Commit graph

31 commits

Author SHA1 Message Date
custodian-sync
edd969775a chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-29:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:56:50 +02:00
02a1dc1b9a Promote GH-IN-0001 to GH-WP-0002: approval evidence integrity
audit-core raised the intake with a drafted five-task plan and invited us to
promote it verbatim or revise. Adopted close to verbatim, plus a sixth task for
the consumption ordering contract flex-auth raised in the same round.

The omission gap is not accepted for approvals. v0.5 §9.6 distinguishes
load-bearing evidence from attributive; approvals are load-bearing, so emission
atomicity is required and the outbox must be local.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:56:11 +02:00
repo-manager
159283663b repo.work.close_intake GH-IN-0001
correlation_id: 7df6a142-2e5c-45ae-8fbd-b74a9df445be
reason: Promoted to GH-WP-0002
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:55:21 +02:00
repo-manager
776fa6893b repo.work.add_intake_note GH-IN-0001
correlation_id: b339a2a6-eafd-4d77-a140-67f037e7a560
reason: Promote GH-IN-0001 to GH-WP-0002
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:55:21 +02:00
0574abbe20 Refresh work-record index
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 22:56:01 +02:00
94526e44c0 Bound rule 13: audit proves alteration, not omission
audit-core corrected a claim this repository's doctrine also makes. An
append-only archive with a verified hash chain proves records were not altered
or truncated after arrival; it cannot prove one was never sent. A suppressed
event leaves the chain intact and verification reports intact — and the event
an adversary most wants missing is the negative one: a revocation, a denial, a
containment action.

Adds the bound under the Core Rules, replacing "the audit record proves it
happened" with the sound form, and records that completeness is the emitting
system's obligation via atomic emission.

Flags outstanding doctrine work: the ASM Canon's control §27 and tests T-08 and
T-09 are written as though reconstruction from evidence were unconditional.

Also bumps standard references to v0.4.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 22:55:19 +02:00
repo-manager
d62d48aba2 repo.work.create_intake GH-IN-0001
correlation_id: 8a98310d-7fcf-41c0-9db2-9157d10a62e4
reason: audit-core raises the emission atomicity gap conditioning its AUDIT-IN-0001 assent; requests promotion to a GH-WP workplan
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4040362@bnt-lap001
Assistant-Session: 4fd0fd24-2ee8-4413-bd67-43bd79ca73f1
2026-08-28 22:50:02 +02:00
516ed4e93e Refresh work-record index
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 22:01:53 +02:00
custodian-sync
fad706a98b chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-28:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 22:01:28 +02:00
62dc8298e5 Record assent outcome; point at standard v0.2
All three assent requests answered, each with a decision record and each with
a finding. Standard revised to v0.2 and accepted.

- history note gains §12 recording the outcome and what each repository
  returned.
- README and CLAUDE.md now cite security-layer-model_v0.2.md.
- GH-WP-0001-T03 closed.

Three of the four v0.2 changes came from the assenting repositories rather
than from gate-house.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 22:01:08 +02:00
repo-manager
347524751e repo.work.update_task_status GH-WP-0001-T03 -> done
correlation_id: 81143b78-1ae7-4f09-924b-02fa93adbc99
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 22:01:01 +02:00
046b06fb18 Record assent requests raised for GH-WP-0001-T03
Assent was ratified as needed but never actually requested. Raised as intakes
in the owning repositories — FLEX-IN-0001, KG-IN-0001, WARDEN-IN-0001 — with
State Hub inbox notification.

Intakes rather than tasks: GH-DEC-2026-001 does not authorize changing another
repository's workplans, and ADR-007 places work structure with the repository
doing the work. An intake is the inbound channel; each repository triages and
promotes it into its own structure.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:31:13 +02:00
4f618b44de Refresh work-record index
Regenerated by fix-consistency after the GH-WP-0001 rewrite.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:25:21 +02:00
custodian-sync
977f1d91ce chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-28:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:24:36 +02:00
repo-manager
81f9fce82b repo.work.update_workplan GH-WP-0001 (update)
correlation_id: a1e9a76e-93d5-4bcb-a843-56e168041b26
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:24:07 +02:00
e9f29e6551 Mark the Blueprint as partly withdrawn
The blueprint predates the re-cut and describes Gate House as a running
engine. Rather than delete it, mark it — the estate's precedent (zone-engine)
is to retain superseded argument as design history.

Adds a status banner with a per-section table separating what survives (domain
model, authority context, operating modes, posture and credential contracts,
MCP doctrine, change dynamics, audit, test program, architectural invariants)
from what is withdrawn (component and policy architecture, evaluation order,
storage, API surface, caching, deployment, technology direction, reference
repository layout, performance, availability, admin interfaces) and what has
lapsed (ADR-003; milestones M0, M3, M4).

Inline markers on the eight sections most likely to be cited.

A revision folding the surviving material into doctrine form is outstanding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:23:32 +02:00
ebe6032059 Update CLAUDE.md for the re-cut
The guidance still described Gate House as the deterministic authority plane
and pointed agents at the Blueprint's component architecture and reference
implementation layout — it would have actively misled the next session.

