info-tech-canon/infospace
tegwick 30cf417a18
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Generalise the CARING section 32 role set (R-2, INFO-DEC-2026-001)
The role set — Principal, effective actor, Delegator, tool or agent, policy
ceiling, execution context, audit identity — now applies wherever a subject's
access is exercised through another party, rather than to non-human subjects
only.

The gap this closes is not about agents. A support operator impersonating a
customer involves no non-human subject anywhere in the path, yet without the
decomposition that operator's audit identity and policy ceiling collapse into
the customer's, which is the outcome CARING's exposure analysis exists to
prevent. CARING already names customer impersonation as an exposure mode and
ImpersonationBlocked as a control; the vocabulary for analysing it was gated to
subjects the case does not involve. Section 33 was already subject-agnostic, so
the canon applied the execution paths to any subject while restricting the roles
along those paths to non-human ones — an artifact of the section heading, not a
considered position.

Accepted narrowly. Section 32.1 stays agent-stated, with a note on reading the
capability ceiling for a human effective actor. No role is removed, renamed or
added, and section 33 is untouched. Option C, a twelfth dimension, is rejected as
duplicating sections 32 and 33 while touching a dimension set the Kubernetes RBAC
benchmark depends on.

Canon version moves to 0.4.0-RC2-itc2; source version stays 0.4.0-RC2, since
this revises the InfoTechCanon-aligned standard and claims nothing about
upstream CARING. The change is additive: an implementation that applied the set
only to non-human subjects stays conformant for those subjects.

Review record in history/; the SecurityCanon boundary file and placement record
are updated to show R-2 resolved.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3588@bnt-lap001
Assistant-Session: 24b80f66-e5a7-4e61-99fe-2d422e6d17da
2026-09-20 23:55:11 +02:00
..
agent Check import manifests by hash and name together (INFO-WP-0028 T01-T03) 2026-09-20 23:43:34 +02:00
artifacts Publish reciprocal canon federation interface 2026-09-06 01:00:12 +02:00
assimilation Distribute frozen federation corpus by concept destination 2026-09-06 00:44:37 +02:00
concepts Register limited Family concept-area seed 2026-09-06 00:26:29 +02:00
evaluations ITC-WP-0012: integrate Repository Layout Standard 2026-06-13 14:25:54 +02:00
examples Add purpose and demand model extension 2026-05-23 04:59:16 +02:00
indexes Check import manifests by hash and name together (INFO-WP-0028 T01-T03) 2026-09-20 23:43:34 +02:00
interfaces Generalise the CARING section 32 role set (R-2, INFO-DEC-2026-001) 2026-09-20 23:55:11 +02:00
kernel Declare concepts and review boundaries for the silent artifacts (T02) 2026-09-20 23:19:22 +02:00
mappings Canon 0.6.0 freeze: ITC-CAP draft, AVT catalog, joinable review 2026-08-15 19:42:30 +02:00
models Close the last open import pins and the workplan (T04) 2026-09-20 23:50:52 +02:00
patterns feat(ITC-WP-0017): establish AgenticDrivesFunctional pattern 2026-08-22 18:54:01 +02:00
profiles Implement canon conformance and maintenance optimizations 2026-09-05 00:50:09 +02:00
reports Add small SaaS profile proof 2026-05-23 04:26:28 +02:00
schemas Implement canon conformance and maintenance optimizations 2026-09-05 00:50:09 +02:00
standards Generalise the CARING section 32 role set (R-2, INFO-DEC-2026-001) 2026-09-20 23:55:11 +02:00
validation Introduce identity model and reconcile upstream imports 2026-09-05 22:11:46 +02:00
views Check import manifests by hash and name together (INFO-WP-0028 T01-T03) 2026-09-20 23:43:34 +02:00
infospace.yaml Introduce identity model and reconcile upstream imports 2026-09-05 22:11:46 +02:00
README.md Implement infospace scaffold and service baseline 2026-05-23 03:12:02 +02:00

InfoTechCanon Infospace

This directory is the single concrete infospace implemented by this repository. The repository root remains the service, governance, and workplan shell.

The current placement pass copies the seed documents into canonical kernel/, models/, and standards/ paths while keeping seeds/ as provenance until the scaffold migration is reviewed.