Assent to GH-DEC-2026-001 (FLEX-DEC-2026-001), closing FLEX-IN-0001
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

flex-auth answers gate-house's assent request on the three items ratified in
GH-DEC-2026-001, following the estate precedent that a boundary is drawn on
review by the other side.

Assent to all three, with one conformance debt flex-auth accepts as its own and
two conditions on the rename:

- Engine framing and sole decision point: assent. flex-auth cannot hold this
  boundary against zone-engine and decline it as a general rule. But standard
  section 6 also binds flex-auth: DecisionProvenance carries no registry
  snapshot digest, so a decision that turned on registry content cannot be
  replayed from its own provenance. Recorded as a known non-conformance rather
  than claimed as conformance.
- access-engine rename: assent to the name, not to execution. Repository
  identity and runtime identity must rename in separate revertible steps —
  since FLEX-WP-0016 the enforcing ops-warden pin binds tokens to the
  protected-system name, so a single-step rename 401s every warden sign,
  including the certificate the ops-bridge tunnels depend on. FLEX-WP prefix
  ownership stays with the repository.
- Authoring/evaluation split: assent, with the section 6 test applied
  symmetrically — a gate-house authority ceiling that determines an outcome
  reaches the decision as an input claim or as a rule in the versioned policy
  package, so its application stays reconstructable from the decision record.

FLEX-WP-0017-T03 stays wait: the design half re-routes to gate-house, the
durable storage half remains unowned and is raised as an engine gap under
section 5.

Decision id follows the canon scheme {PREFIX}-DEC-YYYY-NNN.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014348@bnt-lap001
Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
This commit is contained in:
tegwick 2026-08-28 21:47:06 +02:00
parent 8f815bb304
commit cde77f0097
6 changed files with 1157 additions and 9 deletions

View file

@ -18,10 +18,28 @@
> gate-house's authority context adopted as input claims, and the access
> lane/rule demarcation recorded.
>
> *Reframe applied. One item remains: the ruled rename to `access-engine`, which
> is a separate governed migration — it touches `FLEX-WP` prefix ownership, State
> Hub identifiers, ops-warden's routing tables, zone-engine's binding boundary
> text, and secrets-engine integrations — and is not authorized by GH-DEC-2026-001.*
> *Reframe applied. **Assent given on 2026-08-28** — `decisions/decisions.md`
> FLEX-DEC-2026-001, answering intake `FLEX-IN-0001`: flex-auth assents to the Engine
> framing, to `access-engine` as the ruled name, and to the authoring/evaluation
> split. One item remains: the rename itself, a separate governed migration — it
> touches `FLEX-WP` prefix ownership, State Hub identifiers, ops-warden's routing
> tables, zone-engine's binding boundary text, and secrets-engine integrations —
> and is not authorized by GH-DEC-2026-001. flex-auth adds two conditions on it
> (FLEX-DEC-2026-001 item 2): repository identity and runtime identity rename in
> separate revertible steps, repository first, because the enforcing ops-warden
> pin binds tokens to the protected-system name; and `FLEX-WP` prefix ownership
> stays with the repository.*
>
> **Known non-conformance — registry provenance.** Standard §6 holds that
> compiled data determining an outcome is still deciding, and that provenance
> must stay reconstructable from the decision. `DecisionProvenance` carries the
> evaluator, mode, policy package, policy version, and directory ETag, but no
> digest of the registry snapshot. A decision that turned on registry content
> cannot be replayed from its own provenance. flex-auth accepts this as its own
> gap rather than claiming conformance; until it is closed, outcome-determining
> content belongs in the versioned policy package, not the registry — for
> zone-engine's zone stance, for gate-house's authority ceilings, and for
> everyone else on the same terms.
> This file captures **why this repository exists**, the **direction it is
> moving toward**, and the **kind of system it is meant to become**.
@ -119,6 +137,15 @@ Gate House holds no runtime position and never renders a decision. A
deterministic authority boundary inside a non-deterministic layer would violate
the invariant the estate is built on.
One condition follows from that, drawn by flex-auth on review (FLEX-DEC-2026-001):
an authority ceiling that determines an outcome must reach the decision either
as an input claim on the request or as a rule in the versioned policy package,
so that its application is reconstructable from the decision record. A ceiling
that resolves an outcome before evaluation runs has decided early. This is not a
limit on gate-house's authorship — it is what keeps that authorship auditable at
decision time, and it is the same test flex-auth applied to zone-engine's zone
stance and, in the note above, to its own registry.
### Protected Systems Own Enforcement
Applications remain policy enforcement points. They extract resource