flex-auth/intakes/intakes.md
tegwick cde77f0097
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assent to GH-DEC-2026-001 (FLEX-DEC-2026-001), closing FLEX-IN-0001
flex-auth answers gate-house's assent request on the three items ratified in
GH-DEC-2026-001, following the estate precedent that a boundary is drawn on
review by the other side.

Assent to all three, with one conformance debt flex-auth accepts as its own and
two conditions on the rename:

- Engine framing and sole decision point: assent. flex-auth cannot hold this
  boundary against zone-engine and decline it as a general rule. But standard
  section 6 also binds flex-auth: DecisionProvenance carries no registry
  snapshot digest, so a decision that turned on registry content cannot be
  replayed from its own provenance. Recorded as a known non-conformance rather
  than claimed as conformance.
- access-engine rename: assent to the name, not to execution. Repository
  identity and runtime identity must rename in separate revertible steps —
  since FLEX-WP-0016 the enforcing ops-warden pin binds tokens to the
  protected-system name, so a single-step rename 401s every warden sign,
  including the certificate the ops-bridge tunnels depend on. FLEX-WP prefix
  ownership stays with the repository.
- Authoring/evaluation split: assent, with the section 6 test applied
  symmetrically — a gate-house authority ceiling that determines an outcome
  reaches the decision as an input claim or as a rule in the versioned policy
  package, so its application stays reconstructable from the decision record.

FLEX-WP-0017-T03 stays wait: the design half re-routes to gate-house, the
durable storage half remains unowned and is raised as an engine gap under
section 5.

Decision id follows the canon scheme {PREFIX}-DEC-YYYY-NNN.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014348@bnt-lap001
Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
2026-08-28 21:47:06 +02:00

2.2 KiB
Raw Blame History

Intake records

FLEX-IN-0001 — Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split

id: FLEX-IN-0001
kind: intake
title: 'Assent requested: Engine framing, access-engine rename, and the authoring/evaluation
  split'
status: closed
origin: cross-repo
origin_ref: gate-house GH-DEC-2026-001
priority: high
owner: flex-auth
requested_by: gate-house
standard: net-kingdom/canon/standards/security-layer-model_v0.1.md
description: 'gate-house asks flex-auth to assent to three items ratified in GH-DEC-2026-001,
  following the estate precedent that a boundary is drawn on review by the other side
  rather than asserted — as flex-auth itself did to zone-engine. (1) flex-auth is
  Engine-layer and is NetKingdoms only policy decision point; the INTENT reframe
  is already applied (commit fe46122) and can be revised or reverted if wrong. (2)
  The ruled rename flex-auth -> access-engine, NOT yet authorized to execute: it is
  a separate governed migration touching FLEX-WP prefix ownership, State Hub identifiers,
  ops-warden routing tables, zone-engine boundary text, and secrets-engine integrations.
  auth-engine was rejected because key-cape owns authentication. (3) The split: flex-auth
  owns evaluation exclusively plus the policy-as-code mechanism; gate-house owns doctrine,
  invariants, authority ceilings, operating modes, and the authority context consumed
  as input claims; policy content stays with the protected system owner. This resolves
  the FLEX-WP-0017 overlap — gate-house designs the approval contract, flex-auth validates
  approvals at decision time. Assent, revision, or rejection all acceptable; the standard
  stays proposed until this is answered.'
created: '2026-08-28T19:30:03.602578Z'
updated: '2026-08-28T19:45:06.001794Z'
notes:
- content: 'Answered by FLEX-DEC-2026-001 (decisions/decisions.md): assent to all three
    items, with one accepted flex-auth conformance debt (registry snapshot absent
    from DecisionProvenance) and two conditions on the rename migration.'
  author: flex-auth
  created: '2026-08-28T19:45:04.030513Z'
closed_at: '2026-08-28T19:45:06.001794Z'
outcome: assented — see FLEX-DEC-2026-001