Point at the accepted standard and its companion

The layer model is accepted at v0.7. References bumped from v0.4, and CLAUDE.md
now sends readers to net-kingdom/SECURITY-COMPANION.md as the working form, and
to ops-warden for how to get things done — doctrine is ours, the paths through
it are not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
tegwick 2026-08-29 11:29:48 +02:00
parent c638822d17
commit f524badd9d
3 changed files with 7 additions and 5 deletions

View file

@ -18,7 +18,7 @@ has lapsed — see the re-cut below.
Gate House is the **council where NetKingdom's security and defence doctrine is
established, documented, taught, and supervised** — a **Staff**-layer repository in the
NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.4.md`, accepted).
NetKingdom security layer model (`net-kingdom/canon/standards/security-layer-model_v0.7.md`, accepted).
It holds no runtime position and renders no authorization decision.
> **The mandate and the operating mode are Gate House's. The decision is access-engine's.
@ -143,8 +143,10 @@ the file, commit, then sync. `SCOPE.md` is derived from `INTENT.md` — keep the
- History and reference notes → `history/YYYY-MM-DD-<slug>.md`, matching the convention in
ops-warden, zone-engine, and secrets-engine.
- Doctrine that stabilizes graduates into `net-kingdom/canon/standards/`, owned by gate-house
and published by net-kingdom. `security-layer-model_v0.4.md` is the first, and is accepted:
all three affected repositories assented, each returning a finding that changed it.
and published by net-kingdom. `security-layer-model_v0.7.md` is the first, accepted
2026-08-29 after seven versions; four repositories assented and each returned findings
that changed it. Its working form is `net-kingdom/SECURITY-COMPANION.md` — read that
first. For how to get something done in the estate, ask ops-warden, not this repo.
- **No implementation layout.** Blueprint §32's reference tree (`api/`, `policy/`, `grants/`,
`deploy/`, …) described the withdrawn engine and does not apply. If work here starts
producing services, schemas that resolve, or anything evaluated at request time, stop —

View file

@ -314,7 +314,7 @@ So *"the audit record proves it happened"* is unsound. The sound form is *"the
archive proves the records it holds were not altered or truncated after
arrival"*. Completeness is the emitting system's obligation, discharged by making
emission atomic with the state change; no archive can retrofit it. See
`net-kingdom/canon/standards/security-layer-model_v0.4.md` §9.6, raised by
`net-kingdom/canon/standards/security-layer-model_v0.7.md` §9.6, raised by
`audit-core` against its own principle.
This bound is not yet reflected in the Active Secrets Management Canon — control

View file

@ -25,7 +25,7 @@ anything depends on at runtime.
NetKingdom's IT security is layered by determinism and by the kind of artifact
each layer produces — see
[`net-kingdom/canon/standards/security-layer-model_v0.4.md`](../net-kingdom/canon/standards/security-layer-model_v0.4.md).
[`net-kingdom/canon/standards/security-layer-model_v0.7.md`](../net-kingdom/canon/standards/security-layer-model_v0.7.md).
```text
Taxonomy cross-cutting language info-tech-canon, net-kingdom canon