From e878db0f0b4225e5976d98ed20babb37eab13d00 Mon Sep 17 00:00:00 2001 From: repo-manager Date: Fri, 28 Aug 2026 21:30:03 +0200 Subject: [PATCH] repo.work.create_intake FLEX-IN-0001 correlation_id: 6ecb3fb9-f866-4c24-ad03-ba9e15915442 reason: Request assent for GH-DEC-2026-001 boundaries source: repo-manager Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- intakes/intakes.md | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) create mode 100644 intakes/intakes.md diff --git a/intakes/intakes.md b/intakes/intakes.md new file mode 100644 index 0000000..20854ff --- /dev/null +++ b/intakes/intakes.md @@ -0,0 +1,34 @@ +# Intake records + +## FLEX-IN-0001 — Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split + +```yaml +id: FLEX-IN-0001 +kind: intake +title: 'Assent requested: Engine framing, access-engine rename, and the authoring/evaluation + split' +status: open +origin: cross-repo +origin_ref: gate-house GH-DEC-2026-001 +priority: high +owner: flex-auth +requested_by: gate-house +standard: net-kingdom/canon/standards/security-layer-model_v0.1.md +description: 'gate-house asks flex-auth to assent to three items ratified in GH-DEC-2026-001, + following the estate precedent that a boundary is drawn on review by the other side + rather than asserted — as flex-auth itself did to zone-engine. (1) flex-auth is + Engine-layer and is NetKingdom’s only policy decision point; the INTENT reframe + is already applied (commit fe46122) and can be revised or reverted if wrong. (2) + The ruled rename flex-auth -> access-engine, NOT yet authorized to execute: it is + a separate governed migration touching FLEX-WP prefix ownership, State Hub identifiers, + ops-warden routing tables, zone-engine boundary text, and secrets-engine integrations. + auth-engine was rejected because key-cape owns authentication. (3) The split: flex-auth + owns evaluation exclusively plus the policy-as-code mechanism; gate-house owns doctrine, + invariants, authority ceilings, operating modes, and the authority context consumed + as input claims; policy content stays with the protected system owner. This resolves + the FLEX-WP-0017 overlap — gate-house designs the approval contract, flex-auth validates + approvals at decision time. Assent, revision, or rejection all acceptable; the standard + stays proposed until this is answered.' +created: '2026-08-28T19:30:03.602578Z' +updated: '2026-08-28T19:30:03.602578Z' +```