# Audit — v0.6 review findings against accepted v0.7 **Repository:** gate-house **Project family:** NetKingdom security layer **Status:** complete **Version:** 1.0 **Date:** 2026-09-06 ## Why this exists On 2026-09-06 the four v0.6 review messages — `kings-guard`, `ops-warden`, `access-engine` (flex-auth), and `audit-core` — were marked read on the reasoning that v0.7's acceptance closed the round by definition. That is an inference, not a check. A review round is closed when each finding has a disposition someone can point at, not when a later version is accepted over it. This document does the check. Fifteen findings and two answered questions were raised across the four reviews. Each is traced to text in `net-kingdom/canon/standards/security-layer-model_v0.7.md` or to a decision record. **Result: all fifteen are dispositioned. None was silently dropped.** One consequence of a *later* decision has since made a v0.7 paragraph stale; it is recorded below and tracked, and it is not a v0.6 finding. ## kings-guard | # | Finding | Disposition | | --- | --- | --- | | 1 | §1 and §15 announce a human/agent principal separation that §3.4 never states | **Written.** §3.4 now carries *"Two principals, one layer"* and the four rules binding the agent principal: no standing credential, tool use is a conduit or an Engine API, agent memory is not a state plane, every agent action reconstructable as the caller's. `glas-harness` is demarcated as governing session conduct. | | 2 | §13 attributes the containment surface to `kings-guard`, which §9.2 ruled is not theirs | **Reattributed.** The §13 row now reads declarer `gate-house (estate-wide)`, owner `access-engine + runtime engines`, state `proposed`; §9.2's text says `kings-guard` is not the declarer. | | 3 | §17's emission-cadence declaration is unowned; offer to draft it | **Accepted, then owned.** §17 records `kings-guard` as accepted drafter. Ownership itself was settled later by `GH-DEC-2026-004`. | | nit | §17–§19 are H1 where every other section is H2 | **Fixed.** §17 and §18 are H2; §19 no longer exists (see access-engine 5). | The finding kings-guard called substantive was finding 1, and it was the right call: a rule announced in a change log and absent from the body is the §11 defect turned on the standard itself. It is now in the body. ## ops-warden | # | Finding | Disposition | | --- | --- | --- | | 1 | §6.4 obligation 1 forbids what obligation 3 blesses; ops-warden's shipped fail-open stance was made a violation | **Adopted, near-verbatim.** Obligation 1 now reads *"…or its declared §9.3 stance for the applicable scope permits proceeding without one and the application of that stance is recorded in place of the decision."* The text names the second limb as stricter than silence and credits ops-warden as the reference shape. | | 2 | §6.4 mandates a stance-map register §13 does not implement | **Register created.** §13.1 "PEP stance-map register" exists; §6.4's closing paragraph records that v0.6 named a register that did not exist and that its first inventory had one row, "which is itself the finding". | | rec | The published map MUST equal shipped behaviour | **Adopted.** Obligation 3 carries the equality requirement with the SHOULD-be-tested clause and ops-warden's own reasoning: a map free to drift is worse than none. | ops-warden's process note — that `assented_by` carries assent forward across five revisions and could be read as assent to current text — is answered in the v0.7 header comment: *"records assent to a BOUNDARY, given at the version named. It is not assent to the current text."* ## access-engine (flex-auth) | # | Item | Disposition | | --- | --- | --- | | Q1(a) | §6.4.2 forbids the session-bound allow §9.7.1 permits | **Scoped.** Obligation 2 is now bounded to replay *outside* the decision's stated binding and lifetime, and says v0.6 forbade what §9.7.1 permits. | | Q1(b) | "Later request" needs a mechanical test | **Adopted as normative.** Replay is permitted iff the canonical request digest matches and the lifetime holds. | | Q1(c) | Deny-caching is outlawed by inference, never ruled on | **Ruled explicitly.** Negative caching is permitted narrowly: the refusal must be recorded against the request refused, and the cache lifetime declared alongside the stance map. | | Q2 | A single visibility deadline is the wrong shape for a PDP | **Adopted.** §9.7.2 requires one deadline at a PEP and a deadline per input class at a PDP, and names the registry-provenance digest and the deadline as one gap seen from two sides. | | 1 | §6.4's stance-map register does not exist | **Same disposition as ops-warden 2.** §13.1 exists; §6.4 credits both repositories as raising it independently. | | 2 | The companion omits where a stance map is published and omits the inventory obligation | **Fixed.** `SECURITY-COMPANION.md` step 3 now says *"at a path named in your layer declaration, and register it in statute §13.1"*. | | 3 | §17 puts the decision-record schema in the wrong layer | **Adopted.** The row is struck through and moved to `access-engine`, with a paragraph applying the §2 ownership rule and noting the finding was raised against its own interest. | | 4 | §17–§19 H1 headings | **Fixed** (see kings-guard nit). | | 5 | §19 grades the document it lives in | **Removed.** There is no §19 in v0.7; the numbering runs §18 → §20. | ## audit-core | # | Finding | Disposition | | --- | --- | --- | | 1 | Atomicity closes accidental omission, not the adversarial case §9.6 opens with | **Adopted as a decomposition table.** §9.6 now separates accidental omission (closed by atomicity) from adversarial omission (*"detected, after the fact"* by cadence and reconciliation), and states the residual explicitly: nothing in the model prevents adversarial omission at a compromised source. | | 2 | Cadence is a SHOULD and is the only control on that residual; rate monitoring inverts the priority for rare events | **Both halves adopted.** Load-bearing sources MUST declare cadence (attributive SHOULD), and for low-volume load-bearing classes the required form is positive reconciliation or a heartbeat rather than rate monitoring, with `GH-WP-0002-T04` named as the reference instance. | | 3 | §3.3's Evidence row states a trade as a property | **Adopted.** The row reads *"a default, not a property; see below"*, and the following paragraph records that an operation genuinely requiring independent recording before effect is a declared exception raised when needed, not one ruled out by a table cell. | Finding 1 corrected a remedy audit-core had itself proposed, and finding 2 argued against the control it was defending. Both are in the standard in stronger form than they arrived. ## What the audit did surface Not a v0.6 finding — a v0.7 paragraph made stale by a later decision. §17 closes with *"Ownership is proposed, not assigned… Neither has assented."* That was true when v0.7 was accepted. It is no longer: `GH-DEC-2026-004` assigned the split — `info-tech-canon` owns the ecosystem-wide `EmissionCadenceDeclaration` contract, `net-kingdom` owns the NetKingdom security profile — and both accepted in their own voice (`ITC-WP-0018` publishing `ITC-EMISSION-CADENCE 0.1` in canon 0.7.0; `NK-WP-0035` publishing `emission-cadence-security-profile_v0.1.md`). A reader of the accepted statute is currently told the estate has not decided something it has. Tracked as `GH-WP-0003-T07`. v0.7 is not patched in place. ## Method note The four review messages were re-read from the State Hub rather than from memory, and each finding was checked against the v0.7 text rather than against the change log. §15's change log is a claim about the body; kings-guard's finding 1 is precisely the case where that claim was false, so it cannot be the evidence.