# Intake records ## FLEX-IN-0001 — Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split ```yaml id: FLEX-IN-0001 kind: intake title: 'Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split' status: open origin: cross-repo origin_ref: gate-house GH-DEC-2026-001 priority: high owner: flex-auth requested_by: gate-house standard: net-kingdom/canon/standards/security-layer-model_v0.1.md description: 'gate-house asks flex-auth to assent to three items ratified in GH-DEC-2026-001, following the estate precedent that a boundary is drawn on review by the other side rather than asserted — as flex-auth itself did to zone-engine. (1) flex-auth is Engine-layer and is NetKingdom’s only policy decision point; the INTENT reframe is already applied (commit fe46122) and can be revised or reverted if wrong. (2) The ruled rename flex-auth -> access-engine, NOT yet authorized to execute: it is a separate governed migration touching FLEX-WP prefix ownership, State Hub identifiers, ops-warden routing tables, zone-engine boundary text, and secrets-engine integrations. auth-engine was rejected because key-cape owns authentication. (3) The split: flex-auth owns evaluation exclusively plus the policy-as-code mechanism; gate-house owns doctrine, invariants, authority ceilings, operating modes, and the authority context consumed as input claims; policy content stays with the protected system owner. This resolves the FLEX-WP-0017 overlap — gate-house designs the approval contract, flex-auth validates approvals at decision time. Assent, revision, or rejection all acceptable; the standard stays proposed until this is answered.' created: '2026-08-28T19:30:03.602578Z' updated: '2026-08-28T19:30:03.602578Z' ```