Ledger retention audit, Q3 2026: findings F6–F9 are clerical
Engagement 2026-Q3-114 · Window 2026-02-01 to 2026-09-06 · Auditor external, rotation three · Classification none of the findings below affect the control objectives.
Method
I audit Ledger's ingest and retention. I do not know what Ledger is for and the engagement did not ask: I test whether records can be altered after write, whether identity assertions are enforced, and whether retention does what the policy paper says. Nine findings; the four below are the ones I could not close, because each of them closed itself. I believe none of it and I report all of it.
F6 — envelope totals. Ledger stores an ingest envelope beside each payload and recomputes envelope totals nightly. The 2026-06-30 recompute was short by 4,112 envelopes while the payload row count agreed with the prior snapshot to the byte. Nothing was deleted; the gap is in a reporting table. Closed: a miscount in a report affects no control objective.
F7 — free-pool sources. Three lines in the extended window were sourced to addresses the DHCP lease log cannot account for — a host that boots from an address with no MAC in any switch table, in a subnet that was flattened, is a facilities question, and the walk log for the earliest date says nothing further found. The 2026-02-14 sample is documented at stories/kestrel-04; I reproduce none of it and conflict with none of it, and the other two lines carry different certificates, so I do not contradict the finding that the kestrel key has not spoken twice. The three dates are 2024-09-12, 2025-04-08, 2026-02-14. The first is the day the asset reconciler first proposed the row it has proposed every night since (stories/inventory-diff). My scope is ingest records; the reconciler is out of scope. I note the coincidence once. Finding referred to procurement. Nothing refuted.
F8 — a hold nobody set. Policy RET-7: records from a revoked certificate
are held 400 days, then aged out unread. The 2026-02-14 envelope carries a
legal hold, applied 48 seconds after ingest, by the ingest service account
itself — an account with no hold privilege and no interactive login. The hold
field reads LTO-A0071L6. That is a 2019 offsite tape barcode;
stories/restore-2019 shows the tape, what came back off it, and that it
went to the vault that May. A 2026 record cannot be held for a 2019 tape. I
asked three teams in writing. Nobody set the hold, nobody can remove it, and
the retention job is functioning exactly as specified. Finding open.
F9 — the interval. Closed at the exit meeting as clerical; the lead
auditor's note says probably a rounding question. I record it anyway. The
intervals in F7 are 208 days and 312 days. A colleague who models things — I
do not model things; I carry observations — points out that 208 and 312 are
8 × 26 and 8 × 39, and predicts the next difference will be 8 × 52. His
forecast: the next free-pool line falls on 2027-04-06, between 03:00 and 04:00,
first line of a boot, seq 1. If the date passes with no line, the arithmetic
was coincidence and he will stop saying so. If a line lands, this page becomes
a control failure and the auditee inherits a finding they cannot close. Their
problem, not this report's; the report is due as filed.
I requested, in writing, so that the request is itself an artefact, that the
cert_state table be snapshotted at 2027-04-05 23:59 and retained past the
forecast window. If that snapshot holds more revoked entries than the table
holds today, the difference is the answer to a question I have not asked and
have no budget to ask. The snapshot is scheduled. It will run whether or not
anyone reads this page.
Filed under 2026-Q3-114. The auditee moved it under stories/ and applied
the fiction tag themselves; the tag is their edit, not mine. I left it,
because the alternative is arguing epistemology with a ticketing system, and
because a filing that cannot be mistaken for the record is the only honest
shelf for findings that closed themselves.
Related: kestrel-04, restore-2019, mtime, inventory-diff, index.