- Lead with the re-cut and the INV-02 argument, and say plainly that any
  proposal having Gate House decide, store, evaluate, or enforce at request
  time is wrong regardless of how well built.
- Add the decision record to the document hierarchy, above the Canon, and
  mark the Blueprint as partly withdrawn with the surviving sections named.
- Reframe the invariants as doctrine Gate House authors rather than
  constraints on code it writes; add the Staff/Tooling rule as binding on
  this repo itself.
- Record the normative demarcations: access lane vs access rule, doctrine vs
  runbook, control plane as Engine vocabulary.
- Replace the implementation-layout guidance with where doctrine artifacts
  go, and note that T-01…T-10 are specifications executed by whitehat.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:22:51 +02:00
f4353fddbc Rewrite README against the re-cut
The README described the withdrawn engine framing and stated "Gate House
authorizes", contradicting INTENT.md. It now leads with the Staff-layer
doctrine council role, the layer model, and the INV-02 argument for why
Gate House is not the decision point.

Its one already-correct sentence — Gate House as observability for governed
secrets under sound governance policy — is what the rewrite builds on.

Flags the Blueprint as predating the re-cut so readers are not misled by it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:21:51 +02:00
repo-manager
7b2d2eff91 chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:17:05 +02:00
a7d11914d7 Ignore local repo-manager index
.repo-manager/index.json is a rebuildable local cache written by rmgr, not
repository state. repo-manager gitignores its own; match that.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:16:19 +02:00
repo-manager
f861f45ca2 repo.work.resolve_decision GH-DEC-2026-001
correlation_id: 18f20bc4-d273-4697-9bd0-c2e43536cd36
reason: Ratify the 2026-08-28 layer model rulings
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:16:01 +02:00
repo-manager
d9b52dfda1 repo.work.create_decision GH-DEC-2026-001
correlation_id: 7ac7bd1d-2de1-4158-997a-d7b4bb2fb0d5
reason: Ratify the three linked rulings from the 2026-08-28 security estate review
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 21:15:15 +02:00
7f13f7290d Rewrite INTENT.md: Gate House as the doctrine council
Re-cuts Gate House from deterministic authority plane to the Staff-layer
council where NetKingdom's security and defence doctrine is established,
documented, taught, and supervised.

The decisive argument is now stated in the document itself: a decision point
inside Gate House would place the deterministic authority boundary inside the
non-deterministic management layer, violating INV-02 — the first invariant the
repository exists to defend. access-engine (currently flex-auth) stays the only
policy decision point.

Adds the layer model and the Staff invariant (Staff never touches tooling
directly), a corrected responsibility table that names access-engine,
zone-engine, and the canon repos, the access lane/rule demarcation with
ops-warden and ops-mason, the conformance loop, and falsifiers.

Drops the /authorize surface, policy evaluation order, policy engine
selection, grant storage, revocation, and the technical direction section.
Keeps what no other repo owns: operating modes, the principal/actor/runtime
triple, mandates and ceilings, change dynamics, MCP doctrine, the posture
asymmetry, and the assurance specifications.

Addresses the name/metaphor risk in the opening: the gate house is where the
watch is set and the porter's rules are posted, not the gate itself.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 20:16:31 +02:00
4d913c52fd Record layer-model rulings: Staff, net-kingdom canon, access-engine
Name the top layer Staff rather than Helpers, throughout. Place the layer
model in net-kingdom canon rather than info-tech-canon — it is NetKingdom
security architecture, not general semantic contract.

Record flex-auth's reframing as an Engine with access-engine as the working
rename target, and note the one cost: "access" is already spoken for
operationally by ops-warden and ops-mason, so adopting it requires
demarcating access lanes from access rules in both INTENTs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 20:04:57 +02:00
9f7df24c73 Record security layer model and gate-house re-cut
Reference note from the 2026-08-28 review of INTENT.md across the security
estate. Establishes the four-layer model (taxonomy / tooling / engines /
helpers), distinguished by determinism and artifact kind, and its
self-similarity to the ASM Canon's three planes.

Key finding: gate-house's authority-plane framing places a deterministic
decision point inside the non-deterministic management layer, violating
INV-02, and collides with flex-auth's declared ownership of authorization.
zone-engine §5 already ruled that flex-auth is the only policy decision
point. Re-cuts gate-house as the doctrine and conformance council.

Not canon and not a decision record; the decisions it recommends still
have to be written and assented to.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 19:55:40 +02:00
repo-manager
83369c7217 chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 17:51:10 +02:00
custodian-sync
2a5f26ef74 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-25:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 17:51:09 +02:00
a97e7c8ee1 Register with repo-manager and add agent guidance
Register gate-house as category: tooling, domain: infotech, workplan
prefix GH-WP, via rmgr scaffold. Baseline files: .repo-classification.yaml,
SCOPE.md, AGENTS.md, workplans/GH-WP-0001-foundation.md. rmgr conform
passes with no findings.

SCOPE.md is derived from INTENT.md; GH-WP-0001 targets milestone M0
(executable skeleton) from ArchitectureBlueprint.md §41.

Move ArchitectureBlueprint.md to the repository root, matching its own
reference layout (§32). spec/ retains the Active Secrets Management Canon,
the external standard Gate House conforms to.

Add CLAUDE.md documenting the document precedence (Canon → INTENT →
Blueprint → README), the load-bearing security invariants, the fixed
domain vocabulary, and the stable identifier scheme.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-24 20:41:58 +02:00
8604fe6021 Added active secrets management standard and architecture blueprint draft 2026-08-24 20:26:50 +02:00
683f6d2769 Seeded INTENT.md and README.md 2026-08-24 19:58:45 +02:00
65268fd221 Initial commit 2026-08-24 17:43:01 +00:00