Commit graph

78 commits

Author SHA1 Message Date
repo-manager
f5f4548323 repo.work.update_task_status GH-WP-0003-T02 -> done
correlation_id: 11d61b2f-b3c5-4e23-816a-358632f2a089
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:11:17 +02:00
repo-manager
8fcf28bc93 repo.work.update_task_status GH-WP-0003-T01 -> done
correlation_id: 025159db-79aa-4286-ad0f-8d9745b9432e
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:11:12 +02:00
42e9bcc747 Adopt the recomputability boundary as GH-DEC-2026-007
GH-WP-0003-T04. kings-guard's answer to KG-IN-0003 is adopted: the
posture/maturity line is recomputability, not volatility. Their argument
holds — volatility describes the two categories without partitioning
them, and every case it does not obviously cover becomes an argument at
exactly the boundary §6 exists to keep out of argument. The test is
§9.5's own determinism clause pointed where it had not been pointed.

Added one clause they did not propose, because their framing opens a
loophole: recomputability is assessed over the stated criteria, so a
criterion that dereferences a judgment is deterministic in form and
inferential in substance, and would put an opinion inside an engine
wearing a rule's clothes. A criterion MUST bottom out in evidence about
the subject, not in another party's conclusion about it. A recorded
judgment is evidence that the judgment was made, never that the thing
judged is so — the same distinction §9.6 draws about archives and
GH-DEC-2026-005 draws about valid_now.

All three kings-guard consequences carried, including the constraint they
volunteered against themselves (readiness is not an input to posture) and
their honest limit, which makes §17 load-bearing for the rule.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:08:32 +02:00
repo-manager
cb9b0b80fc repo.work.update_task_status GH-WP-0003-T04 -> done
correlation_id: f9867ccb-8aba-4a36-bbad-6b82b4e63538
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:08:15 +02:00
repo-manager
150ddfb4aa repo.work.create_decision GH-DEC-2026-007
correlation_id: 73b37f0f-be76-4919-b982-2411090b48ab
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:07:34 +02:00
1f4fd20519 Amend GH-DEC-2026-005: strike the G3 trigger, record what the PEP stopped checking
Two corrections from the repositories that implemented the decision, both
volunteered against their own interest.

approval-engine and flex-auth independently reported that the deferred
option's G3 revisit trigger was already spent when the decision was
written. Verified here against flex-auth/schemas/decision_envelope.schema.json:
FLEX-WP-0019 closed G3 on 2026-09-02 by adding the field, not by
composition. That resolves against ratification — carrying its own end was
the one structural thing the composed bundle did that the split does not,
so the strongest case for option D is answered, and the answer is no.

secrets-engine reported that the split reduces what the PEP verifies: the
distinct-approver threshold is now folded into valid_now and no longer
checked independently. Correct on layering and a real reduction; both are
true. Recorded with its compensating property — reconstructability at the
issuer under §9.6, which is detection rather than prevention.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:05:01 +02:00
10a9dc71ef Settle the §13 register disposition as GH-DEC-2026-006
GH-WP-0003-T03. maturity-engine holds the §13 gap register and the §13.1
stance-map inventory as queryable data and proposed the statute tables
become pointers. Two things are true at once: a statute should not carry
state, and a standard must be readable on its own.

The registers become pointers, and not before maturity-engine publishes a
committed, versioned export readable without a live query. Publication is
the migration's precondition, not its follow-up — pointing an auditor at
a live engine is not a register they can read, and would repeat in the
other direction the exact defect §13.1 was created to fix.

Until the export lands the tables stay and rows are transcribed, so
user-engine, tenant-engine, ops-warden and ops-mason are inventoried in
v0.8 either way rather than waiting on the condition.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 08:02:05 +02:00
repo-manager
e4373bafd5 repo.work.create_decision GH-DEC-2026-006
correlation_id: b0e67698-7b4b-400a-86e3-f06c4c3464f6
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:38:49 +02:00
repo-manager
ddb02d0836 repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:38:10 +02:00
fcdcb0af9b Audit the v0.6 review findings against accepted v0.7
Marking the 2026-08-29 review round read on the reasoning that v0.7's
acceptance closed it was an inference, not a check. This does the check:
fifteen findings and two answered questions from kings-guard, ops-warden,
access-engine and audit-core, each traced to v0.7 text or a decision
record rather than to the §15 change log.

All fifteen are dispositioned. None was silently dropped. The change log
deliberately is not the evidence — kings-guard's finding 1 was exactly
the case where the change log claimed a rule the body did not contain.

