repo.work.create_decision GH-DEC-2026-005
correlation_id: a62fcaea-d7f9-4b8a-9d68-d3e0e9a2fe14 reason: rmgr CLI source: repo-manager Assistant: claude-code Assistant-Model: opus Assistant-Process: 425128@bnt-lap001 Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
This commit is contained in:
parent
be18542cc6
commit
60e2e7de65
1 changed files with 35 additions and 0 deletions
|
|
@ -453,3 +453,38 @@ NetKingdom security profile, or if Info Tech Canon cannot provide a stable
|
||||||
cross-domain contract boundary. Reversal must still name one owner for every
|
cross-domain contract boundary. Reversal must still name one owner for every
|
||||||
artifact; returning to undifferentiated "Taxonomy ownership" is not an
|
artifact; returning to undifferentiated "Taxonomy ownership" is not an
|
||||||
acceptable outcome.
|
acceptable outcome.
|
||||||
|
|
||||||
|
## GH-DEC-2026-005 — The approval-claim is the step-1 artifact on the PEP consumption path
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
id: GH-DEC-2026-005
|
||||||
|
kind: decision
|
||||||
|
title: The approval-claim is the step-1 artifact on the PEP consumption path
|
||||||
|
status: resolved
|
||||||
|
owner: Bernd Worsch
|
||||||
|
repo: gate-house
|
||||||
|
standard: net-kingdom/canon/standards/security-layer-model_v0.7.md
|
||||||
|
source_note: docs/contracts/approval-consumption.md
|
||||||
|
origin: GH-IN-0002
|
||||||
|
requested_dispositions:
|
||||||
|
- approved
|
||||||
|
- revised
|
||||||
|
- rejected
|
||||||
|
affects:
|
||||||
|
- gate-house
|
||||||
|
- approval-engine
|
||||||
|
- flex-auth
|
||||||
|
- secrets-engine
|
||||||
|
- ops-warden
|
||||||
|
rationale: 'Confirmed, with one addition. GH-DEC-2026-003 already named step 1 by
|
||||||
|
endpoint and by field; the approval-claim is what that endpoint serves and valid_now
|
||||||
|
is its field. ActionAuthorization is a proposed, unratified shape carrying no doctrine
|
||||||
|
standing here. The addition is that the split validation is stated as doctrine rather
|
||||||
|
than left implicit: each artifact is checked by the consumer against the layer that
|
||||||
|
owns its data, and no PIP republishes a PDP decision. The state-hub authority requirement
|
||||||
|
in the secrets-engine validator is struck because State Hub is a read model and
|
||||||
|
holds no runtime approval authority.'
|
||||||
|
decided_by: Bernd Worsch
|
||||||
|
created: '2026-09-05T23:28:23.931441Z'
|
||||||
|
updated: '2026-09-05T23:28:23.931441Z'
|
||||||
|
```
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue