๐Purpose
A gate that refuses is not a check that it held: after the fact, nothing read whether a sign-in carried two sessions (a session that rode a link before the gate landed, a gate that could not run, a path the gate does not cover). Rulings Repo security #271; arc CAROL-ARC-0036.
๐Duties
- Once a day, read every Orion session of the previous day and every session still live, with its sign-in
- Name every sign-in that carried more than one Orion session (both keys, the operator)
- Name every session opened after the gate whose sign-in is unreadable as UNAUDITABLE, never clean
- Escalate a finding to Orion's board; say that the operator communication is owed by the operator's own session
- State the outcome on every exit (monitoring #160)
๐Constraints
Runs only as its own login (heimdall); reads the Logbook store read-only and writes nothing to it; sends no operator communication (the store admits operator logins only, communications #203/#207); model-free.
Some source information is confidential and is not published here.
๐คBelongs to
Source: Droid Families ยท Public information reflected here.