Record assent outcome; point at standard v0.2
All three assent requests answered, each with a decision record and each with a finding. Standard revised to v0.2 and accepted. - history note gains §12 recording the outcome and what each repository returned. - README and CLAUDE.md now cite security-layer-model_v0.2.md. - GH-WP-0001-T03 closed. Three of the four v0.2 changes came from the assenting repositories rather than from gate-house. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
parent
347524751e
commit
62dc8298e5
3 changed files with 35 additions and 3 deletions
|
|
@ -18,7 +18,7 @@ has lapsed — see the re-cut below.
|
||||||
|
|
||||||
Gate House is the **council where NetKingdom's security and defence doctrine is
|
Gate House is the **council where NetKingdom's security and defence doctrine is
|
||||||
established, documented, taught, and supervised** — a **Staff**-layer repository in the
|
established, documented, taught, and supervised** — a **Staff**-layer repository in the
|
||||||
NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.1.md`).
|
NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.2.md`, accepted).
|
||||||
It holds no runtime position and renders no authorization decision.
|
It holds no runtime position and renders no authorization decision.
|
||||||
|
|
||||||
> **The mandate and the operating mode are Gate House's. The decision is access-engine's.
|
> **The mandate and the operating mode are Gate House's. The decision is access-engine's.
|
||||||
|
|
@ -141,7 +141,8 @@ the file, commit, then sync. `SCOPE.md` is derived from `INTENT.md` — keep the
|
||||||
- History and reference notes → `history/YYYY-MM-DD-<slug>.md`, matching the convention in
|
- History and reference notes → `history/YYYY-MM-DD-<slug>.md`, matching the convention in
|
||||||
ops-warden, zone-engine, and secrets-engine.
|
ops-warden, zone-engine, and secrets-engine.
|
||||||
- Doctrine that stabilizes graduates into `net-kingdom/canon/standards/`, owned by gate-house
|
- Doctrine that stabilizes graduates into `net-kingdom/canon/standards/`, owned by gate-house
|
||||||
and published by net-kingdom. `security-layer-model_v0.1.md` is the first.
|
and published by net-kingdom. `security-layer-model_v0.2.md` is the first, and is accepted:
|
||||||
|
all three affected repositories assented, each returning a finding that changed it.
|
||||||
- **No implementation layout.** Blueprint §32's reference tree (`api/`, `policy/`, `grants/`,
|
- **No implementation layout.** Blueprint §32's reference tree (`api/`, `policy/`, `grants/`,
|
||||||
`deploy/`, …) described the withdrawn engine and does not apply. If work here starts
|
`deploy/`, …) described the withdrawn engine and does not apply. If work here starts
|
||||||
producing services, schemas that resolve, or anything evaluated at request time, stop —
|
producing services, schemas that resolve, or anything evaluated at request time, stop —
|
||||||
|
|
|
||||||
|
|
@ -25,7 +25,7 @@ anything depends on at runtime.
|
||||||
|
|
||||||
NetKingdom's IT security is layered by determinism and by the kind of artifact
|
NetKingdom's IT security is layered by determinism and by the kind of artifact
|
||||||
each layer produces — see
|
each layer produces — see
|
||||||
[`net-kingdom/canon/standards/security-layer-model_v0.1.md`](../net-kingdom/canon/standards/security-layer-model_v0.1.md).
|
[`net-kingdom/canon/standards/security-layer-model_v0.2.md`](../net-kingdom/canon/standards/security-layer-model_v0.2.md).
|
||||||
|
|
||||||
```text
|
```text
|
||||||
Taxonomy cross-cutting language info-tech-canon, net-kingdom canon
|
Taxonomy cross-cutting language info-tech-canon, net-kingdom canon
|
||||||
|
|
|
||||||
|
|
@ -240,3 +240,34 @@ Open:
|
||||||
3. Adapt the other `INTENT.md` files that need clarification, and seek assent
|
3. Adapt the other `INTENT.md` files that need clarification, and seek assent
|
||||||
from flex-auth and ops-warden for the boundaries in §7.
|
from flex-auth and ops-warden for the boundaries in §7.
|
||||||
4. Rewrite `GH-WP-0001`; revise the Blueprint per §10.
|
4. Rewrite `GH-WP-0001`; revise the Blueprint per §10.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 12. Outcome — assent, and what it changed
|
||||||
|
|
||||||
|
Added 2026-08-28, after the review closed.
|
||||||
|
|
||||||
|
Assent was requested as intakes in the owning repositories (`FLEX-IN-0001`,
|
||||||
|
`KG-IN-0001`, `WARDEN-IN-0001`) with State Hub notification. All three assented,
|
||||||
|
each with its own decision record, and each returned a finding:
|
||||||
|
|
||||||
|
- **flex-auth** (`FLEX-DEC-2026-001`) — assent to all three items, reasoning
|
||||||
|
that it *"cannot hold this boundary against zone-engine and decline it as a
|
||||||
|
general rule"*. Self-declared a non-conformance: `DecisionProvenance` carries
|
||||||
|
no digest of the registry snapshot, so a decision turning on registry content
|
||||||
|
is not replayable from its own provenance. Drew one boundary back at
|
||||||
|
gate-house: an authority ceiling that determines an outcome must reach the
|
||||||
|
decision as an input claim or a versioned policy rule.
|
||||||
|
- **kings-guard** (`KG-DEC-2026-001`) — assent, and **declined the offered
|
||||||
|
relaxation of §5**, arguing that latency and blast radius both argue for
|
||||||
|
keeping it and that a containment path bypassing the decision point becomes an
|
||||||
|
authority path the moment it is subverted. Raised the real defect instead: §4
|
||||||
|
catalogued containment while §5 forbade the only route to discharging it.
|
||||||
|
- **ops-warden** (`ADR-0010`) — assent to all three; the access-engine veto was
|
||||||
|
not exercised. Grepped §5 as invited and self-reported a signing write to
|
||||||
|
OpenBao. Offered the amendment that became §5.3.
|
||||||
|
|
||||||
|
The standard was revised to **v0.2** and accepted. Three of the four changes
|
||||||
|
came from the assenting repositories rather than from gate-house; the
|
||||||
|
conformance loop in §12 of that standard turned on first contact, which is the
|
||||||
|
only evidence so far against this repository's paper-generator falsifier.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue