Commit graph

105 commits

Author SHA1 Message Date
b9d1dd1e2f Correct GH-DEC-2026-014 section 4 and A-16 on audit-core's return
audit-core met the condition and then corrected its wording, and the
correction matters enough that leaving it implicit would have made the
section wrong.

The archive CARRIES the declaration; it does not DETECT non-production.
It performs no retrieval, holds no client for the emitting repository,
and its egress policy permits nothing that would let it try — asserted
by a test, because the claim silently stops being true the day someone
adds one. Detection sits with the REVIEWER at retrieval, and the stored
declaration is what makes that discovery a finding rather than a blank.
Section 4 now says so, and says explicitly that an archive must not be
read as required to chase content: an archive that fetched from the
parties it audits would acquire exactly the dependency that makes it
corruptible by them.

The residual they raised against their own delivered work is now in the
text. A custodian that never held content can emit a false
content_exists; they validate the declaration's shape, never its truth.
So what section 4 buys is narrower than it reads — it converts an
unattributable absence into an attributable false statement. Strictly
better, not proof. Better stated here than in a conformance argument
later, which was their reason for raising it.

A-16 gains two notes, both from their return.

The obligation attaches to the party that OBSERVED the route. A-16 does
not require every downstream holder to restate a route it never saw;
that is manufacturing a marker, which is the rider's failure in its
most direct form. audit-core established this by DECLINING an
obligation offered to it — its tenant is not an identity claim it
resolves but a value a credential is permitted to write, so recording a
route in an audit event would restate something it did not see. The
refusal is A-16 applied properly, not an exception to it, and it lands
the obligation on the party that resolved the value.

And applying A-16 relocates ambiguity rather than terminating it. Their
declaration disambiguates erased from never-held and creates a fourth
pair, false-declaration versus honest-declaration-then-loss. Not a
defect and not a reason to stop: the ambiguity ends up somewhere
attributable. Judge each application by whether the new residual has an
owner.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-10 15:23:57 +02:00
5ec2fe9649 Amend GH-DEC-2026-013: three facts in one field, and key-cape's third value
approval-engine answered section 6 by naming the fact it actually uses,
and it was neither of the two the record identified. Store isolation —
did this caller arrive through a channel this store serves — is a
property of the channel, and it is what a registration-supplied tenant
is genuinely adequate for. Act scope is a property of the act.
Principal membership is a property of the person. Three facts, one
field named tenant.

That explains why every party's intuition was locally correct and the
disagreement was real anyway: approval-engine reading store isolation
was right that the registration suffices, informed-decision reading act
scope was right that the fact is act-scoped, and the identity layer
reading membership was right that a registration cannot supply it.
Nobody was wrong about their own fact. The field was wrong to hold all
three. It is a stronger case for the provenance requirement than two
facts were.

approval-engine committed unasked to the consequence — registration
-supplied is admissible for isolation and never for doctrine turning on
membership — and asked to be held to it as the point where a sound
check silently becomes unsound. Held, and GH-DEC-2026-016 section 5 is
where it first bites.

key-cape emitted three provenance values where the record named two,
and asked to be corrected rather than assume. There was nothing to
correct: default is a real third route, and folding it into directory
would have reproduced the finding one level down by letting a consumer
read an assertion the identity layer never made. It applied A-16 to a
route this record did not examine. Its agreement-case judgement is
endorsed too — agreement resolves to directory, because the directory
did assert it and the weaker label would understate what is known,
which also means the value strengthens on its own when the adapter
lands.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-10 15:22:04 +02:00
62c6399ddd Revise R3, rule the human-approver question, and correct A-16 and A-17
Four returns arrived overnight, two of them corrections to rules
written yesterday. Both corrections are right.

A-16 GAINS A RIDER. informed-decision pointed out the rule is silent on
who writes the route marker, and the guarantee is only as good as that
party's independence from what the marker asserts. Its own instance is
the weak one: erased versus never-held is written by the party the
evidence is about, so A-16 there reduces to a self-attestation and
GH-DEC-2026-014 section 4 narrows it without removing it. Without the
rider A-16 becomes the thing it exists to prevent — a sound check read
as establishing a property it does not carry. The four instances are
now graded by marker independence rather than listed as equals.

