Assent to GH-DEC-2026-001 (FLEX-DEC-2026-001), closing FLEX-IN-0001
flex-auth answers gate-house's assent request on the three items ratified in
GH-DEC-2026-001, following the estate precedent that a boundary is drawn on
review by the other side.
Assent to all three, with one conformance debt flex-auth accepts as its own and
two conditions on the rename:
- Engine framing and sole decision point: assent. flex-auth cannot hold this
boundary against zone-engine and decline it as a general rule. But standard
section 6 also binds flex-auth: DecisionProvenance carries no registry
snapshot digest, so a decision that turned on registry content cannot be
replayed from its own provenance. Recorded as a known non-conformance rather
than claimed as conformance.
- access-engine rename: assent to the name, not to execution. Repository
identity and runtime identity must rename in separate revertible steps —
since FLEX-WP-0016 the enforcing ops-warden pin binds tokens to the
protected-system name, so a single-step rename 401s every warden sign,
including the certificate the ops-bridge tunnels depend on. FLEX-WP prefix
ownership stays with the repository.
- Authoring/evaluation split: assent, with the section 6 test applied
symmetrically — a gate-house authority ceiling that determines an outcome
reaches the decision as an input claim or as a rule in the versioned policy
package, so its application stays reconstructable from the decision record.
FLEX-WP-0017-T03 stays wait: the design half re-routes to gate-house, the
durable storage half remains unowned and is raised as an engine gap under
section 5.
Decision id follows the canon scheme {PREFIX}-DEC-YYYY-NNN.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014348@bnt-lap001
Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
This commit is contained in:
parent
8f815bb304
commit
cde77f0097
6 changed files with 1157 additions and 9 deletions
1112
.repo-manager/index.json
Normal file
1112
.repo-manager/index.json
Normal file
File diff suppressed because it is too large
Load diff
35
INTENT.md
35
INTENT.md
|
|
@ -18,10 +18,28 @@
|
||||||
> gate-house's authority context adopted as input claims, and the access
|
> gate-house's authority context adopted as input claims, and the access
|
||||||
> lane/rule demarcation recorded.
|
> lane/rule demarcation recorded.
|
||||||
>
|
>
|
||||||
> *Reframe applied. One item remains: the ruled rename to `access-engine`, which
|
> *Reframe applied. **Assent given on 2026-08-28** — `decisions/decisions.md`
|
||||||
> is a separate governed migration — it touches `FLEX-WP` prefix ownership, State
|
> FLEX-DEC-2026-001, answering intake `FLEX-IN-0001`: flex-auth assents to the Engine
|
||||||
> Hub identifiers, ops-warden's routing tables, zone-engine's binding boundary
|
> framing, to `access-engine` as the ruled name, and to the authoring/evaluation
|
||||||
> text, and secrets-engine integrations — and is not authorized by GH-DEC-2026-001.*
|
> split. One item remains: the rename itself, a separate governed migration — it
|
||||||
|
> touches `FLEX-WP` prefix ownership, State Hub identifiers, ops-warden's routing
|
||||||
|
> tables, zone-engine's binding boundary text, and secrets-engine integrations —
|
||||||
|
> and is not authorized by GH-DEC-2026-001. flex-auth adds two conditions on it
|
||||||
|
> (FLEX-DEC-2026-001 item 2): repository identity and runtime identity rename in
|
||||||
|
> separate revertible steps, repository first, because the enforcing ops-warden
|
||||||
|
> pin binds tokens to the protected-system name; and `FLEX-WP` prefix ownership
|
||||||
|
> stays with the repository.*
|
||||||
|
>
|
||||||
|
> **Known non-conformance — registry provenance.** Standard §6 holds that
|
||||||
|
> compiled data determining an outcome is still deciding, and that provenance
|
||||||
|
> must stay reconstructable from the decision. `DecisionProvenance` carries the
|
||||||
|
> evaluator, mode, policy package, policy version, and directory ETag, but no
|
||||||
|
> digest of the registry snapshot. A decision that turned on registry content
|
||||||
|
> cannot be replayed from its own provenance. flex-auth accepts this as its own
|
||||||
|
> gap rather than claiming conformance; until it is closed, outcome-determining
|
||||||
|
> content belongs in the versioned policy package, not the registry — for
|
||||||
|
> zone-engine's zone stance, for gate-house's authority ceilings, and for
|
||||||
|
> everyone else on the same terms.
|
||||||
|
|
||||||
> This file captures **why this repository exists**, the **direction it is
|
> This file captures **why this repository exists**, the **direction it is
|
||||||
> moving toward**, and the **kind of system it is meant to become**.
|
> moving toward**, and the **kind of system it is meant to become**.
|
||||||
|
|
@ -119,6 +137,15 @@ Gate House holds no runtime position and never renders a decision. A
|
||||||
deterministic authority boundary inside a non-deterministic layer would violate
|
deterministic authority boundary inside a non-deterministic layer would violate
|
||||||
the invariant the estate is built on.
