Align INTENT and SCOPE to security layer model v0.7; plan conformance work
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

The standard was accepted at v0.7 on 2026-08-29. Four of flex-auth's review
findings are in the accepted text: 9.3's two-owner split, 6.4.2 scoped to the
decision's own binding with our canonical request digest as its mechanical test,
9.7.2 split by role, and 17 moving the decision-record schema to access-engine.

INTENT.md
- Machine-readable layer declaration in frontmatter (layer: Engine, role: PDP),
  which section 11 requires and we did not have. audit-core noted our
  declaration was legible only by following the decision trail.
- PDP failure semantics stated: our outage is consumer residue, not input
  degradation; fail-open is not expressible by a PDP at all.
- Four owned obligations added: the decision-record schema as our contract, the
  request digest as the published replay test, a lifetime on every allow, and
  visibility deadlines per input class.
- A Layer Conformance section stating the state honestly: conforming with one
  declared gap, no Tooling client, not PEP-shaped.
- Vocabulary correction: earlier text dropped "control plane" as Staff
  vocabulary. Section 8 binds it to the Engine layer, which is why kings-guard
  was asked to release it. The term is ours; we prefer "decision engine" for
  precision, not boundary.

SCOPE.md
- Layer and role in the one-liner; the four obligations In Scope; five
  boundaries established in review but never written down Out of Scope.
- Three capability blocks marked planned for workplans completed in May are now
  current; two blocks added.
- Superseded ADR-0006 citation corrected to ADR-0009, which retires the global
  flag outright rather than deferring it.

history/2026-08-29-layer-model-v0.7-alignment-review.md checks each obligation
against the code and finds six gaps. FLEX-WP-0019 closes them, with T02 before
T04 because a visibility deadline for registry-borne facts is unfalsifiable
until provenance can identify the snapshot a decision read.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014348@bnt-lap001
Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
This commit is contained in:
tegwick 2026-08-29 14:43:49 +02:00
parent 5753b47ccb
commit 0e2efa8fcf
6 changed files with 492 additions and 64 deletions