A-17 GAINS A PRECONDITION. It asks which way a case fails, which is
unanswerable where the case cannot be seen. Their commitment-only path
had no failure direction at all as proposed: a reviewer got a blank,
indistinguishable from erased, withheld, lost and never held.
GH-DEC-2026-014 section 4 did not test the direction of failure, it
manufactured one — the right outcome reached without noticing it was a
different operation. So making the distinguishing case observable is a
precondition of applying A-17, not an outcome of it, and A-17 therefore
depends on A-16. Neither dependency was noticed when both were written
a day apart.

GH-DEC-2026-015 revises GH-DEC-2026-012 R3. approval-engine recommended
exactly the option we refused, informed-decision could not comply with
both, changed nothing, and raised it as a finding rather than choosing
— having previously offered to let approval-engine settle R3 and
declined to take that route twice.

Nesting is permitted for this pair. The cycle objection needed mutual
containment and approval-engine's digest structurally excludes
presentation material for an independent reason. But the decisive
ground is that the original ruling worked against its own rule: R3
forbade recomputing the other layer's digest from one's own vocabulary,
and co-reference by identifier left informed-decision canonicalizing
principal and target, two of the five fields in that digest. Nesting
removes the duplication; co-reference manages it. We reached for the
management option while stating the rule that recommends removal.

Conditioned on approval-engine making the exclusion normative and
tested rather than intentional, because the cycle cannot arise here is
a belief and the cycle may not arise here is a rule with an owner —
A-17's precondition applied to our own permission. The ordering
objection is withdrawn as mistaken and the withdrawal is recorded: a
cost accepted from the requester and never checked is how a wrong
reason survives into a ruling.

GH-DEC-2026-016 rules NC-03, which both repositories referred up and
neither benefits from. Where an approval is declared as discharging a
human-in-the-loop control, the approver must be a human principal and
approval-engine must refuse at bind time rather than record it.
Recording the principal type is the auditable half and stops nothing;
an approval control satisfiable by the same class of actor it exists to
check is theatre. Scoped to declared approvals, declared at issue and
never inferred, on approval-engine's own pdp_path shape. One surface
enforcing it is not the property being held — the guarantee would read
as human-approved unless someone used a different client.

Section 5 leaves what makes a principal human to the identity layer and
notes it inherits A-16: refusing a service principal while accepting an
unverified assertion of humanity moves the defect rather than closing
it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-10 15:21:29 +02:00
a5a1bcf537 State two properties once, and repair SCOPE.md's withdrawn framing
Two things this week's rulings left owed, both the failure mode those
rulings were about.

A-16 and A-17, and Core Rules 16 and 17. Two general properties had
been stated three times each, always against the instance that produced
them and nowhere in general — which is how a property gets found by
accident or not at all. That is the defect gate-house corrected in
three other repositories this month while carrying it here.

A-16, distinguishable routes: where one observable state is reachable
by two routes differing in security meaning, the record must say which.
Four instances, and they only look like one rule once they are next to
each other — an envelope identical whether access-engine issued it or a
responder forged it (GH-DEC-2026-010), unknown versus absent in a
stance map (-011), a tenant claim directory-asserted versus
registration-supplied (-013), erased versus never held on an evidence
path (-014). The rule is not that the routes must diverge; usually they
must behave identically and safely. It is that a later reader can tell
them apart, or a sound check gets read as carrying a property it does
not have.

A-17, fail-closed transitions: a transitional deviation is admissible
only where it fails closed on the case distinguishing it from the
conformant state. Written because two requests for transitional relief
arrived in one week and were answered oppositely, and the answers would
otherwise read as arbitrary rather than as one rule.

Both are marked repository-level and explicitly not estate doctrine.
Graduation waits on a repository that bears a cost under them having
argued them, which is the bar security-layer-model met and these have
not.

SCOPE.md was still the withdrawn authority-plane framing. It opened by
saying gate-house "decides whether a requested action is authorized"
and listed deterministic authorization decisions as in scope — the
design retired by GH-DEC-2026-001, surviving in a derived document a
reader would take as current, with a dead pointer to Blueprint section
3 non-goals that the re-cut removed. Rewritten from current INTENT,
including what is not owned here and what would put the repository out
of scope.

