Apply GH-DEC-2026-017: INTENT.md governs, layer.yaml is derived, no version
Verified against gate-house's committed files before editing: GH-DEC-2026-017
in decisions/decisions.md and amendments A9-A13 in
docs/amendments/v0.8-section-11-declaration-amendments.md, then ops-warden's
reference change set (wiki/playbooks/netkingdom-layer-declaration.md and its
applied instance, ops-warden a70f559). Ruling and playbook agree.
layer.yaml: standard_version removed; marked derived: true / derived_from:
INTENT.md; header rewritten to say it does not govern and that a post-fold
disagreement between the forms is a finding. The Framework comment is
de-versioned for the same reason.
INTENT.md: the frontmatter layer: key is the declaration. It carried no
standard_version key, but its standard: path pinned _v0.7.md; de-versioned as
the reference instance did, since a pinned path reads as a validity condition.
Prose citing v0.7 as the accepted statute is left as is.
NO LAYER VALUE IS CHANGED. INTENT.md says Engine, layer.yaml says engine; the
section 3 vocabulary is closed and compared after an ASCII fold, so they agree.
No conformance checker exists in this repository, and no test reads
standard_version, so nothing else had to change with the field. Test suite:
156 passed. companion_version and schema_version are left untouched; the
ruling does not cover them.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 07:35:00 +02:00
|
|
|
# approval-engine — DERIVED form of the NetKingdom security layer declaration
|
2026-08-29 11:58:28 +02:00
|
|
|
#
|
Apply GH-DEC-2026-017: INTENT.md governs, layer.yaml is derived, no version
Verified against gate-house's committed files before editing: GH-DEC-2026-017
in decisions/decisions.md and amendments A9-A13 in
docs/amendments/v0.8-section-11-declaration-amendments.md, then ops-warden's
reference change set (wiki/playbooks/netkingdom-layer-declaration.md and its
applied instance, ops-warden a70f559). Ruling and playbook agree.
layer.yaml: standard_version removed; marked derived: true / derived_from:
INTENT.md; header rewritten to say it does not govern and that a post-fold
disagreement between the forms is a finding. The Framework comment is
de-versioned for the same reason.
INTENT.md: the frontmatter layer: key is the declaration. It carried no
standard_version key, but its standard: path pinned _v0.7.md; de-versioned as
the reference instance did, since a pinned path reads as a validity condition.
Prose citing v0.7 as the accepted statute is left as is.
NO LAYER VALUE IS CHANGED. INTENT.md says Engine, layer.yaml says engine; the
section 3 vocabulary is closed and compared after an ASCII fold, so they agree.
No conformance checker exists in this repository, and no test reads
standard_version, so nothing else had to change with the field. Test suite:
156 passed. companion_version and schema_version are left untouched; the
ruling does not cover them.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 07:35:00 +02:00
|
|
|
# THIS FILE DOES NOT GOVERN. The declaration is the `layer:` key in INTENT.md's
|
|
|
|
|
# frontmatter; this file is a derived artifact under §11's derived-artifact rule
|
|
|
|
|
# and must agree with it (GH-DEC-2026-017 §1, amendment A11). A disagreement
|
|
|
|
|
# between the two forms is a finding in its own right and is reported, never
|
|
|
|
|
# resolved away by precedence.
|
|
|
|
|
#
|
|
|
|
|
# INTENT.md says `Engine`, this file says `engine`. The §3 vocabulary is closed
|
|
|
|
|
# (Taxonomy, Tooling, Engine, Staff) and compared after an ASCII case fold
|
|
|
|
|
# (GH-DEC-2026-017 §2-§3, A9), so these are the same value. Neither is
|
|
|
|
|
# re-spelled; folding case is the checker's job.
|
|
|
|
|
#
|
|
|
|
|
# Framework: net-kingdom/canon/standards/security-layer-model
|
2026-08-29 11:58:28 +02:00
|
|
|
# Companion: net-kingdom/SECURITY-COMPANION.md v0.2
|
|
|
|
|
# Voice: INTENT.md (this repository's own, per §11 "who must declare")
|
|
|
|
|
#
|
|
|
|
|
# Reference form offered by ops-warden and adopted by audit-core and
|
|
|
|
|
# kings-guard. Prose cannot distinguish a declaration from a transcribed
|
|
|
|
|
# review; this file is the mechanical half.
|
|
|
|
|
|
|
|
|
|
schema_version: "0.1"
|
|
|
|
|
framework: netkingdom-security-layer-model
|
Apply GH-DEC-2026-017: INTENT.md governs, layer.yaml is derived, no version
Verified against gate-house's committed files before editing: GH-DEC-2026-017
in decisions/decisions.md and amendments A9-A13 in
docs/amendments/v0.8-section-11-declaration-amendments.md, then ops-warden's
reference change set (wiki/playbooks/netkingdom-layer-declaration.md and its
applied instance, ops-warden a70f559). Ruling and playbook agree.
