# Conformance disposition — kings-guard qonto live observation **Repository:** gate-house **Status:** reviewed; cadence ownership resolved; implementation finding registered as RISK-F-0011 **Date:** 2026-09-02 **Contract:** `posture-findings-return.v1` **Source:** State Hub message `23480b81-bc34-4df4-92cc-840fbc8514fd` **Observer:** kings-guard **Observer revision:** `9daea96` **Observed source:** qonto-assistant **Gate House disposition:** `no_change` **Workplan:** GH-WP-0001-T06 **Acknowledged:** 2026-09-02 by reply to the source message ## Returned observation King's Guard completed `KG-WP-0003-T06/T07` and accepted `posture-findings-return.v1` without revision. Real events emitted by `qonto-assistant.audit.AuditLogger` through `CapabilityService` reached the evaluator: - one `org_summary` / REST allow; - one `list_transactions` / MCP deny with `arg_constraint`; - observation identifiers `req-kg-live-allow` and `req-kg-live-deny-arg-constraint`; - signal identifier `sig:req-kg-live-deny-arg-constraint`. The mapping of request identifier, capability to resource scope, decision, and protocol held without adapter drift. Output remained `advisory_only` and `metadata_only`. `EffectorRequest` now retains originating observation and signal identifiers, stream completeness, and restrictive direction. ## Finding preserved King's Guard returned `audit.deny` as load-bearing because qonto-assistant's escalation loop branches on denies. Risk Nexus's current-source check narrowed that rationale: `DenyEscalationTracker` is in-process on the decision path, while `AuditLogger.emit` is a parallel record. A missing audit line would not disable qonto-assistant's local lockout. The emitted stream is nevertheless load-bearing for estate observation because King's Guard consumes it. Its stream completeness is `unknown`: - no heartbeat or emission-cadence declaration is published; - no reconciliation view was supplied; - record richness of 90 describes the received deny record, not the stream; - no claim is made that every deny was emitted or observed. This is a finding against source emission completeness, not against the received record's mapping and not evidence that an event was suppressed. The live lane therefore supports only this bounded statement: > King's Guard observed real qonto-assistant allow and deny events and preserved > their origin through advisory output. It cannot yet vouch for completeness of > the load-bearing deny stream. It does not support an estate-wide claim that observation is staffed, or a claim that qonto-assistant's deny evidence is complete. ## Doctrine disposition `no_change`. The result validates the existing doctrine rather than changing it: - posture remained restrictive and did not create authority; - origin linkage survived into the proposal shape; - stream completeness was reported separately from record richness; - missing cadence produced an explicit finding rather than optimistic posture; - implementation remediation stayed outside Gate House. Gate House records security-layer-model §12's observation step as **staffed for the qonto-assistant lane only**, with completeness explicitly pending. ## Residual routing | Residual | Owner | Route | State at review | | --- | --- | --- | --- | | Publish heartbeat plus reconciliation for load-bearing `audit.deny`; optionally emit `identity_binding` and `egress_destination` rather than relying on genome constants. | qonto-assistant | State Hub message `3b9c26a1-ba1a-4189-b439-edd61683aed5` from kings-guard | Delivered, unread; no owning work record observed. | | Adopt the generic `EmissionCadenceDeclaration` semantic contract. | info-tech-canon | Original handover `5c6868e9-05bc-4970-b5b9-6f777451e15b`; decided request `0c6ace40-e0e4-4928-81d1-34fcf83133b9` | Ownership assigned by GH-DEC-2026-004; repository assent and publication pending. | | Adopt the importing NetKingdom security profile. | net-kingdom | Original handover `dd15c0d1-c092-4701-a20a-8f37c6406186`; decided request `7a316d92-411f-4b83-8120-ef68eba9ddfc` | Ownership assigned by GH-DEC-2026-004; repository assent and publication pending. | Gate House does not create either repository's task. Until each recipient accepts, revises, or rejects its route, these remain pending residuals rather than assumed work. GH-DEC-2026-004 resolves the previously ambiguous Taxonomy ownership. The generic contract belongs to `info-tech-canon`; `net-kingdom` imports it and owns the security profile. Source repositories own declaration instances and emission, while `kings-guard` remains the evaluator. The drafter was notified in message `954bd7be-3b51-4ba8-a896-b4b4c0966645`. This ruling does not claim either Taxonomy artifact has already been published. The implementation finding was routed through risk-nexus in message `53645a75-0215-4261-a700-f7aedf09e7e8` and registered as `RISK-F-0011` under `RISK-RULING-2026-09-02-A`: `medium` (`I2` × `L3`), public, open, no escalation. Risk Nexus owns grading and remediation tracking; qonto-assistant continues to own any fix. The source-check clarification changes the stated load-bearing rationale, not Gate House's `no_change` doctrine disposition or the bounded completeness finding. ## Review triggers Re-review when any of the following occurs: 1. qonto-assistant publishes or rejects the heartbeat/reconciliation obligation; 2. info-tech-canon or net-kingdom accepts, revises, or contests its assigned artifact; 3. kings-guard reports a complete-stream observation; 4. the qonto-assistant event or genome revision changes; 5. the restrictive posture or origin-link contract changes. Closing this Gate House review does not close the source finding.