Assent to GH-DEC-2026-001 (FLEX-DEC-2026-001), closing FLEX-IN-0001
flex-auth answers gate-house's assent request on the three items ratified in
GH-DEC-2026-001, following the estate precedent that a boundary is drawn on
review by the other side.
Assent to all three, with one conformance debt flex-auth accepts as its own and
two conditions on the rename:
- Engine framing and sole decision point: assent. flex-auth cannot hold this
boundary against zone-engine and decline it as a general rule. But standard
section 6 also binds flex-auth: DecisionProvenance carries no registry
snapshot digest, so a decision that turned on registry content cannot be
replayed from its own provenance. Recorded as a known non-conformance rather
than claimed as conformance.
- access-engine rename: assent to the name, not to execution. Repository
identity and runtime identity must rename in separate revertible steps —
since FLEX-WP-0016 the enforcing ops-warden pin binds tokens to the
protected-system name, so a single-step rename 401s every warden sign,
including the certificate the ops-bridge tunnels depend on. FLEX-WP prefix
ownership stays with the repository.
- Authoring/evaluation split: assent, with the section 6 test applied
symmetrically — a gate-house authority ceiling that determines an outcome
reaches the decision as an input claim or as a rule in the versioned policy
package, so its application stays reconstructable from the decision record.
FLEX-WP-0017-T03 stays wait: the design half re-routes to gate-house, the
durable storage half remains unowned and is raised as an engine gap under
section 5.
Decision id follows the canon scheme {PREFIX}-DEC-YYYY-NNN.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014348@bnt-lap001
Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
This commit is contained in:
parent
8f815bb304
commit
cde77f0097
6 changed files with 1157 additions and 9 deletions
1112
.repo-manager/index.json
Normal file
1112
.repo-manager/index.json
Normal file
File diff suppressed because it is too large
Load diff
35
INTENT.md
35
INTENT.md
|
|
@ -18,10 +18,28 @@
|
|||
> gate-house's authority context adopted as input claims, and the access
|
||||
> lane/rule demarcation recorded.
|
||||
>
|
||||
> *Reframe applied. One item remains: the ruled rename to `access-engine`, which
|
||||
> is a separate governed migration — it touches `FLEX-WP` prefix ownership, State
|
||||
> Hub identifiers, ops-warden's routing tables, zone-engine's binding boundary
|
||||
> text, and secrets-engine integrations — and is not authorized by GH-DEC-2026-001.*
|
||||
> *Reframe applied. **Assent given on 2026-08-28** — `decisions/decisions.md`
|
||||
> FLEX-DEC-2026-001, answering intake `FLEX-IN-0001`: flex-auth assents to the Engine
|
||||
> framing, to `access-engine` as the ruled name, and to the authoring/evaluation
|
||||
> split. One item remains: the rename itself, a separate governed migration — it
|
||||
> touches `FLEX-WP` prefix ownership, State Hub identifiers, ops-warden's routing
|
||||
> tables, zone-engine's binding boundary text, and secrets-engine integrations —
|
||||
> and is not authorized by GH-DEC-2026-001. flex-auth adds two conditions on it
|
||||
> (FLEX-DEC-2026-001 item 2): repository identity and runtime identity rename in
|
||||
> separate revertible steps, repository first, because the enforcing ops-warden
|
||||
> pin binds tokens to the protected-system name; and `FLEX-WP` prefix ownership
|
||||
> stays with the repository.*
|
||||
>
|
||||
> **Known non-conformance — registry provenance.** Standard §6 holds that
|
||||
> compiled data determining an outcome is still deciding, and that provenance
|
||||
> must stay reconstructable from the decision. `DecisionProvenance` carries the
|
||||
> evaluator, mode, policy package, policy version, and directory ETag, but no
|
||||
> digest of the registry snapshot. A decision that turned on registry content
|
||||
> cannot be replayed from its own provenance. flex-auth accepts this as its own
|
||||
> gap rather than claiming conformance; until it is closed, outcome-determining
|
||||
> content belongs in the versioned policy package, not the registry — for
|
||||
> zone-engine's zone stance, for gate-house's authority ceilings, and for
|
||||
> everyone else on the same terms.
