Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
|
|
|
---
|
|
|
|
|
id: GH-WP-0001
|
|
|
|
|
type: workplan
|
|
|
|
|
title: "Foundation"
|
|
|
|
|
domain: infotech
|
|
|
|
|
repo: gate-house
|
|
|
|
|
status: proposed
|
2026-08-25 17:51:10 +02:00
|
|
|
state_hub_workstream_id: "2ec4cf1a-a73f-5793-9738-8d8019cccca8"
|
Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
|
|
|
---
|
|
|
|
|
|
|
|
|
|
# Foundation
|
|
|
|
|
|
|
|
|
|
Establish the repository baseline and reach milestone **M0 — Executable Skeleton**
|
|
|
|
|
as defined in `ArchitectureBlueprint.md` §41: a request must produce a
|
|
|
|
|
deterministic `GRANT` / `DENY` with structured audit evidence.
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: GH-WP-0001-T01
|
|
|
|
|
status: todo
|
|
|
|
|
priority: high
|
2026-08-25 17:51:10 +02:00
|
|
|
state_hub_task_id: "af0fa778-89a8-52cf-a73a-021082a98cad"
|
Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Establish the repository baseline: classification, scope, agent instructions,
|
|
|
|
|
workplan spine.
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: GH-WP-0001-T02
|
|
|
|
|
status: todo
|
|
|
|
|
priority: high
|
2026-08-25 17:51:10 +02:00
|
|
|
state_hub_task_id: "6dd21d86-6546-58a7-b59e-fa1db72aae90"
|
Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Record the early ADRs that gate implementation choices — ADR-001 canonical
|
|
|
|
|
authority request schema, ADR-002 principal/actor/runtime identity model,
|
|
|
|
|
ADR-003 policy engine selection. Backlog in `ArchitectureBlueprint.md` §40.
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: GH-WP-0001-T03
|
|
|
|
|
status: todo
|
|
|
|
|
priority: high
|
2026-08-25 17:51:10 +02:00
|
|
|
state_hub_task_id: "12f651be-1c07-587b-a781-4472e189e218"
|
Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Define the canonical authorization request and decision schemas from
|
|
|
|
|
`ArchitectureBlueprint.md` §7 and §8.
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: GH-WP-0001-T04
|
|
|
|
|
status: todo
|
|
|
|
|
priority: medium
|
2026-08-25 17:51:10 +02:00
|
|
|
state_hub_task_id: "7903d142-9763-5b3f-839d-2a1599130a2b"
|
Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Implement the `/authorize` service skeleton with static policy and the
|
|
|
|
|
evaluation order in `ArchitectureBlueprint.md` §13, monotonic toward restriction.
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: GH-WP-0001-T05
|
|
|
|
|
status: todo
|
|
|
|
|
priority: medium
|
2026-08-25 17:51:10 +02:00
|
|
|
state_hub_task_id: "010e3162-cab1-5644-b262-b0d1d7d676f8"
|
Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Emit structured decision evidence for every authorization call, per
|
|
|
|
|
`ArchitectureBlueprint.md` §24.
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: GH-WP-0001-T06
|
|
|
|
|
status: todo
|
|
|
|
|
priority: medium
|
2026-08-25 17:51:10 +02:00
|
|
|
state_hub_task_id: "8cc018e1-2787-5435-9c2c-c2b01cf75ae4"
|
Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Seed the adversarial test suite with the fail-closed and self-escalation cases
|
|
|
|
|
(Canon T-04, T-09; `ArchitectureBlueprint.md` §34.4, §34.8).
|