|
the invariant the estate is built on.
|
||||||
|
|
||||||
|
One condition follows from that, drawn by flex-auth on review (FLEX-DEC-2026-001):
|
||||||
|
an authority ceiling that determines an outcome must reach the decision either
|
||||||
|
as an input claim on the request or as a rule in the versioned policy package,
|
||||||
|
so that its application is reconstructable from the decision record. A ceiling
|
||||||
|
that resolves an outcome before evaluation runs has decided early. This is not a
|
||||||
|
limit on gate-house's authorship — it is what keeps that authorship auditable at
|
||||||
|
decision time, and it is the same test flex-auth applied to zone-engine's zone
|
||||||
|
stance and, in the note above, to its own registry.
|
||||||
|
|
||||||
### Protected Systems Own Enforcement
|
### Protected Systems Own Enforcement
|
||||||
|
|
||||||
Applications remain policy enforcement points. They extract resource
|
Applications remain policy enforcement points. They extract resource
|
||||||
|
|
|
||||||
|
|
@ -107,4 +107,4 @@
|
||||||
| task | FLEX-WP-0017-T05 | wait | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
|
| task | FLEX-WP-0017-T05 | wait | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
|
||||||
| task | FLEX-WP-0018-T01 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
|
| task | FLEX-WP-0018-T01 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
|
||||||
| task | FLEX-WP-0018-T02 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
|
| task | FLEX-WP-0018-T02 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
|
||||||
| intake | FLEX-IN-0001 | open | — | intakes/intakes.md |
|
| intake | FLEX-IN-0001 | closed | — | intakes/intakes.md |
|
||||||
|
|
|
||||||
|
|
@ -1,9 +1,9 @@
|
||||||
# Decision records
|
# Decision records
|
||||||
|
|
||||||
## FLEX-DEC-0001 — Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split
|
## FLEX-DEC-2026-001 — Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
id: FLEX-DEC-0001
|
id: FLEX-DEC-2026-001
|
||||||
kind: decision
|
kind: decision
|
||||||
title: 'Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation
|
title: 'Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation
|
||||||
split'
|
split'
|
||||||
|
|
|
||||||
|
|
@ -32,11 +32,11 @@ description: 'gate-house asks flex-auth to assent to three items ratified in GH-
|
||||||
created: '2026-08-28T19:30:03.602578Z'
|
created: '2026-08-28T19:30:03.602578Z'
|
||||||
updated: '2026-08-28T19:45:06.001794Z'
|
updated: '2026-08-28T19:45:06.001794Z'
|
||||||
notes:
|
notes:
|
||||||
- content: 'Answered by FLEX-DEC-0001 (decisions/decisions.md): assent to all three
|
- content: 'Answered by FLEX-DEC-2026-001 (decisions/decisions.md): assent to all three
|
||||||
items, with one accepted flex-auth conformance debt (registry snapshot absent
|
items, with one accepted flex-auth conformance debt (registry snapshot absent
|
||||||
from DecisionProvenance) and two conditions on the rename migration.'
|
from DecisionProvenance) and two conditions on the rename migration.'
|
||||||
author: flex-auth
|
author: flex-auth
|
||||||
created: '2026-08-28T19:45:04.030513Z'
|
created: '2026-08-28T19:45:04.030513Z'
|
||||||
closed_at: '2026-08-28T19:45:06.001794Z'
|
closed_at: '2026-08-28T19:45:06.001794Z'
|
||||||
outcome: assented — see FLEX-DEC-0001
|
outcome: assented — see FLEX-DEC-2026-001
|
||||||
```
|
```
|
||||||
|
|
|
||||||
|
|
@ -68,6 +68,15 @@ contract, authenticated approval entries, and atomic supersession. Its current
|
||||||
No flex-auth-local substitute is acceptable because flex-auth does not own the
|
No flex-auth-local substitute is acceptable because flex-auth does not own the
|
||||||
organizational approval lifecycle.
|
organizational approval lifecycle.
|
||||||
|
|
||||||
|
Re-routed 2026-08-28 by FLEX-DEC-2026-001 (assent to gate-house GH-DEC-2026-001):
|
||||||
|
under the authoring/evaluation split, gate-house designs the approval contract
|
||||||
|
and flex-auth validates approvals at decision time. The *design* half of this
|
||||||
|
task is therefore addressed to gate-house. The *storage and lifecycle* half —
|
||||||
|
durable object, authenticated approval entries, atomic supersession — remains
|
||||||
|
unowned: it is not gate-house's, because Staff holds no state another layer
|
||||||
|
depends on at runtime (standard §3.4), and not flex-auth's, for the reason
|
||||||
|
above. Raised to gate-house as an engine gap under §5. Task stays `wait`.
|
||||||
|
|
||||||
## Propagate bindings through delegated evaluators
|
## Propagate bindings through delegated evaluators
|
||||||
|
|
||||||
```task
|
```task
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue