Standing audit register (P1-P7 + services review) plus the design-of-record
docs from this arc: Chatty reactions/replies/redactions/edits, contacts
Person layer, and RCS carrier reality.
One page each for machined, secrets, sessiond — what each owns, what
crosses its boundary, and the open gaps before it reaches the RedFlag
capability-token bar. Gaps mapped to concrete RedFlag primitives (token,
closure hash, canonical message, KeyID, independent verifier, binary
integrity, eBPF) with file:line anchors, not doctrine-summary hand-waving.
audit-status.md rolls up priority: P0 unlock/handoff attestation, P1
machined token issuance, P2 secrets caller identity, P3 per-agent UIDs,
P4 binary watchdog shared-deferred with RedFlag SEC-022.
machined system tier landed in souveraine (5039163/116562a); boot-gate
vs session-lock doctrine on record. FEDERATION.md moves here from
souveraine's gitignored docs tree, rewritten: implemented pieces cited,
memfs transport roughed (shared bare remote, branch-per-instance,
domain merge policy, memfs_commit firehose signal), instance awareness
design, and the install-time agent instantiation flag.