flex-auth/intakes/intakes.md
repo-manager e878db0f0b
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
repo.work.create_intake FLEX-IN-0001
correlation_id: 6ecb3fb9-f866-4c24-ad03-ba9e15915442
reason: Request assent for GH-DEC-2026-001 boundaries
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:30:03 +02:00

34 lines
1.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Intake records
## FLEX-IN-0001 — Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split
```yaml
id: FLEX-IN-0001
kind: intake
title: 'Assent requested: Engine framing, access-engine rename, and the authoring/evaluation
split'
status: open
origin: cross-repo
origin_ref: gate-house GH-DEC-2026-001
priority: high
owner: flex-auth
requested_by: gate-house
standard: net-kingdom/canon/standards/security-layer-model_v0.1.md
description: 'gate-house asks flex-auth to assent to three items ratified in GH-DEC-2026-001,
following the estate precedent that a boundary is drawn on review by the other side
rather than asserted — as flex-auth itself did to zone-engine. (1) flex-auth is
Engine-layer and is NetKingdoms only policy decision point; the INTENT reframe
is already applied (commit fe46122) and can be revised or reverted if wrong. (2)
The ruled rename flex-auth -> access-engine, NOT yet authorized to execute: it is
a separate governed migration touching FLEX-WP prefix ownership, State Hub identifiers,
ops-warden routing tables, zone-engine boundary text, and secrets-engine integrations.
auth-engine was rejected because key-cape owns authentication. (3) The split: flex-auth
owns evaluation exclusively plus the policy-as-code mechanism; gate-house owns doctrine,
invariants, authority ceilings, operating modes, and the authority context consumed
as input claims; policy content stays with the protected system owner. This resolves
the FLEX-WP-0017 overlap — gate-house designs the approval contract, flex-auth validates
approvals at decision time. Assent, revision, or rejection all acceptable; the standard
stays proposed until this is answered.'
created: '2026-08-28T19:30:03.602578Z'
updated: '2026-08-28T19:30:03.602578Z'
```