AuthBox
Evidence register

Every capability, beside what proves it.

The support matrix answers what a capability touches. This answers the question after it: how much of it is proven, and by what kind of test. Nothing below is typed by hand — every cell resolves to an entry in a register or to a behaviour in the shipped rehearsal population.

Evidence, a level deeper: the audit chain, the receipts a caller keeps, and the proved register behind every claim.
Unit floor
100 of 106

rows with at least one package under a statement-coverage floor the gate holds

Ledger tiers
76 of 106

rows the exercise ledger reaches at any tier

Rehearsal
45 of 106

rows a behaviour of the shipped population drives against a live deployment

Mutations
95 of 106

rows whose plans carry a declared mutation proving their tests bite

Composed smoke
69 of 106

rows the composed smoke names — a check line of the all-in-one bring-up that an anchor in the register holds to its words

Binaries, clients and the SDK

What is shipped and run. A binary is not a ledger dimension — the ledger keys on settings, operations, status subsystems and console routes, which are what the binary CARRIES — so its evidence is its packages' floors and the rehearsal that drives it.

CapabilityUnit floorLedger tiersRehearsalMutationsComposed smoke
authboxd authboxdHTTPS over mutual TLS · RFC 5280, RFC 8446cmd/authboxd 75 (all)
internal/server 90
internal/config 85
internal/tlsx 90
unit · integration9142
authboxproxy authboxproxyHTTPS over mutual TLS, forwarding to an application · RFC 5280, RFC 8446cmd/authboxproxy 75 (all)
internal/proxy 90
unit · integration · scenario26183
authboxvault authboxvaultHTTPS over mutual TLS · RFC 5280cmd/authboxvault 70 (all)
internal/vault 80
not a ledger dimension003
authboxportal authboxportalHTTPS over mutual TLS · RFC 5280cmd/authboxportal 70 (all)
internal/portal 80
unit · integration · federation0407
authboxkas authboxkasthe OpenTDF key access rewrap operation over mutual TLS · OpenTDF 4.3.0cmd/authboxkas 70 (all)
internal/kas 90
sdk/marked/tdf not in the report
unit · integration1123
authboxldapsync authboxldapsyncLDAP client over LDAPS · RFC 4511, RFC 4513cmd/authboxldapsync 35 (all)
internal/ldapsync 75
not a ledger dimension191
authboxscimsync authboxscimsyncSCIM 2.0 client over HTTPS · RFC 7643, RFC 7644cmd/authboxscimsync exempt · unit
internal/scimsync 80
unit only3233
authboxclient authboxclientHTTPS client against the enrolment and administration surfaces · RFC 2986, RFC 5280cmd/authboxclient 35 (all)
internal/client 85
internal/pki/keystore 90
not a ledger dimension442
authbox-agent authbox-agentHTTPS client against the enrolment surface · RFC 2986cmd/authbox-agent exempt · integrationnot a ledger dimension04absent
authboxctl authboxctllocal administration of a deployment's own statecmd/authboxctl 70 (all)not a ledger dimension001
authboxjs authboxjsbrowser fetch against the console and administration surfacescmd/authbox-sdk exempt · unitunit · integration · federation03absent
Object store object-storean S3 subset in, labelled objects outcmd/authbox-store 50
internal/objectstore 90
internal/authboxkit exempt · unit
not a ledger dimension8146
Dialect sidecar dialect-sidecara customer's own API shape in, the same shape outcmd/authbox-dialect 20
internal/dialectserve 80
internal/dialect 90
internal/dialectconform 80
unit · integration0226

Served surfaces

What answers on a listener. These are the rows the exercise ledger reaches most directly: a surface has a switch, an operation or a console route, and the ledger keys on all three.