One item surfaced, and it is not a v0.6 finding: §17 still says
emission-cadence ownership is proposed and unassented, which
GH-DEC-2026-004 and the info-tech-canon and net-kingdom acceptances have
since made false. Tracked as GH-WP-0003-T07.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:38:09 +02:00
repo-manager
e16cd792b3 repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:32:11 +02:00
0892807b51 Open GH-WP-0003 for the statute v0.8 amendment set
Five rulings made since security-layer-model v0.7 was accepted belong in
the statute and are currently held in gate-house contracts, decision
records, or a reply in another repository's inbox: the §9.7.3 consume
ordering clarification, the §11 emission-guarantee check, the §13/§13.1
register disposition, kings-guard's recomputability boundary for §9.5,
and GH-DEC-2026-005's split-validation doctrine.

Each was correctly kept out of v0.7. Together they are a version. v0.7
stays accepted and unedited; gate-house authors, net-kingdom publishes.

T03 also discharges the four outstanding §13.1 stance-map rows that
user-engine, tenant-engine, ops-warden and ops-mason are waiting on,
either as transcribed entries or as a confirmed pointer to
maturity-engine.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:32:09 +02:00
repo-manager
c6ccf27054 repo.work.create_workplan GH-WP-0003 (create)
correlation_id: 04092a71-e213-4614-8e58-331f37dce7c2
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:31:34 +02:00
1a920a5490 Confirm the approval-claim as the step-1 PEP artifact
approval-engine raised APPROVAL-IN-0002: secrets-engine's PEP validator
expects a flex-auth ActionAuthorization but fetches the approval-claim
endpoint that GH-DEC-2026-003 names as step 1. Two objects on one path.

GH-IN-0002 records the intake; GH-DEC-2026-005 resolves it. The claim is
the step-1 artifact and always was — ActionAuthorization is unratified,
has no valid_now field, and cannot be served from a step-1 call. The
addition beyond confirmation is doctrine: a PEP validates each artifact
against the layer that owns its data, and no PIP republishes the PDP's
decision. The provenance.authority == "state-hub" requirement is struck;
State Hub is a read model and holds no runtime approval authority.

docs/contracts/approval-consumption.md carries the amendment at the
sequence itself so implementers find it there.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:29:28 +02:00
repo-manager
60e2e7de65 repo.work.create_decision GH-DEC-2026-005
correlation_id: a62fcaea-d7f9-4b8a-9d68-d3e0e9a2fe14
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:28:23 +02:00
repo-manager
be18542cc6 repo.work.create_intake GH-IN-0002
correlation_id: d2369d5a-ffae-4dc5-9f6a-ee4011d50b4c
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:28:12 +02:00
cf646c3195 Decide emission cadence ownership
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-04 02:59:35 +02:00
c0c25e7056 Finish GH-WP-0001 conformance loop
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 15:49:25 +02:00
18ec61a696 Record Whitehat ASM fixture calibrations
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 13:12:58 +02:00
774f69ff80 Reconcile T06 calibration and risk disposition
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 13:10:07 +02:00
b3fd044f55 Review Whitehat ASM target triage
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 08:16:01 +02:00
78f1d9f06d Route first posture finding through risk nexus
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 01:10:13 +02:00
0878bef35e Record ASM T-06 candidate handoff
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 00:53:07 +02:00
e04a8b76aa Record fixture-safe ASM T-06 candidate
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 00:52:14 +02:00
8af514ffd1 Record GH-WP-0001-T06 coordination receipts
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 00:27:25 +02:00
feff57675f Record first GH-WP-0001-T06 posture disposition
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-02 00:24:28 +02:00
78ee1c0b8a Record GH-WP-0001-T06 handoff and wait gate
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-01 20:48:33 +02:00
8cb7250230 Publish GH-WP-0001-T06 conformance contracts
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-01 20:46:34 +02:00
a4066aadb5 Complete GH-WP-0001-T05 doctrine blueprint recut
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-01 20:32:13 +02:00
custodian-sync
3b927287d0 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-01:
  - update .custodian-brief.md for gate-house

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-01 20:26:51 +02:00
75ce37207f Complete GH-WP-0001-T04 authority context contract
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-01 20:25:25 +02:00
6076d5d9ba Refresh work-record index
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 17:43:03 +02:00
custodian-sync
1e6710f3d0 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-29:
  - update .custodian-brief.md for gate-house