layer.yaml: standard_version removed; marked derived: true / derived_from:
INTENT.md; header rewritten to say it does not govern and that a post-fold
disagreement between the forms is a finding. The Framework comment is
de-versioned for the same reason.
INTENT.md: the frontmatter layer: key is the declaration. It carried no
standard_version key, but its standard: path pinned _v0.7.md; de-versioned as
the reference instance did, since a pinned path reads as a validity condition.
Prose citing v0.7 as the accepted statute is left as is.
NO LAYER VALUE IS CHANGED. INTENT.md says Engine, layer.yaml says engine; the
section 3 vocabulary is closed and compared after an ASCII fold, so they agree.
No conformance checker exists in this repository, and no test reads
standard_version, so nothing else had to change with the field. Test suite:
156 passed. companion_version and schema_version are left untouched; the
ruling does not cover them.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 07:35:00 +02:00
|
|
|
|
|
|
|
|
# §11 derived-artifact marking (GH-DEC-2026-017 §1 / A11).
|
|
|
|
|
derived: true
|
|
|
|
|
derived_from: INTENT.md
|
|
|
|
|
|
|
|
|
|
# No `standard_version` key, here or in INTENT.md: GH-DEC-2026-017 §5 / A12 —
|
|
|
|
|
# a layer declaration MUST NOT carry a standard version. The declared layer is
|
|
|
|
|
# a standing property; version-scoped state belongs in the derived conformance
|
|
|
|
|
# record. Do not add it back.
|
2026-08-29 11:58:28 +02:00
|
|
|
companion_version: "0.2"
|
|
|
|
|
repository: approval-engine
|
|
|
|
|
layer: engine
|
|
|
|
|
role: pip # §3.3 engine typing; §4 catalog
|
|
|
|
|
declared_by: INTENT.md
|
|
|
|
|
declared_at: "2026-08-29"
|
|
|
|
|
|
|
|
|
|
# §4 catalog entry, transcribed so drift between the catalog and this file
|
|
|
|
|
# is visible. The statute is authoritative for the row.
|
|
|
|
|
catalog_entry:
|
|
|
|
|
owns:
|
|
|
|
|
- the approval object — durable, authenticated, consumable, atomically supersedable
|
|
|
|
|
statute: "§9.4"
|
|
|
|
|
|
|
|
|
|
# §3.3: a PIP supplies facts a decision consumes as claims. Outage is input
|
|
|
|
|
# degradation, which is this engine's fallback to own (§9.3).
|
|
|
|
|
# §6: no repository other than access-engine exposes an authorization decision.
|
|
|
|
|
decision_surfaces_exposed: none
|
|
|
|
|
|
|
|
|
|
# §9.4 — callers needing current state ask this engine. audit-core must not
|
|
|
|
|
# expose an approval-validity query; this engine must not expose a decision.
|
|
|
|
|
approval_validity_query: owned # current-state introspection, not a verdict on "may"
|
|
|
|
|
|
|
|
|
|
# §5 applies to Staff. This is an Engine. Its future transactional store is
|
|
|
|
|
# its own operational store, not a §4 Tooling row (same reasoning as
|
|
|
|
|
# audit-core's PostgreSQL custody).
|
|
|
|
|
tooling_contacts: []
|
|
|
|
|
|
Implement the engine spine: claim, outbox, machine, API
Contracts first (T02–T04): approval claim schema with issuer, freshness,
and binding digest; local transactional outbox wire; load-bearing cadence
as heartbeat or reconciliation (layer.yaml declared).
Then the object (T06–T08): SQLite closed state machine, CAS supersession,
distinct-approver fail-closed, revocation without holder cooperation,
outbox insert in the same transaction. Tests fail the mutation when
emission fails, and revoke while the drain sink is down.
Introspection GET /v1/approvals/{id}/claim is a PIP fact, not a decision.
No public consume (T05 waits on GH-WP-0002-T06). Canon T-06 coverage for
wrong binding, expiry, revoke, and supersede.