CapabilityUnit floorLedger tiersRehearsalMutationsComposed smoke
Enrolment intake enrolment-intakeCSR intake over HTTPS · RFC 2986, RFC 5280internal/api/enroll 85
internal/pki 85
unit · integration1002
ACME server acmeACME with device-attest-01 · RFC 8555, draft-acme-device-attestinternal/acme 80unit · integration · scenario · federation4161
EST server estEnrollment over Secure Transport · RFC 7030internal/est 85unit · integration · federation132
Invitation mail invitation-mailSMTP submission to the organization's relay · RFC 5321internal/vault 80
internal/smtpsink exempt · integration
unit · integration272
Credential claim credential-claimHTTPS with no client certificateinternal/vault 80unit · integration001
OCSP responder ocsp-responderOCSP over HTTP · RFC 6960internal/ocsp 80unit · integration · omni · federation172
Administration API admin-apiHTTPS over mutual TLS · OpenAPI 3.1internal/api/admin 85
internal/server 90
unit · integration · federation8122
Console consoleserver-rendered HTML over mutual TLS · OpenAPI 3.1internal/ui 85
internal/consoleproject 95
unit · integration · scenario · federation8323
Brokerage brokeragemission brokerage over HTTPS · OpenAPI 3.1internal/api/brokerage 80unit · integration · federation2334
Clearance authority clearanceclearance question over HTTPS · OpenAPI 3.1internal/api/clearance 85unit · integration · omni1122
self selfself-description over HTTPS · OpenAPI 3.1internal/api/self 85unit · integration · omni · federation0141
Standing agreements agreementsHTTPS over mutual TLS · OpenAPI 3.1internal/portal 80unit · integration · federation0163
SAML identity provider saml-providerSAML 2.0 Web Browser SSO, HTTP-Redirect and HTTP-POST bindings, signing only · SAML 2.0 Core, SAML 2.0 Bindings, SAML 2.0 Metadata, XML Signature, Exclusive XML Canonicalization 1.0internal/saml 90unit only2232
OIDC provider oidc-providerOpenID Connect authorization code flow with PKCE · OpenID Connect Core 1.0, RFC 8705, RFC 7636internal/oidc 85unit · integration · federation161
AuthZEN PDP authzenOpenID AuthZEN Authorization API · OpenID AuthZEN Authorization API 1.0internal/api/authzen 95unit · integration · federation042
Shared signals transmitter shared-signalsOpenID Shared Signals Framework, RFC 8936 poll, RFC 8417 tokens · RFC 8417, RFC 8936, RFC 9493, OpenID CAEP 1.0, OpenID RISC 1.0internal/ssf 80unit · integration020absent
LDAPS directory ldaps-directoryLDAP v3 over TLS, read-only, SASL EXTERNAL bind · RFC 4511, RFC 4513internal/ldapserve 80unit · integration · federation2223
The federation's names federation-namesauthoritative DNS over UDP and TCP, with DNSSEC signing · RFC 1035, RFC 4034, RFC 4035internal/names 95
internal/dnsserve 80
unit · integration · scenario · federation0294
The anonymous door anonymous-doormatch, strip, forward — no decision and no injected identityinternal/proxy 90unit · integration · scenario012
The front door's directory front-door-directoryone HTML page, GET, no client certificate — drawn from the route tableinternal/proxy 90
internal/authboxkit exempt · unit
unit · scenario03absent
Authorized streams streamslabelled frames over one long-lived request, fanned out by markinginternal/stream 80
internal/proxy 90
unit · integration713absent
The marked response markedone response header carrying a marking, compared against the caller's chaininternal/proxy 90
sdk/marked not in the report
unit only0143
SSH through the door ssh-through-the-doora raw connection wrapped in mutual TLS, routed by SNI, spliced unread · RFC 4253internal/splice 95
internal/proxy 90
unit only06absent
Public listener public-listenerHTTPS with no client certificate requestedinternal/api/public 85unit only002
Embedded documentation embedded-docsthe accreditation collection rendered into the binaryinternal/docs 90
internal/docrender 90
unit · integration · scenario · federation05absent
Health healthliveness and readiness over HTTPSinternal/health 95unit only012
Metrics metricsPrometheus text expositioninternal/telemetry 90unit · integration · omni14absent
Status and topology deployment-statusthe deployment's own state, computed and drawninternal/status 95
internal/topology 95
unit · integration · scenario · federation082
SSH certificate authority ssh-certificate-authorityOpenSSH certificates (PROTOCOL.certkeys) and revocation lists (PROTOCOL.krl) · RFC 4251, RFC 5656internal/sshcert 85
internal/pki 85
internal/api/enroll 85
unit · integration · scenario116absent
The jump door jump-doorSSH — an SSH server on the front door that a client jumps through, one direct-tcpip channel per decision · RFC 4253, RFC 4252, RFC 4254internal/jumpdoor 95
internal/proxy 90
internal/sshcert 85
internal/splice 95
unit · integration06absent

Subsystems

What is inside the box. A subsystem's ledger tiers come from its status keys, which is why a subsystem nothing reports on shows no tier however well its package is covered.

