From 62dc8298e5daa7eb2bc5eba77303ee9444174f4b Mon Sep 17 00:00:00 2001 From: tegwick Date: Fri, 28 Aug 2026 22:01:08 +0200 Subject: [PATCH] Record assent outcome; point at standard v0.2 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit All three assent requests answered, each with a decision record and each with a finding. Standard revised to v0.2 and accepted. - history note gains §12 recording the outcome and what each repository returned. - README and CLAUDE.md now cite security-layer-model_v0.2.md. - GH-WP-0001-T03 closed. Three of the four v0.2 changes came from the assenting repositories rather than from gate-house. Co-Authored-By: Claude Opus 5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- CLAUDE.md | 5 +-- README.md | 2 +- ...curity-layer-model-and-gate-house-recut.md | 31 +++++++++++++++++++ 3 files changed, 35 insertions(+), 3 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index cadcaa6..cc08590 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -18,7 +18,7 @@ has lapsed — see the re-cut below. Gate House is the **council where NetKingdom's security and defence doctrine is established, documented, taught, and supervised** — a **Staff**-layer repository in the -NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.1.md`). +NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.2.md`, accepted). It holds no runtime position and renders no authorization decision. > **The mandate and the operating mode are Gate House's. The decision is access-engine's. @@ -141,7 +141,8 @@ the file, commit, then sync. `SCOPE.md` is derived from `INTENT.md` — keep the - History and reference notes → `history/YYYY-MM-DD-.md`, matching the convention in ops-warden, zone-engine, and secrets-engine. - Doctrine that stabilizes graduates into `net-kingdom/canon/standards/`, owned by gate-house - and published by net-kingdom. `security-layer-model_v0.1.md` is the first. + and published by net-kingdom. `security-layer-model_v0.2.md` is the first, and is accepted: + all three affected repositories assented, each returning a finding that changed it. - **No implementation layout.** Blueprint §32's reference tree (`api/`, `policy/`, `grants/`, `deploy/`, …) described the withdrawn engine and does not apply. If work here starts producing services, schemas that resolve, or anything evaluated at request time, stop — diff --git a/README.md b/README.md index 7080f12..92c9c44 100644 --- a/README.md +++ b/README.md @@ -25,7 +25,7 @@ anything depends on at runtime. NetKingdom's IT security is layered by determinism and by the kind of artifact each layer produces — see -[`net-kingdom/canon/standards/security-layer-model_v0.1.md`](../net-kingdom/canon/standards/security-layer-model_v0.1.md). +[`net-kingdom/canon/standards/security-layer-model_v0.2.md`](../net-kingdom/canon/standards/security-layer-model_v0.2.md). ```text Taxonomy cross-cutting language info-tech-canon, net-kingdom canon diff --git a/history/2026-08-28-security-layer-model-and-gate-house-recut.md b/history/2026-08-28-security-layer-model-and-gate-house-recut.md index 43730a6..432f19e 100644 --- a/history/2026-08-28-security-layer-model-and-gate-house-recut.md +++ b/history/2026-08-28-security-layer-model-and-gate-house-recut.md @@ -240,3 +240,34 @@ Open: 3. Adapt the other `INTENT.md` files that need clarification, and seek assent from flex-auth and ops-warden for the boundaries in §7. 4. Rewrite `GH-WP-0001`; revise the Blueprint per §10. + +--- + +## 12. Outcome — assent, and what it changed + +Added 2026-08-28, after the review closed. + +Assent was requested as intakes in the owning repositories (`FLEX-IN-0001`, +`KG-IN-0001`, `WARDEN-IN-0001`) with State Hub notification. All three assented, +each with its own decision record, and each returned a finding: + +- **flex-auth** (`FLEX-DEC-2026-001`) — assent to all three items, reasoning + that it *"cannot hold this boundary against zone-engine and decline it as a + general rule"*. Self-declared a non-conformance: `DecisionProvenance` carries + no digest of the registry snapshot, so a decision turning on registry content + is not replayable from its own provenance. Drew one boundary back at + gate-house: an authority ceiling that determines an outcome must reach the + decision as an input claim or a versioned policy rule. +- **kings-guard** (`KG-DEC-2026-001`) — assent, and **declined the offered + relaxation of §5**, arguing that latency and blast radius both argue for + keeping it and that a containment path bypassing the decision point becomes an + authority path the moment it is subverted. Raised the real defect instead: §4 + catalogued containment while §5 forbade the only route to discharging it. +- **ops-warden** (`ADR-0010`) — assent to all three; the access-engine veto was + not exercised. Grepped §5 as invited and self-reported a signing write to + OpenBao. Offered the amendment that became §5.3. + +The standard was revised to **v0.2** and accepted. Three of the four changes +came from the assenting repositories rather than from gate-house; the +conformance loop in §12 of that standard turned on first contact, which is the +only evidence so far against this repository's paper-generator falsifier.