View file

@ -2,9 +2,9 @@
"schema": "repo_manager.index.v1",
"slug": "flex-auth",
"repo_root": "/home/worsch/flex-auth",
"head_sha": "54aae6b6b365407c102c511e30c392b459423be2",
"observed_at": "2026-08-29T00:42:15.556704Z",
"source_fingerprint": "3cadc015fd19f01f7381a51c7d7b0aa461f875bfe59253be427e9d5d8f373795",
"head_sha": "5753b47ccb72f96689df9ec5eeb7be100f6817cd",
"observed_at": "2026-08-29T08:19:42.754823Z",
"source_fingerprint": "2d3773fc38408c64d1a9a4efc7335ed792f361cdf6464f04389615c9b443fa53",
"source_files": [
".repo-classification.yaml",
"INTENT.md",
@ -1071,7 +1071,7 @@
"status": "resolved",
"title": "Review of security layer model v0.4: assent with findings, one rule contested",
"source_path": "decisions/decisions.md",
"uuid": null,
"uuid": "2e96321d-c7bf-4127-9c30-f3def32e5bee",
"parent_id": null,
"extra": {
"record": {
@ -1101,7 +1101,47 @@
"updated": "2026-08-29T00:42:13.009799Z",
"rationale": "Assent to security-layer-model v0.4, with one rule contested and two capability assignments not accepted as assented. Section 9.3 conflicts with shipped assented behavior: it rules engine-unreachability fallback into the engine, where it cannot live, and collides with ops-warden ADR-0009's per-zone consumer PEP map. Section 13 names access-engine as intended owner of containment (accept as proposed owner only, pending per 9.2) and of authentication/assurance evidence (declined as stated; the identity layer and audit-core own that). Three consistency defects: frontmatter status proposed contradicts section 14 'accepted'; the adoption count reads seven of fifteen with remaining eight against sixteen estate-authored repositories and nine listed; section 14 says three repositories above a table of four. FLEX-IN-0002 answered: the approval boundary unblocks T03 design, T05 additionally needs the approval claim bound to the NewDecisionBinding request digest and a named owner and ordering for single consumption; the maturity claim route is practical as a request claim but not as registry content until the self-declared provenance digest gap closes.",
"decided_by": "flex-auth (reviewing side)",
"decided_at": "2026-08-29T00:42:13.009799Z"
"decided_at": "2026-08-29T00:42:13.009799Z",
"state_hub_decision_id": "2e96321d-c7bf-4127-9c30-f3def32e5bee"
}
}
},
{
"kind": "decision",
"id": "FLEX-DEC-2026-003",
"status": "resolved",
"title": "Review of security layer model v0.6 and companion v0.1: assent, two answers, five findings",
"source_path": "decisions/decisions.md",
"uuid": null,
"parent_id": null,
"extra": {
"record": {
"id": "FLEX-DEC-2026-003",
"kind": "decision",
"title": "Review of security layer model v0.6 and companion v0.1: assent, two answers, five findings",
"status": "resolved",
"origin": "cross-repo",
"origin_ref": "net-kingdom security-layer-model_v0.6 + companion_v0.1",
"standard": "net-kingdom/canon/standards/security-layer-model_v0.6.md",
"owner": "flex-auth",
"affects": [
"flex-auth",
"gate-house",
"net-kingdom",
"info-tech-canon",
"ops-warden",
"approval-engine"
],
"requested_dispositions": [
"assent",
"revise",
"reject"
],
"created": "2026-08-29T08:18:39.602701Z",
"updated": "2026-08-29T08:19:41.832549Z",
"rationale": "Assent to v0.6 and companion v0.1, with two answers and five findings, none blocking. Q1: section 6.4.2 is right but collides with 9.7.1's session-bound allow, needs the request digest as its mechanical replay test, and should rule explicitly on deny-caching. Q2: the visibility deadline does land on a PDP and harder than at a PEP, but must be per input class rather than one number, and it makes flex-auth's registry-provenance gap load-bearing rather than untidy. Findings: 6.4's stance-map register does not exist in section 13 and neither document says where a map is published; the companion omits it too, which is the sufficiency gap gate-house asked for; section 17 puts the decision-record schema in Taxonomy when it is the PDP's output artifact, inverting the section 2 rule flex-auth used to decline authentication evidence; sections 17-19 are H1 outside the hierarchy; section 19 grades the document it lives in and will age.",
"decided_by": "flex-auth (reviewing side)",
"decided_at": "2026-08-29T08:19:41.832549Z"
}
}
},
@ -1147,7 +1187,7 @@
"status": "closed",
"title": "Review requested: security layer model v0.3 (approval-engine, maturity-engine)",
"source_path": "intakes/intakes.md",
"uuid": null,
"uuid": "01a04afa-307b-7e9e-b210-261badabcec7",
"parent_id": null,
"extra": {
"record": {
@ -1171,7 +1211,8 @@
}
],
"closed_at": "2026-08-29T00:42:14.888434Z",
"outcome": "assented with findings \u2014 see FLEX-DEC-2026-002"
"outcome": "assented with findings \u2014 see FLEX-DEC-2026-002",
"state_hub_intake_id": "01a04afa-307b-7e9e-b210-261badabcec7"
}
}
}
@ -1179,17 +1220,17 @@
"events": [
{
"type": "repo.command.applied",
"command": "repo.work.close_intake",
"operation": "close",
"correlation_id": "1e832e3c-4e51-4dfd-919d-40593c18b2ab",
"kind": "intake",
"id": "FLEX-IN-0002",
"git_sha": "54aae6b6b365407c102c511e30c392b459423be2",
"command": "repo.work.resolve_decision",
"operation": "resolve",
"correlation_id": "fe430c1e-83bb-4dba-b6fc-337baa1a0059",
"kind": "decision",
"id": "FLEX-DEC-2026-003",
"git_sha": "5753b47ccb72f96689df9ec5eeb7be100f6817cd",
"files_touched": [
"intakes/intakes.md"
"decisions/decisions.md"
],
"source": "repo-manager",
"emitted_at": "2026-08-29T00:42:15.556791Z"
"emitted_at": "2026-08-29T08:19:42.754925Z"
}
]
}