Assent to GH-DEC-2026-001 (FLEX-DEC-2026-001), closing FLEX-IN-0001
flex-auth answers gate-house's assent request on the three items ratified in
GH-DEC-2026-001, following the estate precedent that a boundary is drawn on
review by the other side.
Assent to all three, with one conformance debt flex-auth accepts as its own and
two conditions on the rename:
- Engine framing and sole decision point: assent. flex-auth cannot hold this
boundary against zone-engine and decline it as a general rule. But standard
section 6 also binds flex-auth: DecisionProvenance carries no registry
snapshot digest, so a decision that turned on registry content cannot be
replayed from its own provenance. Recorded as a known non-conformance rather
than claimed as conformance.
- access-engine rename: assent to the name, not to execution. Repository
identity and runtime identity must rename in separate revertible steps —
since FLEX-WP-0016 the enforcing ops-warden pin binds tokens to the
protected-system name, so a single-step rename 401s every warden sign,
including the certificate the ops-bridge tunnels depend on. FLEX-WP prefix
ownership stays with the repository.
- Authoring/evaluation split: assent, with the section 6 test applied
symmetrically — a gate-house authority ceiling that determines an outcome
reaches the decision as an input claim or as a rule in the versioned policy
package, so its application stays reconstructable from the decision record.
FLEX-WP-0017-T03 stays wait: the design half re-routes to gate-house, the
durable storage half remains unowned and is raised as an engine gap under
section 5.
Decision id follows the canon scheme {PREFIX}-DEC-YYYY-NNN.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014348@bnt-lap001
Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
This commit is contained in:
parent
8f815bb304
commit
cde77f0097
6 changed files with 1157 additions and 9 deletions
|
|
@ -68,6 +68,15 @@ contract, authenticated approval entries, and atomic supersession. Its current
|
|||
No flex-auth-local substitute is acceptable because flex-auth does not own the
|
||||
organizational approval lifecycle.
|
||||
|
||||
Re-routed 2026-08-28 by FLEX-DEC-2026-001 (assent to gate-house GH-DEC-2026-001):
|
||||
under the authoring/evaluation split, gate-house designs the approval contract
|
||||
and flex-auth validates approvals at decision time. The *design* half of this
|
||||
task is therefore addressed to gate-house. The *storage and lifecycle* half —
|
||||
durable object, authenticated approval entries, atomic supersession — remains
|
||||
unowned: it is not gate-house's, because Staff holds no state another layer
|
||||
depends on at runtime (standard §3.4), and not flex-auth's, for the reason
|
||||
above. Raised to gate-house as an engine gap under §5. Task stays `wait`.
|
||||
|
||||
## Propagate bindings through delegated evaluators
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue