Five rulings made since security-layer-model v0.7 was accepted belong in
the statute and are currently held in gate-house contracts, decision
records, or a reply in another repository's inbox: the §9.7.3 consume
ordering clarification, the §11 emission-guarantee check, the §13/§13.1
register disposition, kings-guard's recomputability boundary for §9.5,
and GH-DEC-2026-005's split-validation doctrine.
Each was correctly kept out of v0.7. Together they are a version. v0.7
stays accepted and unedited; gate-house authors, net-kingdom publishes.
T03 also discharges the four outstanding §13.1 stance-map rows that
user-engine, tenant-engine, ops-warden and ops-mason are waiting on,
either as transcribed entries or as a confirmed pointer to
maturity-engine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
approval-engine raised APPROVAL-IN-0002: secrets-engine's PEP validator
expects a flex-auth ActionAuthorization but fetches the approval-claim
endpoint that GH-DEC-2026-003 names as step 1. Two objects on one path.
GH-IN-0002 records the intake; GH-DEC-2026-005 resolves it. The claim is
the step-1 artifact and always was — ActionAuthorization is unratified,
has no valid_now field, and cannot be served from a step-1 call. The
addition beyond confirmation is doctrine: a PEP validates each artifact
against the layer that owns its data, and no PIP republishes the PDP's
decision. The provenance.authority == "state-hub" requirement is struck;
State Hub is a read model and holds no runtime approval authority.
docs/contracts/approval-consumption.md carries the amendment at the
sequence itself so implementers find it there.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Updated by fix-consistency on 2026-08-29:
- update .custodian-brief.md for gate-house
Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
Adopt approval-engine's outbox wire as Gate House doctrine, specify the
heartbeat-and-reconciliation detection surface, and settle consumption
ordering: the PEP consumes by CAS before the side effect. T05's §11
check is written here and queued for statute v0.8.
Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
correlation_id: 1fd8961e-6174-4479-8bd8-ca17ee5f9040
reason: GH-WP-0002-T03: record the revocation failure mode so it is not an implementation accident
source: repo-manager
Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
Updated by fix-consistency on 2026-08-29:
- update .custodian-brief.md for gate-house
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
The layer model is accepted at v0.7. References bumped from v0.4, and CLAUDE.md
now sends readers to net-kingdom/SECURITY-COMPANION.md as the working form, and
to ops-warden for how to get things done — doctrine is ours, the paths through
it are not.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Updated by fix-consistency on 2026-08-29:
- update .custodian-brief.md for gate-house
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
audit-core raised the intake with a drafted five-task plan and invited us to
promote it verbatim or revise. Adopted close to verbatim, plus a sixth task for
the consumption ordering contract flex-auth raised in the same round.
The omission gap is not accepted for approvals. v0.5 §9.6 distinguishes
load-bearing evidence from attributive; approvals are load-bearing, so emission
atomicity is required and the outbox must be local.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
audit-core corrected a claim this repository's doctrine also makes. An
append-only archive with a verified hash chain proves records were not altered
or truncated after arrival; it cannot prove one was never sent. A suppressed
event leaves the chain intact and verification reports intact — and the event
an adversary most wants missing is the negative one: a revocation, a denial, a
containment action.
Adds the bound under the Core Rules, replacing "the audit record proves it
happened" with the sound form, and records that completeness is the emitting
system's obligation via atomic emission.
Flags outstanding doctrine work: the ASM Canon's control §27 and tests T-08 and
T-09 are written as though reconstruction from evidence were unconditional.
Also bumps standard references to v0.4.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
correlation_id: 8a98310d-7fcf-41c0-9db2-9157d10a62e4
reason: audit-core raises the emission atomicity gap conditioning its AUDIT-IN-0001 assent; requests promotion to a GH-WP workplan
source: repo-manager
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4040362@bnt-lap001
Assistant-Session: 4fd0fd24-2ee8-4413-bd67-43bd79ca73f1
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Updated by fix-consistency on 2026-08-28:
- update .custodian-brief.md for gate-house
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
All three assent requests answered, each with a decision record and each with
a finding. Standard revised to v0.2 and accepted.
- history note gains §12 recording the outcome and what each repository
returned.
- README and CLAUDE.md now cite security-layer-model_v0.2.md.
- GH-WP-0001-T03 closed.
Three of the four v0.2 changes came from the assenting repositories rather
than from gate-house.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Assent was ratified as needed but never actually requested. Raised as intakes
in the owning repositories — FLEX-IN-0001, KG-IN-0001, WARDEN-IN-0001 — with
State Hub inbox notification.
Intakes rather than tasks: GH-DEC-2026-001 does not authorize changing another
repository's workplans, and ADR-007 places work structure with the repository
doing the work. An intake is the inbound channel; each repository triages and
promotes it into its own structure.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Regenerated by fix-consistency after the GH-WP-0001 rewrite.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9