docs/stance-register-review.md is published, dated 2026-09-06, and titled "the register has a second row". Three things moved under it: §13.1 now carries five rows rather than two, v0.8 §6.4 obligation 3 ruled that unknown is not a zone and must resolve to fail_closed, and two rows are now marked non-conformant. The review's closing line warned that the cost of two incommensurable axes is small and the cost of five is not. Five arrived in fourteen days. The plan supersedes rather than amends: a published review silently rewritten to match the world is FLEX-DEC-2026-008's defect, and flex-auth does not exempt its own artifacts from a rule it holds others to. Recorded accurately rather than flatteringly — the divergence was resolved by gate-house doctrine in secrets-engine's direction, not by flex-auth's review, and ops-warden's marked-non-conformant row is right to stay unconverted until WARDEN-WP-0040 raises zone coverage. Conformance and correctness have come apart on that cell. INTENT.md stays at standard_version 0.7: v0.8 is still proposed, and the trigger for the bump is stated in T04 so it is not "fixed" early. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 28468@bnt-lap001 Assistant-Session: c76569b2-6056-4dad-aea4-49cd7a018f5d |
||
|---|---|---|
| .claude/rules | ||
| .forgejo/workflows | ||
| .github/workflows | ||
| .repo-manager | ||
| charts/flex-auth | ||
| cmd/flex-auth | ||
| decisions | ||
| deploy | ||
| docs | ||
| examples | ||
| history | ||
| intakes | ||
| internal | ||
| pkg/api | ||
| railiance | ||
| registry | ||
| schemas | ||
| tests | ||
| tools | ||
| values | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .golangci.yml | ||
| .repo-classification.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| Containerfile | ||
| Containerfile.t03-review | ||
| go.mod | ||
| go.sum | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
| SCOPE.md | ||
| tenancy.yaml | ||
| WORK-RECORDS.md | ||
flex-auth
Policy-as-code authorization registry and control plane for NetKingdom-aligned systems.
The live Forge and State Hub coordinate is still flex-auth (repository UUID
fda8ad85-a7d7-4055-8f21-902a533e59df, Forge ID 42). FLEX-WP-0020 will
rename that coordinate to access-engine and keep the Go module, binary,
FLEX_AUTH_* variables, Helm releases, container package
coulomb/flex-auth, and policy/API vocabulary unchanged. Work-record
frontmatter stays repo: flex-auth until State Hub rebind. Planned clone:
https://forgejo.coulomb.social/coulomb/access-engine.git.
Start with INTENT.md for the project boundary and direction. Research notes and ADRs live in docs/ and docs/adr/.
The product boundary is captured in SCOPE.md, and the current Product Requirements Document is docs/ProductRequirementsDocument.md.
The 2026-05-15 pre-implementation assessment that shapes the current sequencing is in docs/pre-implementation-assessment.md.
The CARING reference-implementation approach is captured in docs/caring-architecture-blueprint.md.
Workplans live in workplans/, with sequencing captured in docs/workplan-planning-map.md.