The layer model is accepted at v0.7. References bumped from v0.4, and CLAUDE.md
now sends readers to net-kingdom/SECURITY-COMPANION.md as the working form, and
to ops-warden for how to get things done — doctrine is ours, the paths through
it are not.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
audit-core corrected a claim this repository's doctrine also makes. An
append-only archive with a verified hash chain proves records were not altered
or truncated after arrival; it cannot prove one was never sent. A suppressed
event leaves the chain intact and verification reports intact — and the event
an adversary most wants missing is the negative one: a revocation, a denial, a
containment action.
Adds the bound under the Core Rules, replacing "the audit record proves it
happened" with the sound form, and records that completeness is the emitting
system's obligation via atomic emission.
Flags outstanding doctrine work: the ASM Canon's control §27 and tests T-08 and
T-09 are written as though reconstruction from evidence were unconditional.
Also bumps standard references to v0.4.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
All three assent requests answered, each with a decision record and each with
a finding. Standard revised to v0.2 and accepted.
- history note gains §12 recording the outcome and what each repository
returned.
- README and CLAUDE.md now cite security-layer-model_v0.2.md.
- GH-WP-0001-T03 closed.
Three of the four v0.2 changes came from the assenting repositories rather
than from gate-house.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
The guidance still described Gate House as the deterministic authority plane
and pointed agents at the Blueprint's component architecture and reference
implementation layout — it would have actively misled the next session.
- Lead with the re-cut and the INV-02 argument, and say plainly that any
proposal having Gate House decide, store, evaluate, or enforce at request
time is wrong regardless of how well built.
- Add the decision record to the document hierarchy, above the Canon, and
mark the Blueprint as partly withdrawn with the surviving sections named.
- Reframe the invariants as doctrine Gate House authors rather than
constraints on code it writes; add the Staff/Tooling rule as binding on
this repo itself.
- Record the normative demarcations: access lane vs access rule, doctrine vs
runbook, control plane as Engine vocabulary.
- Replace the implementation-layout guidance with where doctrine artifacts
go, and note that T-01…T-10 are specifications executed by whitehat.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9