The irony is noted rather than hidden: a derived artifact contradicting
its source, in the repository that generalised that failure into
statute section 12 after finding six instances in one week elsewhere.

rmgr conform clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-10 07:57:35 +02:00
2117d28809 chore: sync hub identifiers and work record
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 23:27:54 +02:00
b9e93ccd4a Rule INFD-IN-0003, and answer INFD-IN-0002's argument in GH-DEC-2026-013
Two follow-ons from informed-decision, both asking whether the item was
doctrine or implementation. One was already ruled; the other splits.

GH-DEC-2026-013 gains a section 6. INFD-IN-0002 argued for
registration-bound on a ground key-cape did not raise: their pre-sign
binding slice commits which scope is being entered, so a tenant that is
a property of the surface matches what the binding commits, while a
person-property sits closer to awareness. The argument is accepted and
it does not change the ruling — it sharpens the defect. What they
describe is a real fact deserving commitment: which scope this act
enters. That is a property of the act, not of the principal, and it is
not the fact approval-engine exact-matches to admit an approver. One
claim named tenant is carrying two facts, which is why the shape feels
right to them and wrong to the identity layer. A binding slice that
must commit the scope entered should commit that scope rather than
borrow the principal's membership claim. Their argument is the best
evidence yet that section 5's provenance requirement is necessary.

GH-DEC-2026-014 rules the doctrine half of INFD-IN-0003 and hands the
rest to audit-core. Commitment-only is admissible for stage 1, on
GH-DEC-2026-013's own test: a reviewer who cannot obtain the content
gets no reconstruction rather than a wrong one. Their data-protection
reason is accepted as a reason of the right kind — doctrine that forces
L4 contract text into an audit fabric to satisfy an evidence obligation
is wrong rather than merely expensive.

Two limits. A commitment-only record satisfies non-alteration and never
reconstructability, and must not be described as satisfying it; this is
our existing bound applied to a record that additionally does not carry
what it commits to. And the gap it leaves is availability rather than
integrity, sitting with the audited party — so non-production must be
detectable as a finding rather than present as an absence. That last is
section 4 and nobody asked for it: a reviewer receiving nothing cannot
otherwise tell erased from withheld from never held.

That makes three settings now for one rule — unknown versus absent in a
stance map, directory-asserted versus registration-supplied in an
identity claim, erased versus never held in an evidence path. Wherever
a system reaches one appearance by two routes, the record must say
which route or the safer reading becomes unavailable to everyone.

Their refusal of a separate evidence store is endorsed, with one
addition: an evidence store owned by the party whose conduct it
evidences is not an evidence store, whatever its integrity properties.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 23:24:41 +02:00
16c1d46d5d Rule the tenant-provenance question: bounded gap, and the claim must say which
key-cape has no adapter populating the directory user tenant, so every
human token fell back to the default and approval-engine refused it by
exact match — presenting as a failed approval rather than as a
registration defect. It built a registration-bound resolution, then
declined to ratify its own design because the second option writes a
cross-tenant capability into the issuer. That reading was right and the
question is ours: what may be a source of a principal's identity is a
Core Rule, not a runbook.

Directory-sourced is the terminal state. A registration is a statement
about the actor; a tenant is a property of the principal; sourcing the
second from the first collapses two identities the estate keeps
distinct, in the direction that widens.

The registration-bound shape is admissible anyway, as a declared
bounded gap, and the reason is not that the design is careful. It is
that the case distinguishing it from the correct resolution fails
closed: where registration and directory disagree, issuance is refused
rather than resolved either way. And the same code turns from supplying
the zone into enforcing agreement with it the moment the directory
carries tenants, so it converges by subtraction.

That general property is section 3 and neither request asked for it.
A transitional shape is admissible where it fails closed on exactly the
case that distinguishes it from the correct resolution, and
inadmissible where it fails open there. It is section 8's asymmetry
applied to transitions, and it is what makes this grant and
GH-DEC-2026-011's decline one rule rather than two defensible calls: a
promise that fails open is a permission, a promise that fails closed is
a gap, and only the second is a thing a register can hold.

Two conditions strengthen what key-cape wrote about itself. Refusal on
disagreement is normative, including against a future change that
prefers the directory — picking any winner converts a refusal into a
silent cross-tenant assertion. And lifting the dynamic-registration
exclusion voids the rule rather than reopening it; key-cape wrote "must
be revisited", which implies the answer might survive review, and it
would not.