CapabilityUnit floorLedger tiersRehearsalMutationsComposed smoke
Registration authority registration-authorityPKCS#10 forwarded over EST or ACME to the organisation's own CA · RFC 7030, RFC 8555, RFC 2986internal/pki/ra 70
internal/pki 85
unit · integration06absent
Enrolment invitations invitationssingle-use expiring tokeninternal/invite 90unit · integration · federation1001
The door follows the project door-follows-projectroute records derived from the signed bundle a door already pollsinternal/dataset 90
internal/proxy 90
internal/replica 90
internal/credential 95
internal/api/admin 85
internal/api/enroll 85
internal/portal 80
unit · integration · federation044
Service certificates service-certificatesderived identity plus a bounded, single-use invitationinternal/dataset 90
internal/pki 85
internal/api/admin 85
internal/api/enroll 85
internal/client 85
internal/credential 95
internal/proxy 90
internal/portal 80
internal/acme 80
internal/vault 80
unit · integration · federation0610
Attested custody attested-custodyrecorded key-custody claim on an issued credentialinternal/attestrecord 100unit · integration2112
Device attestation device-attestationkey-attestation statements verified against manufacturer roots · draft-acme-device-attestinternal/attestverify 95unit · integration2112
CA hierarchy ca-hierarchyX.509 issuance · RFC 5280internal/pki 85
internal/pki/keystore 90
unit · integration082
CRL distribution crl-distributionX.509 certificate revocation lists · RFC 5280internal/pki 85unit · integration · federation181
OCSP client ocsp-clientOCSP over HTTP against an upstream CA · RFC 6960internal/ocsp 80unit · integration27absent
Post-quantum issuance post-quantumML-DSA certificates alongside the classical set · FIPS 204internal/pki 85unit only01absent
PKCS#12 export pkcs12-exportPKCS#12 with PBES2 and an SHA-256 HMAC · RFC 7292, RFC 8018internal/pkcs12 85not a ledger dimension041
Short-lived profile short-lived-profilecertificate profiles with a validity measured in hours · RFC 5280internal/pki 85unit · integration122
Entities and groups entities-and-groupsX.500-shaped directory of subjects · RFC 4514internal/dataset 90
internal/identity 90
unit · integration · omni · federation7272
Dynamic group membership members-everyonea declared membership, resolved at load into the ordinary member listinternal/dataset 90
internal/authz 90
not a ledger dimension09absent
Missions missionsnamed requirements over a subject's standinginternal/authz 90unit · integration · omni · federation18303
Data markings data-markingsOpenTDF attribute URIs · OpenTDF 4.3.0internal/opentdf 90unit · integration1353
Obligations obligationsstanding compliance questions over the storeinternal/obligation 95unit · integration · scenario · federation031
Goals goalsobligation reports joined over a project treeinternal/goal 80unit · integration · scenario · federation06absent
Delegated identity (XPE) xpeX-ProxiedEntitiesChain and X-ProxiedIssuers-Chaininternal/xpe 95unit · integration · omni · federation0142
WebAuthn step-up webauthnWebAuthn assertion as a second signature · W3C WebAuthn Level 2internal/webauthn 85unit · integration · scenario · federation16absent
Signed actions signed-actionsactor signature over one action, and a periodic chain-head countersignature · RFC 7515internal/attest 85unit · integration · omni · federation0131
Decision receipts receiptsJWS over one permitted decision · RFC 7515internal/receipt 95unit · integration · federation1493
Authorization engine authorization-enginethe specification IS the authorization map · OpenAPI 3.1internal/authz 90
internal/spec 95
internal/conformance 85
unit · integration · federation742
Activity projection activitya projection over the decision record and this process's own countersinternal/activity 90unit · integration · scenario · federation012absent
Entity history entity-historya projection over records that already existinternal/history 90unit · integration · scenario · federation363
SPIFFE federation spiffe-federationX509-SVID peers from declared foreign trust domains · SPIFFE X509-SVIDinternal/federation 95
internal/spiffeid 85
unit · integration · federation051
Foreign-schema codec seam foreignseam between AuthBox's model and a foreign onesdk/foreign not in the report
internal/foreign 90
not a ledger dimension09absent
STANAG label seam stanagseam between a NATO confidentiality label and this dictionary · STANAG 4774, STANAG 4778internal/stanag 90not a ledger dimension014absent
Replicas replicassigned dataset bundles with a monotonic serialinternal/replica 90unit · integration · federation143
Replica publish replica-publishsigned replica bundle of the live store, on a cadence, served on requestinternal/replica 90unit · integration · scenario · federation0272
Sync engine and live cascade sync-engineauthority bundles, adopted from an upstream and served per consumerinternal/syncengine 95
internal/authoritybundle 75
internal/authorityserve 80
unit · integration · federation0264
Project authority federation project-authoritya project owned by another AuthBox, with a freshness budgetinternal/upstream 75unit · integration · federation091
Org attribute authorities org-attribute-authoritiessigned assertions over an attribute name somebody else ownsinternal/authoritybundle 75unit · integration · omni · federation002
Kubernetes ingress mode proxy-kuberneteslist and watch over this cluster's Servicesinternal/proxy 90unit · integration · scenario017absent
Self-enrolling credential managed-credentialthe companion enrols and renews its own certificateinternal/credential 95
internal/credential/selfenroll 80
unit only702
Audit chain audit-chainappend-only hash-chained records, sealed into segmentsinternal/audit 95unit · integration · omni · federation753
Signed audit export audit-exporta sealed segment turned into an artifact a SIEM can prove it receivedinternal/auditexport 80not a ledger dimension042
Front-door audit hand-off door-audit-handoffone plan-055 signed export per sealed segment, POSTed in ordinal orderinternal/auditexport 80
internal/activity 90
unit · integration · federation752
Transparency log transparency-logstatic tile tree with signed-note checkpoints · C2SP tlog-tiles, C2SP signed-noteinternal/tlog 90unit · integration062
Backup and restore backup-restorea manifest-wrapped tar of the dataset, the audit segments and the keystoreinternal/backup 75unit · integration15absent
Policy export policy-exportthe declared requirements as Rego and Cedarinternal/policycodec 90unit · integration05absent
Control mapping and OSCAL controlsNIST 800-53 control mapping, emitted as an OSCAL component definition · NIST SP 800-53 Rev. 5, OSCAL 1.1internal/assurance 75integration02absent
Operational log operational-logstructured operational logginginternal/telemetry 90unit · omni04absent
Store backends store-backendsmemory, file, PostgreSQL and MySQL behind one repository interfaceinternal/store 75
internal/store/file 75
internal/store/memory 95
internal/store/sqlstore exempt · db
internal/store/sqlstore/postgres exempt · db
internal/store/sqlstore/mysql exempt · db
unit · integration · federation093
The Register — AuthBox's own design system design-systemone stylesheet and three embedded faces in, every door AuthBox draws outinternal/authboxkit exempt · unitnot a ledger dimension06absent
A day in the harbour watch walkthroughsix acts over a running federated composition, asserted as it goes—not a ledger dimension016

