# Specification traceability

| Requirement | Implementation |
| --- | --- |
| 20 core modules | `config/gateway.php` module catalogue |
| External and internal zones | Separate `/external/v1` and `/internal/v1` route groups |
| Canonical commands/events | `CanonicalEnvelope` and declared catalogues |
| Provider isolation | `ProviderAdapter`, `AdapterRegistry`, sandbox adapters |
| FEI authority | Canonical internal command boundary; no FEI storage access |
| Ledger authority | `AuthorityPolicy` blocks accounts, journals and postings |
| Apps through BFFs | No mobile or web-app route group in Gateway |
| Webhook validation/replay | External webhook group with replay middleware |
| Provider certification | Registry certification state and existing certification framework |
| Zero-trust context | Canonical envelope requires identity, entity, tenant, capability, purpose and correlation |
| Idempotency | Required in command envelope and route middleware |
| UK English and brand | UK copy, Ledger colour/typography contract and Threasury logo |
| Future extensibility | Adapter interface, capability routing and versioned contracts |
| Institutional Control Tower | Nine governed modules backed by migration `012_control_tower.sql`, protected session APIs and responsive operations interface |
| Connected applications | Typed FEI, Ledger, BFF, partner, regulated-provider, screening and institutional-service registry with approval-held activation |
| Operator API keys | KMS/Secrets Manager persistence, Argon2id hashes, scopes, environment separation, CIDR policy, one-time display, rotation and revocation |
| Approvals | Risk-tiered, expiring, hash-bound four-eyes workflow with requester/decision-maker separation |
| Compliance and screenings | Evidence-linked alert workflow and tokenised provider-executed screening requests; no decision authority in middleware |
| Alert routes | Governed resource references, deterministic filters, deduplication, escalation and approval-held activation |
| Activity feed | Secret-redacted, SHA-256-linked operational activity records |

## Institutional upgrade

| Upgrade requirement | Enforced implementation | Activation evidence |
| --- | --- | --- |
| Genuine edge mTLS | API Gateway versioned truststore, disabled execute-api endpoint, Lambda certificate authoriser, signed edge assertion and private VPC Link origin | Untrusted certificate, forged header, expired certificate, suspended certificate and direct-origin tests |
| Certificate-to-partner identity | `gateway_partner_certificates`, strongly consistent DynamoDB edge registry and `TrustedEdgeIdentity` independent backend validation | Exactly one active partner mapping per SHA-256 thumbprint |
| OAuth plus mTLS | OAuth `client_credentials`, scoped permissions and certificate-bound `cnf.x5t#S256` tokens | Token rejection under another certificate |
| Secrets lifecycle | Secrets Manager, ECS workload identity, KMS encryption and 30-day database rotation with test step | Rotation logs, emergency-rotation exercise and expiry alarms |
| Multi-AZ runtime | ECS/Fargate tasks, private load balancer and private subnets across three Availability Zones | Task-loss and AZ-isolation exercise |
| Multi-AZ authoritative state | Aurora writer and reader, three-subnet group, automatic failover and continuous backups | Timed failover and isolated restoration evidence |
| Autoscaling | ECS target tracking with deployment circuit breaker and rollback | Load test without SLO breach |
| Durable MSK backbone | Transactional database outbox and IAM-authenticated local MSK bridge | Broker interruption, duplicate, back-pressure and poison-message tests |
| Domain topics and ordering | Governed topic set and business-key partitioning | Per-key ordering tests; no global-ordering claim |
| Signed canonical contracts | `CanonicalSchemaRegistry`, versioned JSON contracts, signature and backward-compatibility checks | CI compatibility and consumer-impact evidence |
| Policy as code | Versioned policy decisions with six outcomes, input hashes, reasons and obligations | Purpose, consent, jurisdiction, legal-entity, classification and approval tests |
| Immutable audit | Chained audit records, Merkle checkpoints, HMAC signature and S3 Object Lock compliance retention | Retrieve and verify signed checkpoint and object version |
| OpenTelemetry and SLOs | OTLP trace export, correlation propagation and formal service-objective registry | Trace completeness and alert simulations |
| Adapter certification | 33 mandatory functional, resilience, security and reconciliation scenarios | All scenarios pass before fail-closed promotion |
| Partner portal | UK-English portal, governed progression, applications, schemas, documentation and assurance surfaces | Sandbox-to-production onboarding exercise |
| Continuous assurance | Dependency, secret, SAST, IaC, container, SBOM and provenance gates | Protected pipeline results; critical findings block publication |
| Disaster recovery | AWS Backup, point-in-time recovery, optional cross-region backup and immutable evidence replication, active-passive runbook | Annual regional exercise meets approved RTO/RPO |
| No legacy providers | Institutional test scans the repository for prohibited legacy identities | Zero matches outside non-production logs |