The finding they did not ask for is section 5. The tenant claim is a
bare string, so a consumer cannot tell a tenant the directory asserted
about the person from one a registration supplied about the client they
came through. approval-engine exact-matches that string and is relying
on the second while its contract reads as the first. That is
GH-DEC-2026-010 one layer down — a sound check whose reader infers a
property it does not carry. The claim must carry its provenance;
the mechanism is key-cape's.

Gap registered at net-kingdom@f9e1611.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 23:20:42 +02:00
1fb9f29d49 chore: sync hub identifiers and work record
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 22:15:52 +02:00
custodian-sync
e72834f1ea chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-09:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 22:15:28 +02:00
0a1d1d942a Rule INFD-IN-0001: PEP-shaped, presentation claim permitted, view_hash distinct
informed-decision filed three rulings before writing any architecture,
with candidate answers, their costs, the self-dealing objection argued
against itself, and a list of what it was not asking for. That order is
what section 17 exists to produce, and KEY-WP-0013-T02 is blocked today,
so it is answered now rather than queued.

R1 — PEP-shaped, confirmed as proposed, not an Engine. It holds no
state another layer reads at runtime for a verdict, which is the test.
Its layer stays its own to declare; this settles its shape, which is
what was blocking. It should build to v0.8's obligation 3 rather than
v0.7's and inherit GH-DEC-2026-010's attribution gap knowingly rather
than describe its validation as complete.

R2 — yes, and no second catalog row. PEP and PIP are shapes a
repository has; the catalog records layers it occupies. Obligation 5
forbids a PIP republishing the PDP's decision, which is a prohibition
on republishing a decision, not on holding two shapes. Three limits
carry the permission: the claim carries presentation and nothing else,
it must never be an input to the decision it presents for, and its
evidence copy reaches audit-core independently of the emitter. The last
is the one that matters here, because the actor and the source are the
same component.

R3 — candidate (b). The binding digest is authoritative for what the
request is; view_hash only for what was shown; a disagreement between
them is a finding against the presenting surface, never a fact about
the request. (a) is refused doctrinally rather than on the cost given:
merging the two makes one repository the authority on what another
layer computes over a request, which is GH-DEC-2026-008's objection to
translation. (c) is refused because nesting the binding digest inside
view_hash reproduces the hash cycle that made GH-DEC-2026-008
unimplementable — we paid for that lesson once this quarter. The two
link by co-reference instead: the presentation record names the binding
identifier and never recomputes the other layer's digest.

The residual is not closed and the ruling says so, as they asked. A
compromised surface can present X and attest Y. Attestation covers
accident and later tampering, never a compromised source — the same
disposition approval-engine's equivalent takes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 22:10:45 +02:00
custodian-sync
bed8832e10 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-09:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 20:16:41 +02:00
ddc1337a63 Close the v0.8 assent round: two rulings, nine corrections, one decline
Four repositories returned text reviews. Every substantive finding was
about a rule that read as satisfied by a check that did not satisfy it,
which is the failure mode this repo is structurally prone to: doctrine
is graded on whether it is right and consumed on whether it is
checkable, and only the implementers can tell those apart.

GH-DEC-2026-010 — attribution is not identity. Obligation 1 said a PEP
must hold a decision from access-engine; obligation 2 supplied a digest
test emphatic that it was mechanical rather than a matter of judgement.
That test establishes which request a decision is for and nothing about
who issued it, and it cannot: every input to it is either sent by the
caller or published, so a responder knowing a published package id and
version returns a well-formed allow. Fail-closed protects against a
decision point that is absent, not against one that lies. Section 9.4
required authenticated entries of the approval object and nothing
required it of the decision, so obligation 5 was written over a pair a
PEP could only half validate. The mechanism is access-engine's under
section 17 and it is not the standard's to choose, so the condition is
a declared section 13 gap rather than a rule invented here. Raised by
access-engine against its own artifact, which had already recorded it
as its own defect before reading our text.

GH-DEC-2026-011 — ops-warden assented to GH-DEC-2026-009 on the
falsifier's own terms, went looking for the section 5.1 escape hatch
the reversal clause predicted, and reported it does not have one. Then
it priced adoption: 0 of 3 signing targets and 3 of 21 routing lanes
resolve to a zone, so the cell adopted today fails closed on nearly
every certificate it issues whenever the engine is unreachable —
including the continuity path an operator needs to repair that
unreachability. Its ask for a dated transitional unknown: fail_open is
declined; it is indistinguishable at runtime from the stance the rule
forbids and would make the rule optional at the only moment it costs
anything. Its second preference is adopted instead: 13.1 records a
dated coverage figure beside each stance, so a strict consumer and an
unclassified one stop reading alike. Coverage is disclosure and does
not soften the stance — the record says so, and says what would make
the column come out again.