Build-time tools

What this repository's own claims depend on. Nothing here runs in a deployment, so nothing here is a ledger dimension or a rehearsal act; the floor and the mutations are the whole of the proof.

CapabilityUnit floorLedger tiersRehearsalMutationsComposed smoke
Documentation and register renderer docs-rendererregisters in, generated documents outcmd/authbox-docs exempt · unitnot a ledger dimension015absent
The mark and the tool that derives it brand-markdelivered artwork in, the forms every surface serves outcmd/authbox-brand 85
internal/brand 90
not a ledger dimension00absent
Mutation harness mutation-harnessapply a declared deletion, require the named tests to failcmd/authbox-assure exempt · unitnot a ledger dimension012absent
Release evidence report evidence-reporteach gate's own machine-readable output, assembledcmd/authbox-testreport exempt · unit
internal/testreport 90
not a ledger dimension06absent
Benchmark regression gate bench-gatetwo `go test -bench` runs comparedcmd/authbox-benchcompare exempt · unit
internal/benchcompare 90
not a ledger dimension06absent
Software bill of materials sbomCycloneDX-shaped JSON built from the build itself · CycloneDX 1.5cmd/authbox-sbom exempt · unit
internal/sbom 85
not a ledger dimension05absent
Release signing release-signinga detached signature over the release's SHA256SUMScmd/authbox-sign exempt · unit
internal/relsign 85
internal/changelog 85
internal/provenance 80
not a ledger dimension012absent
Release courier bundle release-mediaone tar archive with a signed MANIFEST naming every file's digest and posturecmd/authbox-release exempt · unit
internal/relbundle 85
internal/relimages 90
not a ledger dimension013absent
Reference stream sink stream-sinkverified frames in, receipts and frame hashes on diskcmd/authbox-ingest 25not a ledger dimension7131
Local S3 shim store-shimloopback S3 in, mutual TLS outcmd/authbox-store-shim 25not a ledger dimension00absent
Marked-response showcase showcase-recordssix classified records, every response labelled, and a TDF export of eachcmd/authbox-showcase-records 55not a ledger dimension0222
OIDC login showcase showcase-oidca relying party's discovery, PKCE authorization code and RFC 8705 mTLS token exchangecmd/authbox-showcase-oidc 50not a ledger dimension102
SAML service provider showcase showcase-samla service provider's SP metadata, HTTP-Redirect AuthnRequest and POST-binding assertion consumer, with signature verificationcmd/authbox-showcase-saml 65not a ledger dimension2231
Fixture PKI and demonstration data fixture-dataa fixture hierarchy and a curated demonstration organizationcmd/authbox-testpki 30 (all)
cmd/authbox-demogen 85
internal/testpki 85
internal/testkit exempt · integration
not a ledger dimension132
Rehearsal population rehearsala population file, a deterministic schedule, and a run log of acts against a deployment's own doorscmd/authbox-simulate exempt · unit
internal/simulate 50
not a ledger dimension112absent
Compose-to-Kubernetes translation compose-translationa rendered `docker compose config` document translated to Kubernetes objectscmd/authbox-kube exempt · unit
internal/composekube 90
not a ledger dimension03absent
Scanner gate and suppression register scan-gatefive scanners' native JSON, judged against one registercmd/authbox-scan 80
internal/scanreg 85
not a ledger dimension05absent

