ADAPTIVE-WP-0009: record draft-6 review outcome
Some checks failed
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Has been cancelled

Draft-6 (net-kingdom 2744ce7) applies tenant-engine's review only; findings
1-5 all still stand. Adds two findings from draft-6 itself: off-ladder
notation (P-, R0/R1) with no declaration form, and no obligation to notify
dependent tiers when a delivering service downgrades its posture. Reframes
T06 to reuse draft-6's level-plus-named-exception grammar.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-08-17 21:52:15 +02:00
parent e8ebd5cdd2
commit f759735aab

View file

@ -9,6 +9,7 @@ owner: codex
topic_slug: helix-forge
created: "2026-08-17"
updated: "2026-08-17"
state_hub_workstream_id: "ac4f4540-75a1-4dbf-9cb7-57e5be97499f"
---
# Tenancy Posture alignment — tier assurance claims
@ -41,9 +42,41 @@ rule that would catch a tier claiming isolation it cannot evidence. §11.3
requires the mapping be "recorded once when the tier is defined" — this repo owns
tier definition, so this repo owns the recording surface.
## Draft-6 update (2026-08-17)
The framework moved to **draft-6** (`net-kingdom` commit `2744ce7`) after this
workplan was written. It applies `tenant-engine`'s review only; **none of the
five findings below are addressed yet**, which is expected — T05 has not replied.
Three things in draft-6 change how we should proceed:
**The ratification test is proven, not theoretical.** tenant-engine assessed
itself, could not express itself in three places, and the document changed —
§4.1, §4.4, §5.2 and a new E registry exception. T06 now has live precedent to
cite rather than an invitation in §20.2.
**Draft-6 establishes exactly the shape findings 1 and 3 need.** The new
**registry exception** (declare an E level plus a named list of tables excluded
because they are registries, not tenant data) and **Decision 5.2** (a level
reports the weakest surface, not the best) both work by *level plus a named,
reviewable exception*. That is the pattern to reuse when proposing an
availability floor and a retention P floor — an amendment consistent with the
document's own new grammar is far cheaper to land than a novel one.
**The delivering service got weaker, and that is a sellability fact.**
`tenant-engine` self-corrected from a guessed `I2 A3 E2 P1 R1` down to
`I1 A2 E2 P— R0/R1` — acting identity arrives in the request body, three read
routes are unauthorized including the one `flex-auth` calls for `aal2`-class
decisions, and it is still on SQLite. Consequence for this repo: **no tier
resting on tenant-engine can make an isolation claim of any kind today.**
Nothing is blocked, because no tier makes one — but this is the concrete reason
T02/T03 should land before a tier author assumes otherwise.
## Findings against the framework
Raised for amendment, not as blockers. Detail belongs in T06.
Findings 15 were raised against draft-5 and all still stand in draft-6.
Findings 67 are new, from draft-6 itself.
1. **Availability has no ladder.** §11.3 and Q5 both require an availability
claim to map to "a minimum level the delivering service actually holds", but
@ -69,6 +102,21 @@ Raised for amendment, not as blockers. Detail belongs in T06.
5. **§8.3.1 constrains pricing design directly.** Co-residents are equal and no
resource governor exists, so a performance-differentiated tier is unsellable
below P2. This is a pricing-model validation rule, not only an ops fact.
6. **Off-ladder notation appears in a worked example.** Draft-6 records
`tenant-engine` as `P—` (still on SQLite, below P0's meaning) and `R0/R1` (a
dual value). Neither is on any ladder. This is the same wall T01 hit from the
other side: the ladders have no way to say *not on this axis at all*, so the
first two repos to try both invented notation. Strengthens T01's proposed
`not-applicable` declaration form — it is now a demonstrated gap with two
independent instances, not a special plea from a design-time repo.
7. **`P—` is a sellability fact with no home.** A tier's minimum is only as good
as the delivering service's actual level, and draft-6 shows that level can be
revised *downward* by a self-report at any time. Nothing in §11 obliges a
service to notify the tiers that depend on it when its posture drops. A tier
recorded as conformant at definition time can silently become an over-claim
through no act of its own — the same coupling as finding 3, one layer up.
Propose: a posture downgrade (§6 permits them, declared) must notify the
owners of any tier whose recorded minimum it breaches.
## Publish The Repo Posture Vector
@ -76,6 +124,7 @@ Raised for amendment, not as blockers. Detail belongs in T06.
id: ADAPTIVE-WP-0009-T01
status: todo
priority: high
state_hub_task_id: "870c32dc-89dd-415f-b45f-f9484dd5119b"
```
Publish `adaptive-pricing`'s posture vector per §5 / §20.2, declared in-repo
@ -102,6 +151,7 @@ pushed into a misleading `P0 R0`.
id: ADAPTIVE-WP-0009-T02
status: todo
priority: high
state_hub_task_id: "4420edb0-c9ea-4d2c-850e-2435cbd57f34"
```
Add an **optional** `assurance_claims` block to the canonical pricing schema
@ -127,6 +177,7 @@ Constraints:
id: ADAPTIVE-WP-0009-T03
status: todo
priority: high
state_hub_task_id: "96c3340d-2429-4901-800c-2c7144ab14f4"
```
Extend `adaptive_pricing_core/boundary_engine.py` with explainable rules, in
@ -151,6 +202,7 @@ conflation §3 exists to end.
id: ADAPTIVE-WP-0009-T04
status: todo
priority: medium
state_hub_task_id: "9821bc6b-d8ec-41e2-b4ea-ebf1f2dc91a6"
```
Wire the claim check into `adaptive_pricing_core/governance.py` as an approval
@ -168,6 +220,7 @@ definition; a gate that fires more often than that will be worked around.
id: ADAPTIVE-WP-0009-T05
status: wait
priority: high
state_hub_task_id: "3aa82ae3-4a79-4a18-a74e-668e94652ecd"
```
Blocked on T02/T03 for Q5, and on Bernd's decision for Q2.
@ -193,9 +246,17 @@ Reply on the State Hub to message `6d5293ca-4f69-46a6-a78e-b469e626b83d`.
id: ADAPTIVE-WP-0009-T06
status: todo
priority: medium
state_hub_task_id: "489cffb7-9ec3-4335-a93c-0b276a843f8d"
```
Submit the §"Findings" items to `net-kingdom` while v0.1 is still `proposed`.
**Frame them in draft-6's own grammar.** The registry exception and Decision 5.2
both work by *declared level plus a named, reviewable exception*, and draft-6
adopted tenant-engine's corrections wholesale because the ratification test said
it must. Amendments shaped like the ones already accepted will land; novel
structure will not. Cite `2744ce7` as precedent.
Proposed amendments:
- **An availability axis.** Prefer adding one over striking availability from
@ -214,7 +275,10 @@ Proposed amendments:
- **A primacy statement** for finding 4: the tier definition is authoritative
for the minimum; a service's `placement_exceptions` is derived and must
reconcile against it.
- **A `no-runtime-datastore` declaration form** for design-time repos (T01).
- **An off-ladder declaration form** covering both `no-runtime-datastore` (T01)
and draft-6's ad-hoc `P—` (finding 6). One notation, two instances already.
- **A downgrade-notification obligation** in §11 (finding 7): a declared posture
drop must reach the owners of any tier whose recorded minimum it breaches.
Route via `policy-nexus` if it owns canon publication; otherwise direct to
`rapp-postgres` as the raising agent and `net-kingdom` as canon owner.