Align to security layer model v0.7 and open the engine spine
The statute is accepted at v0.7; the operative form is net-kingdom/SECURITY-COMPANION.md v0.2. INTENT now declares Engine / PIP in its own voice, carries the §9.6 threat decomposition, the load-bearing heartbeat obligation, issuer and freshness on the claim, consumption as a mutation, and the custody question closed rather than held open. SCOPE.md is the first-cut boundary (nothing shipped). layer.yaml is the machine-readable declaration. The review under history/ scores intent vs scope vs the empty implementation. APPROVAL-WP-0001 sequences contracts before code and keeps consumption unimplemented until GH-WP-0002-T06. Registered with State Hub as infotech / approval-engine. Assistant: grok Assistant-Session: 01a04ceb-2057-7e20-b0f9-c282964d5dd9
This commit is contained in:
parent
ab5d69e8f1
commit
2a5a47df89
9 changed files with 1069 additions and 35 deletions
76
layer.yaml
Normal file
76
layer.yaml
Normal file
|
|
@ -0,0 +1,76 @@
|
|||
# approval-engine — NetKingdom security layer declaration
|
||||
#
|
||||
# Framework: net-kingdom/canon/standards/security-layer-model_v0.7.md
|
||||
# Companion: net-kingdom/SECURITY-COMPANION.md v0.2
|
||||
# Voice: INTENT.md (this repository's own, per §11 "who must declare")
|
||||
#
|
||||
# Reference form offered by ops-warden and adopted by audit-core and
|
||||
# kings-guard. Prose cannot distinguish a declaration from a transcribed
|
||||
# review; this file is the mechanical half.
|
||||
|
||||
schema_version: "0.1"
|
||||
framework: netkingdom-security-layer-model
|
||||
standard_version: "0.7"
|
||||
companion_version: "0.2"
|
||||
repository: approval-engine
|
||||
layer: engine
|
||||
role: pip # §3.3 engine typing; §4 catalog
|
||||
declared_by: INTENT.md
|
||||
declared_at: "2026-08-29"
|
||||
|
||||
# §4 catalog entry, transcribed so drift between the catalog and this file
|
||||
# is visible. The statute is authoritative for the row.
|
||||
catalog_entry:
|
||||
owns:
|
||||
- the approval object — durable, authenticated, consumable, atomically supersedable
|
||||
statute: "§9.4"
|
||||
|
||||
# §3.3: a PIP supplies facts a decision consumes as claims. Outage is input
|
||||
# degradation, which is this engine's fallback to own (§9.3).
|
||||
# §6: no repository other than access-engine exposes an authorization decision.
|
||||
decision_surfaces_exposed: none
|
||||
|
||||
# §9.4 — callers needing current state ask this engine. audit-core must not
|
||||
# expose an approval-validity query; this engine must not expose a decision.
|
||||
approval_validity_query: owned # current-state introspection, not a verdict on "may"
|
||||
|
||||
# §5 applies to Staff. This is an Engine. Its future transactional store is
|
||||
# its own operational store, not a §4 Tooling row (same reasoning as
|
||||
# audit-core's PostgreSQL custody).
|
||||
tooling_contacts: []
|
||||
|
||||
# §11: record non-Tooling clients so the check is total. None exist: there
|
||||
# is no runtime. Listed targets are the intended Engine APIs and the
|
||||
# uncatalogued hub write, to be filled in as code appears rather than
|
||||
# discovered later as silence.
|
||||
non_tooling_clients: []
|
||||
|
||||
intended_non_tooling_clients:
|
||||
- target: audit-core
|
||||
layer: engine
|
||||
rationale: "Evidence destination for the local outbox drain. Engine API."
|
||||
- target: access-engine
|
||||
layer: engine
|
||||
rationale: "Consumer of claims. This engine does not call it to decide."
|
||||
- target: state-hub
|
||||
layer: not-catalogued
|
||||
rationale: >-
|
||||
Progress events. Outside §5 by the v0.5 scope rule. Recorded, not
|
||||
policed, and must not become a state plane another layer reads for
|
||||
approval current-state.
|
||||
|
||||
# §9.6 — approval evidence is load-bearing. Atomicity prevents accidental
|
||||
# omission; it does not prevent a compromised source. Cadence for
|
||||
# low-volume load-bearing classes is reconciliation or a heartbeat.
|
||||
evidence:
|
||||
kind: load-bearing
|
||||
atomicity: local-outbox # required; not yet implemented
|
||||
cadence_form: heartbeat-or-reconciliation
|
||||
cadence_status: undeclared # APPROVAL-WP-0001-T04
|
||||
residual: adversarial-omission-at-compromised-source
|
||||
custody: same-bound-as-every-other-source # §16 decided: no stronger archive
|
||||
|
||||
declared_shapes:
|
||||
"5.1": []
|
||||
"5.2": []
|
||||
"5.3": []
|
||||
Loading…
Add table
Add a link
Reference in a new issue