diff --git a/CLAUDE.md b/CLAUDE.md index 1157300..7d1f43b 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -18,7 +18,7 @@ has lapsed — see the re-cut below. Gate House is the **council where NetKingdom's security and defence doctrine is established, documented, taught, and supervised** — a **Staff**-layer repository in the -NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.4.md`, accepted). +NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.7.md`, accepted). It holds no runtime position and renders no authorization decision. > **The mandate and the operating mode are Gate House's. The decision is access-engine's. @@ -143,8 +143,10 @@ the file, commit, then sync. `SCOPE.md` is derived from `INTENT.md` — keep the - History and reference notes → `history/YYYY-MM-DD-.md`, matching the convention in ops-warden, zone-engine, and secrets-engine. - Doctrine that stabilizes graduates into `net-kingdom/canon/standards/`, owned by gate-house - and published by net-kingdom. `security-layer-model_v0.4.md` is the first, and is accepted: - all three affected repositories assented, each returning a finding that changed it. + and published by net-kingdom. `security-layer-model_v0.7.md` is the first, accepted + 2026-08-29 after seven versions; four repositories assented and each returned findings + that changed it. Its working form is `net-kingdom/SECURITY-COMPANION.md` — read that + first. For how to get something done in the estate, ask ops-warden, not this repo. - **No implementation layout.** Blueprint §32's reference tree (`api/`, `policy/`, `grants/`, `deploy/`, …) described the withdrawn engine and does not apply. If work here starts producing services, schemas that resolve, or anything evaluated at request time, stop — diff --git a/INTENT.md b/INTENT.md index 40f3265..f92e670 100644 --- a/INTENT.md +++ b/INTENT.md @@ -314,7 +314,7 @@ So *"the audit record proves it happened"* is unsound. The sound form is *"the archive proves the records it holds were not altered or truncated after arrival"*. Completeness is the emitting system's obligation, discharged by making emission atomic with the state change; no archive can retrofit it. See -`net-kingdom/canon/standards/security-layer-model_v0.4.md` §9.6, raised by +`net-kingdom/canon/standards/security-layer-model_v0.7.md` §9.6, raised by `audit-core` against its own principle. This bound is not yet reflected in the Active Secrets Management Canon — control diff --git a/README.md b/README.md index 7c2be9b..2d986de 100644 --- a/README.md +++ b/README.md @@ -25,7 +25,7 @@ anything depends on at runtime. NetKingdom's IT security is layered by determinism and by the kind of artifact each layer produces — see -[`net-kingdom/canon/standards/security-layer-model_v0.4.md`](../net-kingdom/canon/standards/security-layer-model_v0.4.md). +[`net-kingdom/canon/standards/security-layer-model_v0.7.md`](../net-kingdom/canon/standards/security-layer-model_v0.7.md). ```text Taxonomy cross-cutting language info-tech-canon, net-kingdom canon