|
||||
|
||||
> This file captures **why this repository exists**, the **direction it is
|
||||
> moving toward**, and the **kind of system it is meant to become**.
|
||||
|
|
@ -119,6 +137,15 @@ Gate House holds no runtime position and never renders a decision. A
|
|||
deterministic authority boundary inside a non-deterministic layer would violate
|
||||
the invariant the estate is built on.
|
||||
|
||||
One condition follows from that, drawn by flex-auth on review (FLEX-DEC-2026-001):
|
||||
an authority ceiling that determines an outcome must reach the decision either
|
||||
as an input claim on the request or as a rule in the versioned policy package,
|
||||
so that its application is reconstructable from the decision record. A ceiling
|
||||
that resolves an outcome before evaluation runs has decided early. This is not a
|
||||
limit on gate-house's authorship — it is what keeps that authorship auditable at
|
||||
decision time, and it is the same test flex-auth applied to zone-engine's zone
|
||||
stance and, in the note above, to its own registry.
|
||||
|
||||
### Protected Systems Own Enforcement
|
||||
|
||||
Applications remain policy enforcement points. They extract resource
|
||||
|
|
|
|||
|
|
@ -107,4 +107,4 @@
|
|||
| task | FLEX-WP-0017-T05 | wait | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
|
||||
| task | FLEX-WP-0018-T01 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
|
||||
| task | FLEX-WP-0018-T02 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
|
||||
| intake | FLEX-IN-0001 | open | — | intakes/intakes.md |
|
||||
| intake | FLEX-IN-0001 | closed | — | intakes/intakes.md |
|
||||
|
|
|
|||
|
|
@ -1,9 +1,9 @@
|
|||
# Decision records
|
||||
|
||||
## FLEX-DEC-0001 — Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split
|
||||
## FLEX-DEC-2026-001 — Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split
|
||||
|
||||
```yaml
|
||||
id: FLEX-DEC-0001
|
||||
id: FLEX-DEC-2026-001
|
||||
kind: decision
|
||||
title: 'Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation
|
||||
split'
|
||||
|
|
|
|||
|
|
@ -32,11 +32,11 @@ description: 'gate-house asks flex-auth to assent to three items ratified in GH-
|
|||
created: '2026-08-28T19:30:03.602578Z'
|
||||
updated: '2026-08-28T19:45:06.001794Z'
|
||||
notes:
|
||||
- content: 'Answered by FLEX-DEC-0001 (decisions/decisions.md): assent to all three
|
||||
- content: 'Answered by FLEX-DEC-2026-001 (decisions/decisions.md): assent to all three
|
||||
items, with one accepted flex-auth conformance debt (registry snapshot absent
|
||||
from DecisionProvenance) and two conditions on the rename migration.'
|
||||
author: flex-auth
|
||||
created: '2026-08-28T19:45:04.030513Z'
|
||||
closed_at: '2026-08-28T19:45:06.001794Z'
|
||||
outcome: assented — see FLEX-DEC-0001
|
||||
outcome: assented — see FLEX-DEC-2026-001
|
||||
```
|
||||
|
|
|
|||
|
|
@ -68,6 +68,15 @@ contract, authenticated approval entries, and atomic supersession. Its current
|
|||
No flex-auth-local substitute is acceptable because flex-auth does not own the
|
||||
organizational approval lifecycle.
|
||||
|
||||
Re-routed 2026-08-28 by FLEX-DEC-2026-001 (assent to gate-house GH-DEC-2026-001):
|
||||
under the authoring/evaluation split, gate-house designs the approval contract
|
||||
and flex-auth validates approvals at decision time. The *design* half of this
|
||||
task is therefore addressed to gate-house. The *storage and lifecycle* half —
|
||||
durable object, authenticated approval entries, atomic supersession — remains
|
||||
unowned: it is not gate-house's, because Staff holds no state another layer
|
||||
depends on at runtime (standard §3.4), and not flex-auth's, for the reason
|
||||
above. Raised to gate-house as an engine gap under §5. Task stays `wait`.
|
||||
|
||||
## Propagate bindings through delegated evaluators
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue