Point at the accepted standard and its companion

The layer model is accepted at v0.7. References bumped from v0.4, and CLAUDE.md
now sends readers to net-kingdom/SECURITY-COMPANION.md as the working form, and
to ops-warden for how to get things done — doctrine is ours, the paths through
it are not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
tegwick 2026-08-29 11:29:48 +02:00
parent c638822d17
commit f524badd9d
3 changed files with 7 additions and 5 deletions

View file

@ -18,7 +18,7 @@ has lapsed — see the re-cut below.
Gate House is the **council where NetKingdom's security and defence doctrine is Gate House is the **council where NetKingdom's security and defence doctrine is
established, documented, taught, and supervised** — a **Staff**-layer repository in the established, documented, taught, and supervised** — a **Staff**-layer repository in the
NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.4.md`, accepted). NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.7.md`, accepted).
It holds no runtime position and renders no authorization decision. It holds no runtime position and renders no authorization decision.
> **The mandate and the operating mode are Gate House's. The decision is access-engine's. > **The mandate and the operating mode are Gate House's. The decision is access-engine's.
@ -143,8 +143,10 @@ the file, commit, then sync. `SCOPE.md` is derived from `INTENT.md` — keep the
- History and reference notes → `history/YYYY-MM-DD-<slug>.md`, matching the convention in - History and reference notes → `history/YYYY-MM-DD-<slug>.md`, matching the convention in
ops-warden, zone-engine, and secrets-engine. ops-warden, zone-engine, and secrets-engine.
- Doctrine that stabilizes graduates into `net-kingdom/canon/standards/`, owned by gate-house - Doctrine that stabilizes graduates into `net-kingdom/canon/standards/`, owned by gate-house
and published by net-kingdom. `security-layer-model_v0.4.md` is the first, and is accepted: and published by net-kingdom. `security-layer-model_v0.7.md` is the first, accepted
all three affected repositories assented, each returning a finding that changed it. 2026-08-29 after seven versions; four repositories assented and each returned findings
that changed it. Its working form is `net-kingdom/SECURITY-COMPANION.md` — read that
first. For how to get something done in the estate, ask ops-warden, not this repo.
- **No implementation layout.** Blueprint §32's reference tree (`api/`, `policy/`, `grants/`, - **No implementation layout.** Blueprint §32's reference tree (`api/`, `policy/`, `grants/`,
`deploy/`, …) described the withdrawn engine and does not apply. If work here starts `deploy/`, …) described the withdrawn engine and does not apply. If work here starts
producing services, schemas that resolve, or anything evaluated at request time, stop — producing services, schemas that resolve, or anything evaluated at request time, stop —

View file

@ -314,7 +314,7 @@ So *"the audit record proves it happened"* is unsound. The sound form is *"the
archive proves the records it holds were not altered or truncated after archive proves the records it holds were not altered or truncated after
arrival"*. Completeness is the emitting system's obligation, discharged by making arrival"*. Completeness is the emitting system's obligation, discharged by making
emission atomic with the state change; no archive can retrofit it. See emission atomic with the state change; no archive can retrofit it. See
`net-kingdom/canon/standards/security-layer-model_v0.4.md` §9.6, raised by `net-kingdom/canon/standards/security-layer-model_v0.7.md` §9.6, raised by
`audit-core` against its own principle. `audit-core` against its own principle.
This bound is not yet reflected in the Active Secrets Management Canon — control This bound is not yet reflected in the Active Secrets Management Canon — control

View file

@ -25,7 +25,7 @@ anything depends on at runtime.
NetKingdom's IT security is layered by determinism and by the kind of artifact NetKingdom's IT security is layered by determinism and by the kind of artifact
each layer produces — see each layer produces — see
[`net-kingdom/canon/standards/security-layer-model_v0.4.md`](../net-kingdom/canon/standards/security-layer-model_v0.4.md). [`net-kingdom/canon/standards/security-layer-model_v0.7.md`](../net-kingdom/canon/standards/security-layer-model_v0.7.md).
```text ```text
Taxonomy cross-cutting language info-tech-canon, net-kingdom canon Taxonomy cross-cutting language info-tech-canon, net-kingdom canon