--- id: GH-WP-0001 type: workplan title: "Foundation" domain: infotech repo: gate-house status: active state_hub_workstream_id: "2ec4cf1a-a73f-5793-9738-8d8019cccca8" updated: "2026-08-28" --- # Foundation Establish Gate House as the Staff-layer doctrine council: the layer model in canon, the re-cut recorded, the authority context published as a contract access-engine consumes, and the conformance loop turning. Rewritten 2026-08-28 against `decisions/decisions.md` GH-DEC-2026-001. The previous plan targeted Blueprint milestone **M0** — an `/authorize` skeleton — which lapsed with the re-cut. No service is built in this repository. ```task id: GH-WP-0001-T01 status: done priority: high state_hub_task_id: "af0fa778-89a8-52cf-a73a-021082a98cad" ``` Establish the repository baseline: classification, scope, agent instructions, workplan spine. Done — `rmgr conform` passes with no findings. ```task id: GH-WP-0001-T02 status: done priority: high state_hub_task_id: "6dd21d86-6546-58a7-b59e-fa1db72aae90" ``` Settle the boundary with access-engine and the security estate, and record it. Done — the review is in `history/2026-08-28-security-layer-model-and-gate-house-recut.md`, the ruling in GH-DEC-2026-001, and the model in `net-kingdom/canon/standards/security-layer-model_v0.1.md` (proposed). ```task id: GH-WP-0001-T03 status: done priority: high state_hub_task_id: "12f651be-1c07-587b-a781-4472e189e218" ``` Obtain assent for the boundaries that move vocabulary away from repositories currently using it. Requested 2026-08-28 as intakes in the owning repositories, with State Hub inbox notification — the intake is the inbound channel, so each repository triages and promotes into its own work structure rather than having work created for it: - `FLEX-IN-0001` — Engine framing, the access-engine rename, and the authoring/evaluation split. INTENT reframe applied; rename not authorized. - `KG-IN-0001` — Staff placement, "control plane" as Engine vocabulary, and the posture asymmetry. - `WARDEN-IN-0001` — Staff placement, doctrine versus runbook, the access lane/rule demarcation, and adding gate-house to the routing tables. Awaiting response. Assent, revision, or rejection are all acceptable outcomes; a rejection that names a practical failure is the more valuable answer. Promote the standard from `proposed` to `accepted` once the three have answered. ```task id: GH-WP-0001-T04 status: todo priority: high state_hub_task_id: "7903d142-9763-5b3f-839d-2a1599130a2b" ``` Publish the **authority context** as a contract: principal, actor, runtime identity, tenant, environment, mandate, task, operating mode — the vocabulary access-engine consumes as input claims alongside verified identity claims. Record it as ADR-001 and ADR-002. This is the deliverable that makes the doctrine consumable rather than descriptive. ```task id: GH-WP-0001-T05 status: todo priority: medium state_hub_task_id: "010e3162-cab1-5644-b262-b0d1d7d676f8" ``` Revise `ArchitectureBlueprint.md`: fold the surviving material — domain model, authority context, operating modes, posture and credential contracts, MCP doctrine, change dynamics, audit, architectural invariants — into doctrine form, and retire the withdrawn sections from the working document into design history. Currently marked in place with a status banner. ```task id: GH-WP-0001-T06 status: todo priority: medium state_hub_task_id: "8cc018e1-2787-5435-9c2c-c2b01cf75ae4" ``` Close the conformance loop. Hand the assurance specifications T-01…T-10 to whitehat-security as executable targets, agree the posture and findings return path with kings-guard, and establish how conformance review reports back. Until this turns, Gate House is a paper generator by its own falsifier.