ADAPTIVE-WP-0009: record draft-6 review outcome
Some checks failed
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Has been cancelled

Draft-6 (net-kingdom 2744ce7) applies tenant-engine's review only; findings
1-5 all still stand. Adds two findings from draft-6 itself: off-ladder
notation (P-, R0/R1) with no declaration form, and no obligation to notify
dependent tiers when a delivering service downgrades its posture. Reframes
T06 to reuse draft-6's level-plus-named-exception grammar.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-08-17 21:52:15 +02:00
parent e8ebd5cdd2
commit f759735aab

View file

@ -9,6 +9,7 @@ owner: codex
topic_slug: helix-forge topic_slug: helix-forge
created: "2026-08-17" created: "2026-08-17"
updated: "2026-08-17" updated: "2026-08-17"
state_hub_workstream_id: "ac4f4540-75a1-4dbf-9cb7-57e5be97499f"
--- ---
# Tenancy Posture alignment — tier assurance claims # Tenancy Posture alignment — tier assurance claims
@ -41,9 +42,41 @@ rule that would catch a tier claiming isolation it cannot evidence. §11.3
requires the mapping be "recorded once when the tier is defined" — this repo owns requires the mapping be "recorded once when the tier is defined" — this repo owns
tier definition, so this repo owns the recording surface. tier definition, so this repo owns the recording surface.
## Draft-6 update (2026-08-17)
The framework moved to **draft-6** (`net-kingdom` commit `2744ce7`) after this
workplan was written. It applies `tenant-engine`'s review only; **none of the
five findings below are addressed yet**, which is expected — T05 has not replied.
Three things in draft-6 change how we should proceed:
**The ratification test is proven, not theoretical.** tenant-engine assessed
itself, could not express itself in three places, and the document changed —
§4.1, §4.4, §5.2 and a new E registry exception. T06 now has live precedent to
cite rather than an invitation in §20.2.
**Draft-6 establishes exactly the shape findings 1 and 3 need.** The new
**registry exception** (declare an E level plus a named list of tables excluded
because they are registries, not tenant data) and **Decision 5.2** (a level
reports the weakest surface, not the best) both work by *level plus a named,
reviewable exception*. That is the pattern to reuse when proposing an
availability floor and a retention P floor — an amendment consistent with the
document's own new grammar is far cheaper to land than a novel one.
**The delivering service got weaker, and that is a sellability fact.**
`tenant-engine` self-corrected from a guessed `I2 A3 E2 P1 R1` down to
`I1 A2 E2 P— R0/R1` — acting identity arrives in the request body, three read
routes are unauthorized including the one `flex-auth` calls for `aal2`-class
decisions, and it is still on SQLite. Consequence for this repo: **no tier
resting on tenant-engine can make an isolation claim of any kind today.**
Nothing is blocked, because no tier makes one — but this is the concrete reason
T02/T03 should land before a tier author assumes otherwise.
## Findings against the framework ## Findings against the framework
Raised for amendment, not as blockers. Detail belongs in T06. Raised for amendment, not as blockers. Detail belongs in T06.
Findings 15 were raised against draft-5 and all still stand in draft-6.
Findings 67 are new, from draft-6 itself.
1. **Availability has no ladder.** §11.3 and Q5 both require an availability 1. **Availability has no ladder.** §11.3 and Q5 both require an availability
claim to map to "a minimum level the delivering service actually holds", but claim to map to "a minimum level the delivering service actually holds", but
@ -69,6 +102,21 @@ Raised for amendment, not as blockers. Detail belongs in T06.
5. **§8.3.1 constrains pricing design directly.** Co-residents are equal and no 5. **§8.3.1 constrains pricing design directly.** Co-residents are equal and no
resource governor exists, so a performance-differentiated tier is unsellable resource governor exists, so a performance-differentiated tier is unsellable
below P2. This is a pricing-model validation rule, not only an ops fact. below P2. This is a pricing-model validation rule, not only an ops fact.
6. **Off-ladder notation appears in a worked example.** Draft-6 records
`tenant-engine` as `P—` (still on SQLite, below P0's meaning) and `R0/R1` (a
dual value). Neither is on any ladder. This is the same wall T01 hit from the
other side: the ladders have no way to say *not on this axis at all*, so the
first two repos to try both invented notation. Strengthens T01's proposed
`not-applicable` declaration form — it is now a demonstrated gap with two