FLEX-WP-0017 T03 is unblocked on this object; T05 remains blocked only on
consumption ordering.
Assistant: grok
Assistant-Session: 01a04ceb-2057-7e20-b0f9-c282964d5dd9
2026-08-29 12:52:49 +02:00
|
|
|
# §11: record non-Tooling clients so the check is total. The SQLite store is
|
|
|
|
|
# this engine's own operational store, not a §4 Tooling row. Drain is a
|
|
|
|
|
# callback; no audit-core client is compiled in.
|
2026-08-29 11:58:28 +02:00
|
|
|
non_tooling_clients: []
|
|
|
|
|
|
|
|
|
|
intended_non_tooling_clients:
|
|
|
|
|
- target: audit-core
|
|
|
|
|
layer: engine
|
|
|
|
|
rationale: "Evidence destination for the local outbox drain. Engine API."
|
|
|
|
|
- target: access-engine
|
|
|
|
|
layer: engine
|
|
|
|
|
rationale: "Consumer of claims. This engine does not call it to decide."
|
|
|
|
|
- target: state-hub
|
|
|
|
|
layer: not-catalogued
|
|
|
|
|
rationale: >-
|
|
|
|
|
Progress events. Outside §5 by the v0.5 scope rule. Recorded, not
|
|
|
|
|
policed, and must not become a state plane another layer reads for
|
|
|
|
|
approval current-state.
|
|
|
|
|
|
|
|
|
|
# §9.6 — approval evidence is load-bearing. Atomicity prevents accidental
|
|
|
|
|
# omission; it does not prevent a compromised source. Cadence for
|
|
|
|
|
# low-volume load-bearing classes is reconciliation or a heartbeat.
|
|
|
|
|
evidence:
|
|
|
|
|
kind: load-bearing
|
Implement the engine spine: claim, outbox, machine, API
Contracts first (T02–T04): approval claim schema with issuer, freshness,
and binding digest; local transactional outbox wire; load-bearing cadence
as heartbeat or reconciliation (layer.yaml declared).
Then the object (T06–T08): SQLite closed state machine, CAS supersession,
distinct-approver fail-closed, revocation without holder cooperation,
outbox insert in the same transaction. Tests fail the mutation when
emission fails, and revoke while the drain sink is down.
Introspection GET /v1/approvals/{id}/claim is a PIP fact, not a decision.
No public consume (T05 waits on GH-WP-0002-T06). Canon T-06 coverage for
wrong binding, expiry, revoke, and supersede.
FLEX-WP-0017 T03 is unblocked on this object; T05 remains blocked only on
consumption ordering.
Assistant: grok
Assistant-Session: 01a04ceb-2057-7e20-b0f9-c282964d5dd9
2026-08-29 12:52:49 +02:00
|
|
|
atomicity: local-outbox
|
2026-08-29 11:58:28 +02:00
|
|
|
cadence_form: heartbeat-or-reconciliation
|
Implement the engine spine: claim, outbox, machine, API
Contracts first (T02–T04): approval claim schema with issuer, freshness,
and binding digest; local transactional outbox wire; load-bearing cadence
as heartbeat or reconciliation (layer.yaml declared).
Then the object (T06–T08): SQLite closed state machine, CAS supersession,
distinct-approver fail-closed, revocation without holder cooperation,
outbox insert in the same transaction. Tests fail the mutation when
emission fails, and revoke while the drain sink is down.
Introspection GET /v1/approvals/{id}/claim is a PIP fact, not a decision.
No public consume (T05 waits on GH-WP-0002-T06). Canon T-06 coverage for
wrong binding, expiry, revoke, and supersede.
FLEX-WP-0017 T03 is unblocked on this object; T05 remains blocked only on
consumption ordering.
Assistant: grok
Assistant-Session: 01a04ceb-2057-7e20-b0f9-c282964d5dd9
2026-08-29 12:52:49 +02:00
|
|
|
cadence_status: declared
|
|
|
|
|
cadence: cadence.yaml
|
2026-08-29 11:58:28 +02:00
|
|
|
residual: adversarial-omission-at-compromised-source
|
|
|
|
|
custody: same-bound-as-every-other-source # §16 decided: no stronger archive
|
|
|
|
|
|
|
|
|
|
declared_shapes:
|
|
|
|
|
"5.1": []
|
|
|
|
|
"5.2": []
|
|
|
|
|
"5.3": []
|