An engine for modelling and managing decisions.
Find a file
tegwick 39e3380447 Apply GH-DEC-2026-017: INTENT.md governs, layer.yaml is derived, no version
Verified against gate-house's committed files before editing: GH-DEC-2026-017
in decisions/decisions.md and amendments A9-A13 in
docs/amendments/v0.8-section-11-declaration-amendments.md, then ops-warden's
reference change set (wiki/playbooks/netkingdom-layer-declaration.md and its
applied instance, ops-warden a70f559). Ruling and playbook agree.

layer.yaml: standard_version removed; marked derived: true / derived_from:
INTENT.md; header rewritten to say it does not govern and that a post-fold
disagreement between the forms is a finding. The Framework comment is
de-versioned for the same reason.

INTENT.md: the frontmatter layer: key is the declaration. It carried no
standard_version key, but its standard: path pinned _v0.7.md; de-versioned as
the reference instance did, since a pinned path reads as a validity condition.
Prose citing v0.7 as the accepted statute is left as is.

NO LAYER VALUE IS CHANGED. INTENT.md says Engine, layer.yaml says engine; the
section 3 vocabulary is closed and compared after an ASCII fold, so they agree.

No conformance checker exists in this repository, and no test reads
standard_version, so nothing else had to change with the field. Test suite:
156 passed. companion_version and schema_version are left untouched; the
ruling does not cover them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 07:35:00 +02:00
approval_engine Heartbeat per event class, not per source 2026-09-10 20:36:21 +02:00
deploy Record T03 review admission and measured CPU request 2026-09-14 02:47:31 +02:00
docs Record T03 review admission and measured CPU request 2026-09-14 02:47:31 +02:00
examples Enforce declared human controls at approval binding 2026-09-10 19:26:12 +02:00
history Align to security layer model v0.7 and open the engine spine 2026-08-29 11:58:28 +02:00
intakes Record GH-DEC-2026-005; strike the spent G3 revisit trigger 2026-09-06 01:36:03 +02:00
schemas Enforce declared human controls at approval binding 2026-09-10 19:26:12 +02:00
tests Principal is the requesting party, not the approver 2026-09-10 22:43:33 +02:00
workplans Classify open workplans with flavor (CUST-WP-0072). 2026-09-14 15:50:41 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-14 01:10:28 +02:00
.gitignore Implement the engine spine: claim, outbox, machine, API 2026-08-29 12:52:49 +02:00
.repo-classification.yaml Add repo classification to close C-24/C-35 2026-08-29 14:43:52 +02:00
AGENTS.md Finish approval engine spine 2026-09-01 23:45:48 +02:00
cadence.yaml Finish approval engine spine 2026-09-01 23:45:48 +02:00
Containerfile Adopt Alpine as the sanctioned base; release candidate scans clean 2026-09-06 23:01:41 +02:00
INTENT.md Apply GH-DEC-2026-017: INTENT.md governs, layer.yaml is derived, no version 2026-09-21 07:35:00 +02:00
layer.yaml Apply GH-DEC-2026-017: INTENT.md governs, layer.yaml is derived, no version 2026-09-21 07:35:00 +02:00
Makefile Deploy approval service and verify native persistence and audit 2026-09-14 01:08:50 +02:00
pyproject.toml State pdp_digest explicitly; decline to publish a vocabulary mapping 2026-09-06 09:32:11 +02:00
README.md Harden the PEP harness and KeyCape registration request 2026-09-02 15:46:06 +02:00
SCOPE.md Harden the PEP harness and KeyCape registration request 2026-09-02 15:46:06 +02:00
WORK-RECORDS.md Sync approval deployment completion index 2026-09-14 01:11:44 +02:00

approval-engine

The approval as a durable, authenticated, consumable object — issued before an action, verified at the moment of use, and provably not replayable.

An Engine, role PIP, in the NetKingdom security layer model (statute v0.7, accepted; operative form net-kingdom/SECURITY-COMPANION.md). It answers one question, totally and decidably:

Is this approval valid right now — for this exact action, target, actor, and purpose — and has it already been used?

It does not decide whether the action is permitted. That is access-engine, which stays NetKingdom's only policy decision point. An approval is one input to that decision.

Deliberately small, boring, and strict: atomic supersession and single consumption are what make Canon test T-06 — Approval Replay passable. Flexibility here would be a defect. Graded, evidence-based progression belongs to maturity-engine; the two engines are deliberate opposites.

See INTENT.md and SCOPE.md. Declaration: layer.yaml. Claim: docs/approval-claim.md. Consume: docs/approval-consumption.md. Caller auth: docs/caller-authentication.md. PEP sequence: docs/pep-integration.md. Origin: flex-auth FLEX-DEC-2026-001, raised while assenting to the security layer model.

make test
approval-engine migrate --db approvals.sqlite
approval-engine verify --db approvals.sqlite
approval-engine serve --db approvals.sqlite \
  --jwt-issuer https://auth.netkingdom.local \
  --jwt-audience approval-engine \
  --jwks-url http://key-cape.sso.svc.cluster.local:8080/jwks

POST /v1/approvals/{id}/consume implements GH-DEC-2026-003: the PEP atomically spends the approval before the protected side effect. Same-digest retries are idempotent; a different digest conflicts.

Production operations, caller scopes, audit delivery, and PEP sequencing are documented in docs/storage-operations.md, docs/caller-authentication.md, docs/outbox-contract.md, and docs/pep-integration.md. The checked-in StatefulSet deliberately refuses production startup without a migrated persistent store, KeyCape JWT verification, and authenticated audit delivery.