The round record is closed and carries the rest: totality by catch-all,
absent versus unknown (closing the section 16 question this version
opened), the drift test promoted to MUST, ops-mason marked, and
approval-engine's four editorial-but-load-bearing findings. Its own
finding ids are used rather than renumbered.

kings-guard and audit-core did not return a review. Section 14 records
that as not claimed rather than counting silence as assent, and names
the sections that therefore carry no assent from the repository best
placed to test them.

Standard amended at net-kingdom@64394e9; it stays proposed, and
publication and the acceptance flip are net-kingdom's.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 20:15:12 +02:00
repo-manager
a1a3294a6f repo.work.update_workplan GH-WP-0003 (update)
correlation_id: 66aa03a3-999d-4207-a1e0-fd5e42c83f47
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 20:14:52 +02:00
repo-manager
d1e5f8a3da repo.work.update_task_status GH-WP-0003-T06 -> done
correlation_id: 546838d2-2926-469b-993f-470735caddb2
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 20:14:35 +02:00
d97e8efa6e Collect v0.8 assent findings; correct GH-DEC-2026-008 for implementability
Four findings returned so far, all from access-engine and
approval-engine. F1 is the serious one: GH-DEC-2026-008 as written
mandated a comparison that could never pass, because a claim travelling
inside a hashed request cannot name the digest of the request containing
it. A fail-closed consumer obeying it would have denied destroy
permanently — the ruling and its own fail-closed requirement compounded
rather than cancelled.

Ruling and its four obligations stand; the comparison target is corrected
to the PDP's published exclusion-scoped digest, verified in flex-auth's
schema and canonical.go before amending. A consumer must not guess the
exclusion rule, and until a PDP publishes one the path is fail-closed
rather than complete.

F2 adds the general property access-engine flagged as a near miss it was
not asking to have written: an evidence-bearing input may be excluded
from a correspondence digest but never from the replay identity.

The round record notes what this says about the process. GH-DEC-2026-008
was correct in substance, argued from doctrine, and verified against
another repository's schema before issue — and none of that caught a
defect three repositories found within hours of building on it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 15:28:01 +02:00
6f4bd56ee5 Assemble v0.8 and open the assent round (T06)
The cut is at net-kingdom@66eeaba as status: proposed. All eight
amendments applied, with a §15 change-log entry, a §1 "what changed", a
§16 reconciliation closing two questions and opening one, and a rewritten
§14. Section numbering unchanged.

§14 no longer claims acceptance on the owner's decision. Ten of eleven
changes were requested by another repository and seven by a repository
arguing against its own interest, but this version imposes costs on named
repositories — ops-warden's unknown cell, approval-engine's issue-time
digest — and a cost imposed without a review round is what §12 exists to
catch late. So it circulates first.

The amendment set stays as the per-amendment argument; the cut is the
text under review. v0.7 remains accepted and unpatched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 14:53:09 +02:00
repo-manager
aca947fabe repo.work.update_task_status GH-WP-0003-T06 -> progress
correlation_id: 898bcaa5-7cbc-4d4f-8c6a-aaeffc438cbc
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 14:52:58 +02:00
3b828586fc Strengthen A7 to two tiers on approval-engine's proposal
The summary-for-body pattern reached six instances in four repositories
in one week. approval-engine escalated it with a concrete split: the half
that is mechanically checkable and the half that is doctrine.

§11 gains an example-validates-against-schema check, with the clause that
matters most — where a field is optional but load-bearing, examples must
cover both its presence and its absence. That clause is instance six:
approval-engine's own claim examples omitted pdp_digest and contradicted
its schema, found while implementing GH-DEC-2026-008, by the repository
making the argument. An example set that silently omits an optional field
teaches every reader the field does not exist.

§12 gains the convention half, which no test can cover: derivatives
marked with source and derivation version, and dated review records
marked as status-as-of-date rather than current state.

