Align to security layer model v0.7 and open the engine spine

The statute is accepted at v0.7; the operative form is
net-kingdom/SECURITY-COMPANION.md v0.2. INTENT now declares Engine / PIP
in its own voice, carries the §9.6 threat decomposition, the load-bearing
heartbeat obligation, issuer and freshness on the claim, consumption as a
mutation, and the custody question closed rather than held open.

SCOPE.md is the first-cut boundary (nothing shipped). layer.yaml is the
machine-readable declaration. The review under history/ scores intent vs
scope vs the empty implementation. APPROVAL-WP-0001 sequences contracts
before code and keeps consumption unimplemented until GH-WP-0002-T06.

Registered with State Hub as infotech / approval-engine.

Assistant: grok
Assistant-Session: 01a04ceb-2057-7e20-b0f9-c282964d5dd9
This commit is contained in:
tegwick 2026-08-29 11:58:28 +02:00
parent ab5d69e8f1
commit 2a5a47df89
9 changed files with 1069 additions and 35 deletions

34
.custodian-brief.md Normal file
View file

@ -0,0 +1,34 @@
<!-- custodian-brief: generated by statehub register; fix-consistency may replace this file -->
# Custodian Brief - approval-engine
**Project:** approval-engine
**Domain:** infotech
**State Hub:** http://127.0.0.1:8000
**Topic ID:** `cee7bedf-2b48-46ef-8601-006474f2ad7a`
**Layer:** Engine / PIP (statute v0.7)
## Open Workplans
### v0.7 alignment and the engine spine
Workplan file: `workplans/APPROVAL-WP-0001-v07-alignment-and-engine-spine.md`
Open tasks:
- T01 - Align declaration to the accepted statute (done)
- T02 - Publish the approval claim contract
- T03 - Specify the local transactional-outbox contract
- T04 - Declare load-bearing cadence as heartbeat or reconciliation
- T05 - Wait on consumption ordering; do not implement it
- T06 - Durable object, closed state machine, authenticated entries
- T07 - Introspection API as input claims
- T08 - Local outbox in the mutation transaction
- T09 - Canon T-06 and the FLEX-WP-0017 handoff
## Session Start
1. Read `INTENT.md`, `SCOPE.md`, `layer.yaml`, and `AGENTS.md`.
2. Check inbox: `GET /messages/?to_agent=approval-engine&unread_only=true`.
3. Scan `workplans/`.
4. Update task statuses in workplan files as work progresses.
Last generated: 2026-08-29