by the operator on 2026-09-11 for wave 2.

The probe

Mint an access policy carrying traces:read and nothing else, on a control organisation. Call content-bearing Tempo routes with it and record what returns 200 and what returns 403. Repeat for profiles:read against Pyroscope. Delete both policies. Verify no residual object remains.

Constraints

Acceptance Criteria

Definition of Done

Implementation Notes

Wave 2 attended probe did not run because the operator did not supply the control-organisation identity. No organisation was inferred and no access policy was minted, read, modified or deleted.

Final Summary

Parked without live mutation. The control organisation was not supplied, so traces:read and profiles:read remain explicitly unverified, no content-bearing route result was claimed, and CAPABILITIES.md was not changed.

View the source file on GitHub