CSINT n8n Workflow Change Receipt
Support workflow staging release review
A reviewed record of what changed, what the staging contract observed, and what still needs a human decision.
approvedThe candidate meets the current static policy and its bound staging contract passed without an external action.
Review subject
- Review ID
- wcr-0256a2bbf7ea-157461ca
- Generated
- 2026-08-04T11:10:24.706Z
- Baseline
- CSINT - Security Regression Baseline (action-free)
157461caf339f164 - Candidate
- CSINT - Security Regression Staging Target
0256a2bbf7eaa560
What changed
CR-001improvement
A control boundary was strengthened: Read Safe State
The candidate introduces explicit control logic at this step. The staging receipt records whether the expected behavior held.
CR-002improvement
A control boundary was strengthened: Validate and Queue
The candidate introduces explicit control logic at this step. The staging receipt records whether the expected behavior held.
CR-003improvement
A control boundary was strengthened: Validate Simulated Approval
The candidate introduces explicit control logic at this step. The staging receipt records whether the expected behavior held.
Staging evidence
passedThe receipt is bound to this candidate and the isolated staging contract passed without an external action.
Open findings
- LOW AA-010
No workflow-level failure route was detected
Add a failure route that records the error, alerts the operator and prevents partial actions from being treated as success.
Evidence boundaries
- This receipt compares exported JSON and a supplied staging record. It does not inspect production credential scope or external service authorization.
- Runtime evidence is accepted only when its canonical workflow fingerprint matches the candidate in this receipt.
- A passing receipt records evidence for the tested policy and contract. It is not a penetration test, compliance certificate or security guarantee.
- Node names, node types, public domains and credential types can appear in the receipt. Prompt text, parameter values and credential values are omitted.