Commit graph

15 commits

Author SHA1 Message Date
ebe6032059 Update CLAUDE.md for the re-cut
The guidance still described Gate House as the deterministic authority plane
and pointed agents at the Blueprint's component architecture and reference
implementation layout — it would have actively misled the next session.

- Lead with the re-cut and the INV-02 argument, and say plainly that any
  proposal having Gate House decide, store, evaluate, or enforce at request
  time is wrong regardless of how well built.
- Add the decision record to the document hierarchy, above the Canon, and
  mark the Blueprint as partly withdrawn with the surviving sections named.
- Reframe the invariants as doctrine Gate House authors rather than
  constraints on code it writes; add the Staff/Tooling rule as binding on
  this repo itself.
- Record the normative demarcations: access lane vs access rule, doctrine vs
  runbook, control plane as Engine vocabulary.
- Replace the implementation-layout guidance with where doctrine artifacts
  go, and note that T-01…T-10 are specifications executed by whitehat.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:22:51 +02:00
f4353fddbc Rewrite README against the re-cut
The README described the withdrawn engine framing and stated "Gate House
authorizes", contradicting INTENT.md. It now leads with the Staff-layer
doctrine council role, the layer model, and the INV-02 argument for why
Gate House is not the decision point.

Its one already-correct sentence — Gate House as observability for governed
secrets under sound governance policy — is what the rewrite builds on.

Flags the Blueprint as predating the re-cut so readers are not misled by it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:21:51 +02:00
repo-manager
7b2d2eff91 chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:17:05 +02:00
a7d11914d7 Ignore local repo-manager index
.repo-manager/index.json is a rebuildable local cache written by rmgr, not
repository state. repo-manager gitignores its own; match that.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:16:19 +02:00
repo-manager
f861f45ca2 repo.work.resolve_decision GH-DEC-2026-001
correlation_id: 18f20bc4-d273-4697-9bd0-c2e43536cd36
reason: Ratify the 2026-08-28 layer model rulings
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:16:01 +02:00
repo-manager
d9b52dfda1 repo.work.create_decision GH-DEC-2026-001
correlation_id: 7ac7bd1d-2de1-4158-997a-d7b4bb2fb0d5
reason: Ratify the three linked rulings from the 2026-08-28 security estate review
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:15:15 +02:00
7f13f7290d Rewrite INTENT.md: Gate House as the doctrine council
Re-cuts Gate House from deterministic authority plane to the Staff-layer
council where NetKingdom's security and defence doctrine is established,
documented, taught, and supervised.

The decisive argument is now stated in the document itself: a decision point
inside Gate House would place the deterministic authority boundary inside the
non-deterministic management layer, violating INV-02 — the first invariant the
repository exists to defend. access-engine (currently flex-auth) stays the only
policy decision point.

Adds the layer model and the Staff invariant (Staff never touches tooling
directly), a corrected responsibility table that names access-engine,
zone-engine, and the canon repos, the access lane/rule demarcation with
ops-warden and ops-mason, the conformance loop, and falsifiers.

Drops the /authorize surface, policy evaluation order, policy engine
selection, grant storage, revocation, and the technical direction section.
Keeps what no other repo owns: operating modes, the principal/actor/runtime
triple, mandates and ceilings, change dynamics, MCP doctrine, the posture
asymmetry, and the assurance specifications.

Addresses the name/metaphor risk in the opening: the gate house is where the
watch is set and the porter's rules are posted, not the gate itself.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 20:16:31 +02:00
4d913c52fd Record layer-model rulings: Staff, net-kingdom canon, access-engine
Name the top layer Staff rather than Helpers, throughout. Place the layer
model in net-kingdom canon rather than info-tech-canon — it is NetKingdom
security architecture, not general semantic contract.

Record flex-auth's reframing as an Engine with access-engine as the working
rename target, and note the one cost: "access" is already spoken for
operationally by ops-warden and ops-mason, so adopting it requires
demarcating access lanes from access rules in both INTENTs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 20:04:57 +02:00
9f7df24c73 Record security layer model and gate-house re-cut
Reference note from the 2026-08-28 review of INTENT.md across the security
estate. Establishes the four-layer model (taxonomy / tooling / engines /
helpers), distinguished by determinism and artifact kind, and its
self-similarity to the ASM Canon's three planes.

Key finding: gate-house's authority-plane framing places a deterministic
decision point inside the non-deterministic management layer, violating
INV-02, and collides with flex-auth's declared ownership of authorization.
zone-engine §5 already ruled that flex-auth is the only policy decision
point. Re-cuts gate-house as the doctrine and conformance council.

Not canon and not a decision record; the decisions it recommends still
have to be written and assented to.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 19:55:40 +02:00
repo-manager
83369c7217 chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 17:51:10 +02:00
custodian-sync
2a5f26ef74 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-25:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 17:51:09 +02:00
a97e7c8ee1 Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.

SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.

Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.

Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
8604fe6021 Added active secrets management standard and architecture blueprint draft 2026-08-24 20:26:50 +02:00
683f6d2769 Seeded INTENT.md and README.md 2026-08-24 19:58:45 +02:00
65268fd221 Initial commit 2026-08-24 17:43:01 +00:00