Re-cuts Gate House from deterministic authority plane to the Staff-layer
council where NetKingdom's security and defence doctrine is established,
documented, taught, and supervised.
The decisive argument is now stated in the document itself: a decision point
inside Gate House would place the deterministic authority boundary inside the
non-deterministic management layer, violating INV-02 — the first invariant the
repository exists to defend. access-engine (currently flex-auth) stays the only
policy decision point.
Adds the layer model and the Staff invariant (Staff never touches tooling
directly), a corrected responsibility table that names access-engine,
zone-engine, and the canon repos, the access lane/rule demarcation with
ops-warden and ops-mason, the conformance loop, and falsifiers.
Drops the /authorize surface, policy evaluation order, policy engine
selection, grant storage, revocation, and the technical direction section.
Keeps what no other repo owns: operating modes, the principal/actor/runtime
triple, mandates and ceilings, change dynamics, MCP doctrine, the posture
asymmetry, and the assurance specifications.
Addresses the name/metaphor risk in the opening: the gate house is where the
watch is set and the porter's rules are posted, not the gate itself.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Name the top layer Staff rather than Helpers, throughout. Place the layer
model in net-kingdom canon rather than info-tech-canon — it is NetKingdom
security architecture, not general semantic contract.
Record flex-auth's reframing as an Engine with access-engine as the working
rename target, and note the one cost: "access" is already spoken for
operationally by ops-warden and ops-mason, so adopting it requires
demarcating access lanes from access rules in both INTENTs.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Reference note from the 2026-08-28 review of INTENT.md across the security
estate. Establishes the four-layer model (taxonomy / tooling / engines /
helpers), distinguished by determinism and artifact kind, and its
self-similarity to the ASM Canon's three planes.
Key finding: gate-house's authority-plane framing places a deterministic
decision point inside the non-deterministic management layer, violating
INV-02, and collides with flex-auth's declared ownership of authorization.
zone-engine §5 already ruled that flex-auth is the only policy decision
point. Re-cuts gate-house as the doctrine and conformance council.
Not canon and not a decision record; the decisions it recommends still
have to be written and assented to.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Updated by fix-consistency on 2026-08-25:
- update .custodian-brief.md for gate-house
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.
SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.
Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.
Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9