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:54:11 +02:00
repo-manager
d48e9098de repo.work.update_workplan GH-WP-0002 (update)
correlation_id: 0fdd0ae8-0ec0-4704-b80c-5695bf7439fe
reason: All six tasks complete: outbox, revocation failure mode, detection, §11 check queued for v0.8, consumption ordering
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:52:15 +02:00
repo-manager
9a653076f7 repo.work.update_task_status GH-WP-0002-T06 -> done
correlation_id: 1def0243-f331-4165-913a-addd376899d5
reason: GH-WP-0002-T06 complete: contracts and GH-DEC-2026-002/003
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:52:12 +02:00
repo-manager
f05a92915e repo.work.update_task_status GH-WP-0002-T05 -> done
correlation_id: d38a2b44-4fb9-4bde-9426-1e3c5f97d944
reason: GH-WP-0002-T05 complete: contracts and GH-DEC-2026-002/003
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:52:09 +02:00
repo-manager
6f60bda41d repo.work.update_task_status GH-WP-0002-T04 -> done
correlation_id: 930c5835-7f35-4171-8e79-e7a97f0f2c67
reason: GH-WP-0002-T04 complete: contracts and GH-DEC-2026-002/003
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:52:05 +02:00
repo-manager
b3b7eea0db repo.work.update_task_status GH-WP-0002-T03 -> done
correlation_id: 596040b8-7656-4d62-9f1c-01f2e4df1473
reason: GH-WP-0002-T03 complete: contracts and GH-DEC-2026-002/003
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:52:02 +02:00
repo-manager
b2775ba811 repo.work.update_task_status GH-WP-0002-T02 -> done
correlation_id: 905a80c7-6fdb-4539-9a9d-06607a94187f
reason: GH-WP-0002-T02 complete: contracts and GH-DEC-2026-002/003
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:52:00 +02:00
7408ff9234 Publish approval evidence-integrity contracts for GH-WP-0002
Adopt approval-engine's outbox wire as Gate House doctrine, specify the
heartbeat-and-reconciliation detection surface, and settle consumption
ordering: the PEP consumes by CAS before the side effect. T05's §11
check is written here and queued for statute v0.8.

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:51:53 +02:00
repo-manager
2ae611d2ad repo.work.resolve_decision GH-DEC-2026-003
correlation_id: e147a6ab-0644-405e-bdbd-b9dff117d7a8
reason: GH-WP-0002-T06: settle consumption ordering
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:51:01 +02:00
repo-manager
23cbefcb7b repo.work.resolve_decision GH-DEC-2026-002
correlation_id: 75014e3f-ab3f-4038-9e2a-719f2da53abc
reason: GH-WP-0002-T03: record the revocation failure mode
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:50:58 +02:00
repo-manager
6a5d2170a4 repo.work.create_decision GH-DEC-2026-003
correlation_id: e7c050fe-21e4-4529-a79b-d6137438d77a
reason: GH-WP-0002-T06: settle the consumption ordering contract that blocks APPROVAL-WP-0001-T05 and FLEX-WP-0017-T05
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:50:06 +02:00
repo-manager
c5f9169972 repo.work.create_decision GH-DEC-2026-002
correlation_id: 1fd8961e-6174-4479-8bd8-ca17ee5f9040
reason: GH-WP-0002-T03: record the revocation failure mode so it is not an implementation accident
source: repo-manager

Assistant: grok
Assistant-Session: 01a04d89-aaa5-7443-945e-b3055cd4b7e4
2026-08-29 14:50:04 +02:00
custodian-sync
681742767f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-29:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 11:30:11 +02:00
f524badd9d Point at the accepted standard and its companion
The layer model is accepted at v0.7. References bumped from v0.4, and CLAUDE.md
now sends readers to net-kingdom/SECURITY-COMPANION.md as the working form, and
to ops-warden for how to get things done — doctrine is ours, the paths through
it are not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 11:29:48 +02:00
repo-manager
c638822d17 chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:56:51 +02:00
custodian-sync
edd969775a chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-29:
  - update .custodian-brief.md for gate-house

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:56:50 +02:00
02a1dc1b9a Promote GH-IN-0001 to GH-WP-0002: approval evidence integrity
audit-core raised the intake with a drafted five-task plan and invited us to
promote it verbatim or revise. Adopted close to verbatim, plus a sixth task for
the consumption ordering contract flex-auth raised in the same round.

The omission gap is not accepted for approvals. v0.5 §9.6 distinguishes
load-bearing evidence from attributive; approvals are load-bearing, so emission
atomicity is required and the outbox must be local.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:56:11 +02:00
repo-manager
159283663b repo.work.close_intake GH-IN-0001
correlation_id: 7df6a142-2e5c-45ae-8fbd-b74a9df445be
reason: Promoted to GH-WP-0002
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:55:21 +02:00