The statute is accepted at v0.7; the operative form is net-kingdom/SECURITY-COMPANION.md v0.2. INTENT now declares Engine / PIP in its own voice, carries the §9.6 threat decomposition, the load-bearing heartbeat obligation, issuer and freshness on the claim, consumption as a mutation, and the custody question closed rather than held open. SCOPE.md is the first-cut boundary (nothing shipped). layer.yaml is the machine-readable declaration. The review under history/ scores intent vs scope vs the empty implementation. APPROVAL-WP-0001 sequences contracts before code and keeps consumption unimplemented until GH-WP-0002-T06. Registered with State Hub as infotech / approval-engine. Assistant: grok Assistant-Session: 01a04ceb-2057-7e20-b0f9-c282964d5dd9
24 lines
1.1 KiB
Markdown
24 lines
1.1 KiB
Markdown
# approval-engine
|
|
|
|
**The approval as a durable, authenticated, consumable object — issued before an
|
|
action, verified at the moment of use, and provably not replayable.**
|
|
|
|
An Engine, role **PIP**, in the NetKingdom security layer model (statute v0.7,
|
|
accepted; operative form `net-kingdom/SECURITY-COMPANION.md`). It answers one
|
|
question, totally and decidably:
|
|
|
|
> Is this approval valid right now — for this exact action, target, actor, and
|
|
> purpose — and has it already been used?
|
|
|
|
It does **not** decide whether the action is permitted. That is `access-engine`,
|
|
which stays NetKingdom's only policy decision point. An approval is one input to
|
|
that decision.
|
|
|
|
Deliberately small, boring, and strict: atomic supersession and single
|
|
consumption are what make Canon test `T-06 — Approval Replay` passable.
|
|
Flexibility here would be a defect. Graded, evidence-based progression belongs to
|
|
`maturity-engine`; the two engines are deliberate opposites.
|
|
|
|
See [INTENT.md](INTENT.md) and [SCOPE.md](SCOPE.md). Declaration: [layer.yaml](layer.yaml).
|
|
Origin: `flex-auth` `FLEX-DEC-2026-001`, raised while assenting to the security
|
|
layer model.
|