Bound rule 13: audit proves alteration, not omission

audit-core corrected a claim this repository's doctrine also makes. An
append-only archive with a verified hash chain proves records were not altered
or truncated after arrival; it cannot prove one was never sent. A suppressed
event leaves the chain intact and verification reports intact — and the event
an adversary most wants missing is the negative one: a revocation, a denial, a
containment action.

Adds the bound under the Core Rules, replacing "the audit record proves it
happened" with the sound form, and records that completeness is the emitting
system's obligation via atomic emission.

Flags outstanding doctrine work: the ASM Canon's control §27 and tests T-08 and
T-09 are written as though reconstruction from evidence were unconditional.

Also bumps standard references to v0.4.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
tegwick 2026-08-28 22:55:19 +02:00
parent d62d48aba2
commit 94526e44c0
3 changed files with 24 additions and 4 deletions

View file

@ -18,7 +18,7 @@ has lapsed — see the re-cut below.
Gate House is the **council where NetKingdom's security and defence doctrine is
established, documented, taught, and supervised** — a **Staff**-layer repository in the
NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.2.md`, accepted).
NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.4.md`, accepted).
It holds no runtime position and renders no authorization decision.
> **The mandate and the operating mode are Gate House's. The decision is access-engine's.
@ -86,7 +86,9 @@ repositories implement them. A document or proposal that violates one is wrong:
- **Agents cannot edit their own authority ceiling**; policy self-modification is a separately
governed path and high-value security telemetry.
- **Audit evidence is protected from the actor being audited**, and every privileged action
must be reconstructable from it.
must be reconstructable from it — *within the bound in INTENT § Core Rules*: an archive
proves records were not altered or truncated after arrival, never that one was never sent.
Do not write doctrine that says "the audit record proves it happened".
- **Credentials are implementation artifacts of a grant**, materialized by Secrets Engine /
OpenBao *after* authority exists — never the source of authority, never placed in model
context.
@ -141,7 +143,7 @@ the file, commit, then sync. `SCOPE.md` is derived from `INTENT.md` — keep the
- History and reference notes → `history/YYYY-MM-DD-<slug>.md`, matching the convention in
ops-warden, zone-engine, and secrets-engine.
- Doctrine that stabilizes graduates into `net-kingdom/canon/standards/`, owned by gate-house
and published by net-kingdom. `security-layer-model_v0.2.md` is the first, and is accepted:
and published by net-kingdom. `security-layer-model_v0.4.md` is the first, and is accepted:
all three affected repositories assented, each returning a finding that changed it.
- **No implementation layout.** Blueprint §32's reference tree (`api/`, `policy/`, `grants/`,
`deploy/`, …) described the withdrawn engine and does not apply. If work here starts