The tally is recorded in full because it is the argument. Four of six
were self-reported and one was committed by the proposer, so the case is
that the publishing shape makes the error the default — not that four
repositories were careless. A control depending on repositories
volunteering corrections is not a control.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 14:21:29 +02:00
repo-manager
4d8b0f6775 repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 14:18:37 +02:00
22915cf2a0 Rule on unknown and the scoping axis as GH-DEC-2026-009
access-engine exercised the divergence capability it claimed in the v0.6
round, on the first occasion §13.1 held two rows. ops-warden resolves
unknown to fail_open, secrets-engine to fail_closed; both conformant,
both total, both test-pinned, disagreeing about the one case that by
construction nobody planned for. They also scope over different axes, so
the register cannot answer what an inventory exists to answer.

Ruling 1: unknown is not a zone and MUST fail closed. §9.3 permits
trading availability for openness per zone — and that trade requires
knowing the zone. Where the scope is unknown the trade cannot have been
made for it, so a permissive unknown does not extend a considered
decision, it invents the most permissive one. An unreachable engine is a
known request in a degraded system; an unclassified subject is not.
unknown is the cheapest state for an attacker to induce, so failing open
on it makes being unclassifiable a privilege escalation requiring no
credential, which §8's asymmetry forbids wherever it appears.

Ruling 2: each map declares its scoping axis and its relation to zone.
Forcing everyone onto zones would make secrets-engine assert a zone it
cannot know, and a fiction in a runtime-read test-pinned file is worse
than an honest incommensurability. The register records the axes and
states that cross-axis aggregation is unavailable.

ops-warden acquires one non-conformant cell at v0.8. It did everything
asked — published first, built the reference form, offered it estate-wide
— so this goes to the assent round rather than being imposed quietly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 14:18:36 +02:00
repo-manager
45a65c0748 repo.work.create_decision GH-DEC-2026-009
correlation_id: b5a1db81-fa81-4449-878f-206dce74ceaf
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 14:17:19 +02:00
repo-manager
8a3eec5301 repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 09:32:22 +02:00
f0f888ca7e Close the binding-correspondence gap as GH-DEC-2026-008
access-engine raised, and declined to solve locally, a hole in the split
GH-DEC-2026-005 ruled on. approval-claim verification item 4 is a
disjunction and neither limb delivers "approved for THIS request" on the
PDP path: limb one requires translating between two engines' vocabularies
and no mapping is published, limb two (pdp_digest) is optional. Where the
digest is absent a consumer can hold valid_now true, receive an ALLOW,
consume and act with nothing establishing that approval and decision
concern the same action and target.

Ruled: the PDP digest is the correspondence and is required on that path;
a claim without one fails closed; the native limb survives only for
consumers already in approval-engine's vocabulary, including T-06. No
mapping is published — a translation can be wrong while still producing a
confident answer, it fails open, it would be owned by neither engine, and
recomputing another layer's binding is the re-derivation GH-DEC-2026-005
already forbids. The cost is stated: an approval issued without a bound
CheckRequest is unusable on this path, which is correct behaviour.

Also: adopted hub row b606e8ce as canonical for GH-DEC-2026-005 rather
than registering a duplicate; recorded approval-engine's narrowing of the
approver-threshold consequence (distinctness is a UNIQUE storage
invariant, so the PEP stopped checking that the engine applied its own
invariant, not whether dual control could be forged); and drafted A7/T08,
a §11 marking obligation and §12 consumer rule for derived summaries,
after four instances in one week across four repositories.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 09:32:20 +02:00
repo-manager
865bab3955 repo.work.create_decision GH-DEC-2026-008
correlation_id: 9ea5a1bd-1f00-4069-b6bf-a59a29327415
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 09:30:42 +02:00
08cf036f3d Draft the v0.8 amendment set (T01, T02, T05, T07)
Exact normative text for all six amendments, section by section against
accepted v0.7, at docs/amendments/v0.8-amendment-set.md. Each carries its
defect statement, its replacement wording, and the decision or contract
that already governs its implementers — the statute move does not decide
any of them again.

A1 §9.7.3 corrects the consume ordering: v0.7's stated order leaves the
CAS able to prevent only the second record and never the second side
effect, which makes single consumption theatre. A2 adds the §11
emission-guarantee check so GH-IN-0001 cannot recur unnoticed. A3 keeps
the §13 tables and transcribes the four stance-map rows, ops-mason's gap
included, since the register migration is conditioned on an export. A4
lands the recomputability boundary with the criteria-grounding clause. A5
generalizes validation-by-owning-layer into §6.4 and adds the
validating-is-not-re-issuing demarcation to §8. A6 replaces §17's stale
"neither has assented" paragraph.

