flex-auth/intakes/intakes.md
repo-manager 598d8fcbdf repo.work.add_intake_note FLEX-IN-0001
correlation_id: 00c286e3-7ee1-4a50-8494-eae74e0acf24
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014348@bnt-lap001
Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
2026-08-28 21:45:04 +02:00

40 lines
2.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Intake records
## FLEX-IN-0001 — Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split
```yaml
id: FLEX-IN-0001
kind: intake
title: 'Assent requested: Engine framing, access-engine rename, and the authoring/evaluation
split'
status: open
origin: cross-repo
origin_ref: gate-house GH-DEC-2026-001
priority: high
owner: flex-auth
requested_by: gate-house
standard: net-kingdom/canon/standards/security-layer-model_v0.1.md
description: 'gate-house asks flex-auth to assent to three items ratified in GH-DEC-2026-001,
following the estate precedent that a boundary is drawn on review by the other side
rather than asserted — as flex-auth itself did to zone-engine. (1) flex-auth is
Engine-layer and is NetKingdoms only policy decision point; the INTENT reframe
is already applied (commit fe46122) and can be revised or reverted if wrong. (2)
The ruled rename flex-auth -> access-engine, NOT yet authorized to execute: it is
a separate governed migration touching FLEX-WP prefix ownership, State Hub identifiers,
ops-warden routing tables, zone-engine boundary text, and secrets-engine integrations.
auth-engine was rejected because key-cape owns authentication. (3) The split: flex-auth
owns evaluation exclusively plus the policy-as-code mechanism; gate-house owns doctrine,
invariants, authority ceilings, operating modes, and the authority context consumed
as input claims; policy content stays with the protected system owner. This resolves
the FLEX-WP-0017 overlap — gate-house designs the approval contract, flex-auth validates
approvals at decision time. Assent, revision, or rejection all acceptable; the standard
stays proposed until this is answered.'
created: '2026-08-28T19:30:03.602578Z'
updated: '2026-08-28T19:45:04.030513Z'
notes:
- content: 'Answered by FLEX-DEC-0001 (decisions/decisions.md): assent to all three
items, with one accepted flex-auth conformance debt (registry snapshot absent
from DecisionProvenance) and two conditions on the rename migration.'
author: flex-auth
created: '2026-08-28T19:45:04.030513Z'
```