diff --git a/workplans/ADAPTIVE-WP-0009-tenancy-posture-alignment.md b/workplans/ADAPTIVE-WP-0009-tenancy-posture-alignment.md index 966e04c..e1de8ab 100644 --- a/workplans/ADAPTIVE-WP-0009-tenancy-posture-alignment.md +++ b/workplans/ADAPTIVE-WP-0009-tenancy-posture-alignment.md @@ -9,6 +9,7 @@ owner: codex topic_slug: helix-forge created: "2026-08-17" updated: "2026-08-17" +state_hub_workstream_id: "ac4f4540-75a1-4dbf-9cb7-57e5be97499f" --- # Tenancy Posture alignment — tier assurance claims @@ -41,9 +42,41 @@ rule that would catch a tier claiming isolation it cannot evidence. §11.3 requires the mapping be "recorded once when the tier is defined" — this repo owns tier definition, so this repo owns the recording surface. +## Draft-6 update (2026-08-17) + +The framework moved to **draft-6** (`net-kingdom` commit `2744ce7`) after this +workplan was written. It applies `tenant-engine`'s review only; **none of the +five findings below are addressed yet**, which is expected — T05 has not replied. + +Three things in draft-6 change how we should proceed: + +**The ratification test is proven, not theoretical.** tenant-engine assessed +itself, could not express itself in three places, and the document changed — +§4.1, §4.4, §5.2 and a new E registry exception. T06 now has live precedent to +cite rather than an invitation in §20.2. + +**Draft-6 establishes exactly the shape findings 1 and 3 need.** The new +**registry exception** (declare an E level plus a named list of tables excluded +because they are registries, not tenant data) and **Decision 5.2** (a level +reports the weakest surface, not the best) both work by *level plus a named, +reviewable exception*. That is the pattern to reuse when proposing an +availability floor and a retention P floor — an amendment consistent with the +document's own new grammar is far cheaper to land than a novel one. + +**The delivering service got weaker, and that is a sellability fact.** +`tenant-engine` self-corrected from a guessed `I2 A3 E2 P1 R1` down to +`I1 A2 E2 P— R0/R1` — acting identity arrives in the request body, three read +routes are unauthorized including the one `flex-auth` calls for `aal2`-class +decisions, and it is still on SQLite. Consequence for this repo: **no tier +resting on tenant-engine can make an isolation claim of any kind today.** +Nothing is blocked, because no tier makes one — but this is the concrete reason +T02/T03 should land before a tier author assumes otherwise. + ## Findings against the framework Raised for amendment, not as blockers. Detail belongs in T06. +Findings 1–5 were raised against draft-5 and all still stand in draft-6. +Findings 6–7 are new, from draft-6 itself. 1. **Availability has no ladder.** §11.3 and Q5 both require an availability claim to map to "a minimum level the delivering service actually holds", but @@ -69,6 +102,21 @@ Raised for amendment, not as blockers. Detail belongs in T06. 5. **§8.3.1 constrains pricing design directly.** Co-residents are equal and no resource governor exists, so a performance-differentiated tier is unsellable below P2. This is a pricing-model validation rule, not only an ops fact. +6. **Off-ladder notation appears in a worked example.** Draft-6 records + `tenant-engine` as `P—` (still on SQLite, below P0's meaning) and `R0/R1` (a + dual value). Neither is on any ladder. This is the same wall T01 hit from the + other side: the ladders have no way to say *not on this axis at all*, so the + first two repos to try both invented notation. Strengthens T01's proposed + `not-applicable` declaration form — it is now a demonstrated gap with two + independent instances, not a special plea from a design-time repo. +7. **`P—` is a sellability fact with no home.** A tier's minimum is only as good + as the delivering service's actual level, and draft-6 shows that level can be + revised *downward* by a self-report at any time. Nothing in §11 obliges a + service to notify the tiers that depend on it when its posture drops. A tier + recorded as conformant at definition time can silently become an over-claim + through no act of its own — the same coupling as finding 3, one layer up. + Propose: a posture downgrade (§6 permits them, declared) must notify the + owners of any tier whose recorded minimum it breaches. ## Publish The Repo Posture Vector @@ -76,6 +124,7 @@ Raised for amendment, not as blockers. Detail belongs in T06. id: ADAPTIVE-WP-0009-T01 status: todo priority: high +state_hub_task_id: "870c32dc-89dd-415f-b45f-f9484dd5119b" ``` Publish `adaptive-pricing`'s posture vector per §5 / §20.2, declared in-repo @@ -102,6 +151,7 @@ pushed into a misleading `P0 R0`. id: ADAPTIVE-WP-0009-T02 status: todo priority: high +state_hub_task_id: "4420edb0-c9ea-4d2c-850e-2435cbd57f34" ``` Add an **optional** `assurance_claims` block to the canonical pricing schema @@ -127,6 +177,7 @@ Constraints: id: ADAPTIVE-WP-0009-T03 status: todo priority: high +state_hub_task_id: "96c3340d-2429-4901-800c-2c7144ab14f4" ``` Extend `adaptive_pricing_core/boundary_engine.py` with explainable rules, in @@ -151,6 +202,7 @@ conflation §3 exists to end. id: ADAPTIVE-WP-0009-T04 status: todo priority: medium +state_hub_task_id: "9821bc6b-d8ec-41e2-b4ea-ebf1f2dc91a6" ``` Wire the claim check into `adaptive_pricing_core/governance.py` as an approval @@ -168,6 +220,7 @@ definition; a gate that fires more often than that will be worked around. id: ADAPTIVE-WP-0009-T05 status: wait priority: high +state_hub_task_id: "3aa82ae3-4a79-4a18-a74e-668e94652ecd" ``` Blocked on T02/T03 for Q5, and on Bernd's decision for Q2. @@ -193,9 +246,17 @@ Reply on the State Hub to message `6d5293ca-4f69-46a6-a78e-b469e626b83d`. id: ADAPTIVE-WP-0009-T06 status: todo priority: medium +state_hub_task_id: "489cffb7-9ec3-4335-a93c-0b276a843f8d" ``` Submit the §"Findings" items to `net-kingdom` while v0.1 is still `proposed`. + +**Frame them in draft-6's own grammar.** The registry exception and Decision 5.2 +both work by *declared level plus a named, reviewable exception*, and draft-6 +adopted tenant-engine's corrections wholesale because the ratification test said +it must. Amendments shaped like the ones already accepted will land; novel +structure will not. Cite `2744ce7` as precedent. + Proposed amendments: - **An availability axis.** Prefer adding one over striking availability from @@ -214,7 +275,10 @@ Proposed amendments: - **A primacy statement** for finding 4: the tier definition is authoritative for the minimum; a service's `placement_exceptions` is derived and must reconcile against it. -- **A `no-runtime-datastore` declaration form** for design-time repos (T01). +- **An off-ladder declaration form** covering both `no-runtime-datastore` (T01) + and draft-6's ad-hoc `P—` (finding 6). One notation, two instances already. +- **A downgrade-notification obligation** in §11 (finding 7): a declared posture + drop must reach the owners of any tier whose recorded minimum it breaches. Route via `policy-nexus` if it owns canon publication; otherwise direct to `rapp-postgres` as the raising agent and `net-kingdom` as canon owner.