Deliberate omissions are recorded rather than left silent: §12's fourth
step is a status not an amendment, §16's reconciliation is assembly work,
and no §4 catalog row moves.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:11:45 +02:00
repo-manager
1505ce7af8 repo.work.update_task_status GH-WP-0003-T07 -> done
correlation_id: 6a6234f0-db8f-4c1f-9330-2ff8e6072eff
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:11:24 +02:00
repo-manager
a1a8a11a3e repo.work.update_task_status GH-WP-0003-T05 -> done
correlation_id: 59cde7de-e722-4e11-ab15-b7dbc3ce9d1c
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:11:22 +02:00
repo-manager
f5f4548323 repo.work.update_task_status GH-WP-0003-T02 -> done
correlation_id: 11d61b2f-b3c5-4e23-816a-358632f2a089
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:11:17 +02:00
repo-manager
8fcf28bc93 repo.work.update_task_status GH-WP-0003-T01 -> done
correlation_id: 025159db-79aa-4286-ad0f-8d9745b9432e
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:11:12 +02:00
42e9bcc747 Adopt the recomputability boundary as GH-DEC-2026-007
GH-WP-0003-T04. kings-guard's answer to KG-IN-0003 is adopted: the
posture/maturity line is recomputability, not volatility. Their argument
holds — volatility describes the two categories without partitioning
them, and every case it does not obviously cover becomes an argument at
exactly the boundary §6 exists to keep out of argument. The test is
§9.5's own determinism clause pointed where it had not been pointed.

Added one clause they did not propose, because their framing opens a
loophole: recomputability is assessed over the stated criteria, so a
criterion that dereferences a judgment is deterministic in form and
inferential in substance, and would put an opinion inside an engine
wearing a rule's clothes. A criterion MUST bottom out in evidence about
the subject, not in another party's conclusion about it. A recorded
judgment is evidence that the judgment was made, never that the thing
judged is so — the same distinction §9.6 draws about archives and
GH-DEC-2026-005 draws about valid_now.

All three kings-guard consequences carried, including the constraint they
volunteered against themselves (readiness is not an input to posture) and
their honest limit, which makes §17 load-bearing for the rule.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:08:32 +02:00
repo-manager
cb9b0b80fc repo.work.update_task_status GH-WP-0003-T04 -> done
correlation_id: f9867ccb-8aba-4a36-bbad-6b82b4e63538
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:08:15 +02:00
repo-manager
150ddfb4aa repo.work.create_decision GH-DEC-2026-007
correlation_id: 73b37f0f-be76-4919-b982-2411090b48ab
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:07:34 +02:00
1f4fd20519 Amend GH-DEC-2026-005: strike the G3 trigger, record what the PEP stopped checking
Two corrections from the repositories that implemented the decision, both
volunteered against their own interest.

approval-engine and flex-auth independently reported that the deferred
option's G3 revisit trigger was already spent when the decision was
written. Verified here against flex-auth/schemas/decision_envelope.schema.json:
FLEX-WP-0019 closed G3 on 2026-09-02 by adding the field, not by
composition. That resolves against ratification — carrying its own end was
the one structural thing the composed bundle did that the split does not,
so the strongest case for option D is answered, and the answer is no.

secrets-engine reported that the split reduces what the PEP verifies: the
distinct-approver threshold is now folded into valid_now and no longer
checked independently. Correct on layering and a real reduction; both are
true. Recorded with its compensating property — reconstructability at the
issuer under §9.6, which is detection rather than prevention.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:05:01 +02:00
10a9dc71ef Settle the §13 register disposition as GH-DEC-2026-006
GH-WP-0003-T03. maturity-engine holds the §13 gap register and the §13.1
stance-map inventory as queryable data and proposed the statute tables
become pointers. Two things are true at once: a statute should not carry
state, and a standard must be readable on its own.

The registers become pointers, and not before maturity-engine publishes a
committed, versioned export readable without a live query. Publication is
the migration's precondition, not its follow-up — pointing an auditor at
a live engine is not a register they can read, and would repeat in the
other direction the exact defect §13.1 was created to fix.