independent instances, not a special plea from a design-time repo.
7. **`P—` is a sellability fact with no home.** A tier's minimum is only as good
as the delivering service's actual level, and draft-6 shows that level can be
revised *downward* by a self-report at any time. Nothing in §11 obliges a
service to notify the tiers that depend on it when its posture drops. A tier
recorded as conformant at definition time can silently become an over-claim
through no act of its own — the same coupling as finding 3, one layer up.
Propose: a posture downgrade (§6 permits them, declared) must notify the
owners of any tier whose recorded minimum it breaches.
## Publish The Repo Posture Vector ## Publish The Repo Posture Vector
@ -76,6 +124,7 @@ Raised for amendment, not as blockers. Detail belongs in T06.
id: ADAPTIVE-WP-0009-T01 id: ADAPTIVE-WP-0009-T01
status: todo status: todo
priority: high priority: high
state_hub_task_id: "870c32dc-89dd-415f-b45f-f9484dd5119b"
``` ```
Publish `adaptive-pricing`'s posture vector per §5 / §20.2, declared in-repo Publish `adaptive-pricing`'s posture vector per §5 / §20.2, declared in-repo
@ -102,6 +151,7 @@ pushed into a misleading `P0 R0`.
id: ADAPTIVE-WP-0009-T02 id: ADAPTIVE-WP-0009-T02
status: todo status: todo
priority: high priority: high
state_hub_task_id: "4420edb0-c9ea-4d2c-850e-2435cbd57f34"
``` ```
Add an **optional** `assurance_claims` block to the canonical pricing schema Add an **optional** `assurance_claims` block to the canonical pricing schema
@ -127,6 +177,7 @@ Constraints:
id: ADAPTIVE-WP-0009-T03 id: ADAPTIVE-WP-0009-T03
status: todo status: todo
priority: high priority: high
state_hub_task_id: "96c3340d-2429-4901-800c-2c7144ab14f4"
``` ```
Extend `adaptive_pricing_core/boundary_engine.py` with explainable rules, in Extend `adaptive_pricing_core/boundary_engine.py` with explainable rules, in
@ -151,6 +202,7 @@ conflation §3 exists to end.
id: ADAPTIVE-WP-0009-T04 id: ADAPTIVE-WP-0009-T04
status: todo status: todo
priority: medium priority: medium
state_hub_task_id: "9821bc6b-d8ec-41e2-b4ea-ebf1f2dc91a6"
``` ```
Wire the claim check into `adaptive_pricing_core/governance.py` as an approval Wire the claim check into `adaptive_pricing_core/governance.py` as an approval
@ -168,6 +220,7 @@ definition; a gate that fires more often than that will be worked around.
id: ADAPTIVE-WP-0009-T05 id: ADAPTIVE-WP-0009-T05
status: wait status: wait
priority: high priority: high
state_hub_task_id: "3aa82ae3-4a79-4a18-a74e-668e94652ecd"
``` ```
Blocked on T02/T03 for Q5, and on Bernd's decision for Q2. Blocked on T02/T03 for Q5, and on Bernd's decision for Q2.
@ -193,9 +246,17 @@ Reply on the State Hub to message `6d5293ca-4f69-46a6-a78e-b469e626b83d`.
id: ADAPTIVE-WP-0009-T06 id: ADAPTIVE-WP-0009-T06
status: todo status: todo
priority: medium priority: medium
state_hub_task_id: "489cffb7-9ec3-4335-a93c-0b276a843f8d"
``` ```
Submit the §"Findings" items to `net-kingdom` while v0.1 is still `proposed`. Submit the §"Findings" items to `net-kingdom` while v0.1 is still `proposed`.
**Frame them in draft-6's own grammar.** The registry exception and Decision 5.2
both work by *declared level plus a named, reviewable exception*, and draft-6
adopted tenant-engine's corrections wholesale because the ratification test said
it must. Amendments shaped like the ones already accepted will land; novel
structure will not. Cite `2744ce7` as precedent.
Proposed amendments: Proposed amendments:
- **An availability axis.** Prefer adding one over striking availability from - **An availability axis.** Prefer adding one over striking availability from
@ -214,7 +275,10 @@ Proposed amendments:
- **A primacy statement** for finding 4: the tier definition is authoritative - **A primacy statement** for finding 4: the tier definition is authoritative
for the minimum; a service's `placement_exceptions` is derived and must for the minimum; a service's `placement_exceptions` is derived and must
reconcile against it. reconcile against it.
- **A `no-runtime-datastore` declaration form** for design-time repos (T01). - **An off-ladder declaration form** covering both `no-runtime-datastore` (T01)
and draft-6's ad-hoc `P—` (finding 6). One notation, two instances already.
- **A downgrade-notification obligation** in §11 (finding 7): a declared posture
drop must reach the owners of any tier whose recorded minimum it breaches.
Route via `policy-nexus` if it owns canon publication; otherwise direct to Route via `policy-nexus` if it owns canon publication; otherwise direct to
`rapp-postgres` as the raising agent and `net-kingdom` as canon owner. `rapp-postgres` as the raising agent and `net-kingdom` as canon owner.