Assent to GH-DEC-2026-001 (FLEX-DEC-2026-001), closing FLEX-IN-0001
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

flex-auth answers gate-house's assent request on the three items ratified in
GH-DEC-2026-001, following the estate precedent that a boundary is drawn on
review by the other side.

Assent to all three, with one conformance debt flex-auth accepts as its own and
two conditions on the rename:

- Engine framing and sole decision point: assent. flex-auth cannot hold this
  boundary against zone-engine and decline it as a general rule. But standard
  section 6 also binds flex-auth: DecisionProvenance carries no registry
  snapshot digest, so a decision that turned on registry content cannot be
  replayed from its own provenance. Recorded as a known non-conformance rather
  than claimed as conformance.
- access-engine rename: assent to the name, not to execution. Repository
  identity and runtime identity must rename in separate revertible steps —
  since FLEX-WP-0016 the enforcing ops-warden pin binds tokens to the
  protected-system name, so a single-step rename 401s every warden sign,
  including the certificate the ops-bridge tunnels depend on. FLEX-WP prefix
  ownership stays with the repository.
- Authoring/evaluation split: assent, with the section 6 test applied
  symmetrically — a gate-house authority ceiling that determines an outcome
  reaches the decision as an input claim or as a rule in the versioned policy
  package, so its application stays reconstructable from the decision record.

FLEX-WP-0017-T03 stays wait: the design half re-routes to gate-house, the
durable storage half remains unowned and is raised as an engine gap under
section 5.

Decision id follows the canon scheme {PREFIX}-DEC-YYYY-NNN.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014348@bnt-lap001
Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
This commit is contained in:
tegwick 2026-08-28 21:47:06 +02:00
parent 8f815bb304
commit cde77f0097
6 changed files with 1157 additions and 9 deletions

1112
.repo-manager/index.json Normal file

File diff suppressed because it is too large Load diff

View file

@ -18,10 +18,28 @@
> gate-house's authority context adopted as input claims, and the access
> lane/rule demarcation recorded.
>
> *Reframe applied. One item remains: the ruled rename to `access-engine`, which
> is a separate governed migration — it touches `FLEX-WP` prefix ownership, State
> Hub identifiers, ops-warden's routing tables, zone-engine's binding boundary
> text, and secrets-engine integrations — and is not authorized by GH-DEC-2026-001.*
> *Reframe applied. **Assent given on 2026-08-28** — `decisions/decisions.md`
> FLEX-DEC-2026-001, answering intake `FLEX-IN-0001`: flex-auth assents to the Engine
> framing, to `access-engine` as the ruled name, and to the authoring/evaluation
> split. One item remains: the rename itself, a separate governed migration — it
> touches `FLEX-WP` prefix ownership, State Hub identifiers, ops-warden's routing
> tables, zone-engine's binding boundary text, and secrets-engine integrations —
> and is not authorized by GH-DEC-2026-001. flex-auth adds two conditions on it
> (FLEX-DEC-2026-001 item 2): repository identity and runtime identity rename in
> separate revertible steps, repository first, because the enforcing ops-warden
> pin binds tokens to the protected-system name; and `FLEX-WP` prefix ownership
> stays with the repository.*
>
> **Known non-conformance — registry provenance.** Standard §6 holds that
> compiled data determining an outcome is still deciding, and that provenance
> must stay reconstructable from the decision. `DecisionProvenance` carries the
> evaluator, mode, policy package, policy version, and directory ETag, but no
> digest of the registry snapshot. A decision that turned on registry content
> cannot be replayed from its own provenance. flex-auth accepts this as its own
> gap rather than claiming conformance; until it is closed, outcome-determining
> content belongs in the versioned policy package, not the registry — for
> zone-engine's zone stance, for gate-house's authority ceilings, and for
> everyone else on the same terms.
> This file captures **why this repository exists**, the **direction it is
> moving toward**, and the **kind of system it is meant to become**.
@ -119,6 +137,15 @@ Gate House holds no runtime position and never renders a decision. A
deterministic authority boundary inside a non-deterministic layer would violate
the invariant the estate is built on.
One condition follows from that, drawn by flex-auth on review (FLEX-DEC-2026-001):
an authority ceiling that determines an outcome must reach the decision either
as an input claim on the request or as a rule in the versioned policy package,
so that its application is reconstructable from the decision record. A ceiling
that resolves an outcome before evaluation runs has decided early. This is not a
limit on gate-house's authorship — it is what keeps that authorship auditable at
decision time, and it is the same test flex-auth applied to zone-engine's zone
stance and, in the note above, to its own registry.
### Protected Systems Own Enforcement
Applications remain policy enforcement points. They extract resource

View file

@ -107,4 +107,4 @@
| task | FLEX-WP-0017-T05 | wait | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
| task | FLEX-WP-0018-T01 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
| task | FLEX-WP-0018-T02 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
| intake | FLEX-IN-0001 | open | — | intakes/intakes.md |
| intake | FLEX-IN-0001 | closed | — | intakes/intakes.md |

View file

@ -1,9 +1,9 @@
# Decision records
## FLEX-DEC-0001 — Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split
## FLEX-DEC-2026-001 — Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split
```yaml
id: FLEX-DEC-0001
id: FLEX-DEC-2026-001
kind: decision
title: 'Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation
split'

View file

@ -32,11 +32,11 @@ description: 'gate-house asks flex-auth to assent to three items ratified in GH-
created: '2026-08-28T19:30:03.602578Z'
updated: '2026-08-28T19:45:06.001794Z'
notes:
- content: 'Answered by FLEX-DEC-0001 (decisions/decisions.md): assent to all three
- content: 'Answered by FLEX-DEC-2026-001 (decisions/decisions.md): assent to all three
items, with one accepted flex-auth conformance debt (registry snapshot absent
from DecisionProvenance) and two conditions on the rename migration.'
author: flex-auth
created: '2026-08-28T19:45:04.030513Z'
closed_at: '2026-08-28T19:45:06.001794Z'
outcome: assented — see FLEX-DEC-0001
outcome: assented — see FLEX-DEC-2026-001
```

View file

@ -68,6 +68,15 @@ contract, authenticated approval entries, and atomic supersession. Its current
No flex-auth-local substitute is acceptable because flex-auth does not own the
organizational approval lifecycle.
Re-routed 2026-08-28 by FLEX-DEC-2026-001 (assent to gate-house GH-DEC-2026-001):
under the authoring/evaluation split, gate-house designs the approval contract
and flex-auth validates approvals at decision time. The *design* half of this
task is therefore addressed to gate-house. The *storage and lifecycle* half —
durable object, authenticated approval entries, atomic supersession — remains
unowned: it is not gate-house's, because Staff holds no state another layer
depends on at runtime (standard §3.4), and not flex-auth's, for the reason
above. Raised to gate-house as an engine gap under §5. Task stays `wait`.
## Propagate bindings through delegated evaluators
```task