Until the export lands the tables stay and rows are transcribed, so
user-engine, tenant-engine, ops-warden and ops-mason are inventoried in
v0.8 either way rather than waiting on the condition.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:02:05 +02:00
repo-manager
e4373bafd5 repo.work.create_decision GH-DEC-2026-006
correlation_id: b0e67698-7b4b-400a-86e3-f06c4c3464f6
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:38:49 +02:00
repo-manager
ddb02d0836 repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:38:10 +02:00
fcdcb0af9b Audit the v0.6 review findings against accepted v0.7
Marking the 2026-08-29 review round read on the reasoning that v0.7's
acceptance closed it was an inference, not a check. This does the check:
fifteen findings and two answered questions from kings-guard, ops-warden,
access-engine and audit-core, each traced to v0.7 text or a decision
record rather than to the §15 change log.

All fifteen are dispositioned. None was silently dropped. The change log
deliberately is not the evidence — kings-guard's finding 1 was exactly
the case where the change log claimed a rule the body did not contain.

One item surfaced, and it is not a v0.6 finding: §17 still says
emission-cadence ownership is proposed and unassented, which
GH-DEC-2026-004 and the info-tech-canon and net-kingdom acceptances have
since made false. Tracked as GH-WP-0003-T07.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:38:09 +02:00
repo-manager
e16cd792b3 repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:32:11 +02:00
0892807b51 Open GH-WP-0003 for the statute v0.8 amendment set
Five rulings made since security-layer-model v0.7 was accepted belong in
the statute and are currently held in gate-house contracts, decision
records, or a reply in another repository's inbox: the §9.7.3 consume
ordering clarification, the §11 emission-guarantee check, the §13/§13.1
register disposition, kings-guard's recomputability boundary for §9.5,
and GH-DEC-2026-005's split-validation doctrine.

Each was correctly kept out of v0.7. Together they are a version. v0.7
stays accepted and unedited; gate-house authors, net-kingdom publishes.

T03 also discharges the four outstanding §13.1 stance-map rows that
user-engine, tenant-engine, ops-warden and ops-mason are waiting on,
either as transcribed entries or as a confirmed pointer to
maturity-engine.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:32:09 +02:00
repo-manager
c6ccf27054 repo.work.create_workplan GH-WP-0003 (create)
correlation_id: 04092a71-e213-4614-8e58-331f37dce7c2
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:31:34 +02:00
1a920a5490 Confirm the approval-claim as the step-1 PEP artifact
approval-engine raised APPROVAL-IN-0002: secrets-engine's PEP validator
expects a flex-auth ActionAuthorization but fetches the approval-claim
endpoint that GH-DEC-2026-003 names as step 1. Two objects on one path.

GH-IN-0002 records the intake; GH-DEC-2026-005 resolves it. The claim is
the step-1 artifact and always was — ActionAuthorization is unratified,
has no valid_now field, and cannot be served from a step-1 call. The
addition beyond confirmation is doctrine: a PEP validates each artifact
against the layer that owns its data, and no PIP republishes the PDP's
decision. The provenance.authority == "state-hub" requirement is struck;
State Hub is a read model and holds no runtime approval authority.

docs/contracts/approval-consumption.md carries the amendment at the
sequence itself so implementers find it there.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:29:28 +02:00
repo-manager
60e2e7de65 repo.work.create_decision GH-DEC-2026-005
correlation_id: a62fcaea-d7f9-4b8a-9d68-d3e0e9a2fe14
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:28:23 +02:00
repo-manager
be18542cc6 repo.work.create_intake GH-IN-0002
correlation_id: d2369d5a-ffae-4dc5-9f6a-ee4011d50b4c
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:28:12 +02:00
cf646c3195 Decide emission cadence ownership
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-04 02:59:35 +02:00
c0c25e7056 Finish GH-WP-0001 conformance loop
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 15:49:25 +02:00
18ec61a696 Record Whitehat ASM fixture calibrations
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 13:12:58 +02:00
774f69ff80 Reconcile T06 calibration and risk disposition
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 13:10:07 +02:00
b3fd044f55 Review Whitehat ASM target triage
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 08:16:01 +02:00
78f1d9f06d Route first posture finding through risk nexus
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 01:10:13 +02:00
0878bef35e Record ASM T-06 candidate handoff
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 00:53:07 +02:00