Two things this week's rulings left owed, both the failure mode those rulings were about. A-16 and A-17, and Core Rules 16 and 17. Two general properties had been stated three times each, always against the instance that produced them and nowhere in general — which is how a property gets found by accident or not at all. That is the defect gate-house corrected in three other repositories this month while carrying it here. A-16, distinguishable routes: where one observable state is reachable by two routes differing in security meaning, the record must say which. Four instances, and they only look like one rule once they are next to each other — an envelope identical whether access-engine issued it or a responder forged it (GH-DEC-2026-010), unknown versus absent in a stance map (-011), a tenant claim directory-asserted versus registration-supplied (-013), erased versus never held on an evidence path (-014). The rule is not that the routes must diverge; usually they must behave identically and safely. It is that a later reader can tell them apart, or a sound check gets read as carrying a property it does not have. A-17, fail-closed transitions: a transitional deviation is admissible only where it fails closed on the case distinguishing it from the conformant state. Written because two requests for transitional relief arrived in one week and were answered oppositely, and the answers would otherwise read as arbitrary rather than as one rule. Both are marked repository-level and explicitly not estate doctrine. Graduation waits on a repository that bears a cost under them having argued them, which is the bar security-layer-model met and these have not. SCOPE.md was still the withdrawn authority-plane framing. It opened by saying gate-house "decides whether a requested action is authorized" and listed deterministic authorization decisions as in scope — the design retired by GH-DEC-2026-001, surviving in a derived document a reader would take as current, with a dead pointer to Blueprint section 3 non-goals that the re-cut removed. Rewritten from current INTENT, including what is not owned here and what would put the repository out of scope. The irony is noted rather than hidden: a derived artifact contradicting its source, in the repository that generalised that failure into statute section 12 after finding six instances in one week elsewhere. rmgr conform clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm Assistant: claude-code Assistant-Model: opus Assistant-Process: 1754332@bnt-lap001 Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
4.3 KiB
Scope
Derived from INTENT.md. Gate House is the council where NetKingdom's security
and defence doctrine is established, documented, taught, and supervised. It is a
Staff-layer repository: it holds no runtime position and renders no
authorization decision.
The mandate and the operating mode are Gate House's. The decision is access-engine's. The credential is secrets-engine's. The perimeter is ops-mason's and ops-warden's.
In scope
- doctrine — the Active Secrets Management Canon, its invariants, and the
argument behind them; doctrine graduates into
net-kingdom/canon/standards/as it stabilizes - the authority context schema — what must be sayable about an agentic authority request (principal, actor, runtime identity, tenant, environment, mandate, task, operating mode), consumed by access-engine as input claims
- principal / actor / runtime-identity separation as a model
- mandates, delegation, attenuation, and authority ceilings as a model and a governance obligation
- the agentic operating modes — Assistant and Autonomous as distinct security regimes, and the requirements attaching to each
- the Change Dynamics Envelope — how much change the organization tolerates, expressed so engines and Staff can bound it
- the posture contract with King's Guard, including the asymmetry: posture may only restrict
- the MCP and tooling doctrine — tool availability is not permission
- the credential-binding contract stating that credentials are implementation artifacts of a grant, materialized by Secrets Engine after authority exists
- fail-closed semantics and the restrictive-failure rule, as properties the estate must hold
- conformance review — whether an actor's authority in practice matches its declared mandate and ceiling
- the assurance specifications
T-01…T-10, authored here and executed by whitehat-security - the security curriculum — what operators, assistants, and autonomous agents must understand before they are trusted with authority
Decision types GRANT / DENY / REQUIRE_APPROVAL / DEFER are named here
and rendered by access-engine.
Out of scope
Gate House holds no runtime position. Not owned here:
- the authorization decision, policy evaluation, or any
/authorizesurface — access-engine is NetKingdom's only policy decision point - policy engine selection, policy packages, or policy rollout
- grant storage, credential issuance, leases, or revocation
- human identity lifecycle and memberships — User Engine
- tenant and organizational boundaries — Tenant Engine
- authentication and federation — Key Cape
- credential abstraction and lifecycle orchestration — Secrets Engine
- secret storage, PKI, leases, dynamic secret engines — OpenBao
- approval storage and lifecycle — Approval Engine
- audit custody and evidence retention — Audit Core
- operational execution, access lanes, SSH certificates, tunnels, host hardening — Ops Warden
- construction, reconciliation, recovery — Ops Mason
- anomaly detection, behavioral risk inference, security memory — King's Guard
- adversarial testing and attack simulation — Whitehat Security
- the workplans of other repositories
That last one is load-bearing. Work structure belongs to the repository doing the work. Gate House sets doctrine and reviews conformance; an HQ that starts managing the estate's chores has become a second decision point wearing management clothes.
Also out of scope: inventing a new policy language, becoming an IAM suite, secret scanning, SIEM, autonomous remediation, and supporting every agent protocol.
What would put this repository out of scope
If work here starts producing services, schemas that resolve, or anything
evaluated at request time, it belongs to an engine. A decision point inside Gate
House would put the deterministic authority boundary inside the non-deterministic
management layer, violating INV-02 — the first invariant this repository
defends. See decisions/decisions.md GH-DEC-2026-001 and
history/2026-08-28-security-layer-model-and-gate-house-recut.md.
The v0.1 milestones M0–M8 and the reference implementation tree
(api/, policy/, grants/, deploy/) described the withdrawn authority-plane
design and must not be revived.