This deployment’s customer dialects

2 dialect(s), proved — 3 mapped operation(s), 1 of which this deployment can be asked. 62 generated instance(s) were translated and checked against the customer’s own document: 59 translated, 3 refused for carrying no value a required field needed, and 0 refused by the document they were translated into. A dialect is a customer’s own API shape brought as their OpenAPI document, and a mapping of five rule kinds onto it — no expression, no conditional and no code — proved at load against both documents.

DialectDeclared byCustomer documentOperationsAnswerable hereInstances
tideline-gateway/1 deploy/all-in-one/dialectthe all-in-one compositionTideline Access Gateway API 1.1 sha256 2c79635e44d61128
acme-iam/1 internal/dialect/testdata/acme-iaminternal/dialect's own test fixtureAcme IAM Access API 2.4 sha256 7921dbd858e72034

How to read it

Capability
The row's name, its id in the capability register — the name the console's Services page, the exercise ledger and the support matrix all use for the same row — what it speaks, and the standards it speaks it by.
Unit floor
Every package the row declares, with the statement-coverage floor the gate holds it to. (all) marks a floor held against the all-tiers measurement, which folds the compiled binaries in and is not comparable with a unit-report floor. exempt · tier names the tier a package's proof lives in instead. not in the report is a package the coverage report does not measure — the generated SDK, which has no statement coverage here at all.
Ledger tiers
Every tier that reaches any of the row's settings, status subsystems, specification operations or console route. unit only is a row the ledger knows at that tier and no other. not a ledger dimension is a row the ledger cannot key on — a binary or a build-time tool — and is a statement about the ledger rather than about the row.
Rehearsal
How many behaviours of the shipped population drive this capability against a live deployment; hover the number for their names. Each behaviour carries an act kind, and one declared table maps an act kind to the capabilities it exercises. Four rows are credited with the run itself rather than with a behaviour, because the rehearsal, its fixture data, the metrics it reads back and the daemon every act talks to are what a run is rather than something a behaviour does.
Mutations
How many declared mutations prove the rules of this row's plans are not vacuously asserted. Zero is printed as itself: a capability whose plans made no ruling anybody mutated is a finding, not a blank.
Composed smoke
How many check lines of the composed all-in-one bring-up name this capability; hover the number for their text. The corpus is every deploy/all-in-one script plus the makefile's own all-in-one, rehearsal and kind recipes, and a check line is one that prints an OK — what a step says when it held. Each is counted because the row declares an anchor for it: an exact fragment of that line, which a test proves still appears there, so a step that is deleted or reworded drops out of this column instead of being claimed by a row nobody re-read. absent means no check line names this capability — the honest state for the SSH capabilities, the OCSP client, policy export, the post-quantum profile and the build-time tools, which a composed bring-up does not exercise — and is a different statement from a zero, which would read as a measurement.

These columns sample a ladder of tiers — unit, deploy-tier (the static facts of what is shipped: compose files, configurations, dataset fragments, the smokes' own shell helpers, the specification read beside any of them), integration, scenario and omni, the composed smoke, the rehearsal — and where a claim sits on it is part of the claim: a fact that could be read off a checked-in file but is proved only in the composed-smoke column is a proof that costs twenty-five minutes to re-run.

What this page deliberately does not carry is a measured coverage percentage. That figure is the output of a run and not a property of the repository, so a page generated from it would be stale on the next commit. It lives in the release evidence report, assembled at a tag. The floor is the claim a gate holds, and the floor is what is printed here.

Generated from the registers on every documentation run. The same table, with its legend, is beside the support matrix in the technical collection.