info-tech-canon/infospace/agent/briefs/model-network.md
tegwick f7b17b83f2
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Declare concepts and review boundaries for the silent artifacts (T02)
Twelve of the thirteen artifacts that declared nothing now declare what they
define, together with the map-assigned concepts the Organization Model was
missing and the Landscape seed concepts the extractor cannot see because they
are listed rather than defined in prose. The ownership index grows from 164
entries to 750, undeclared prose definitions fall from 637 to 57, and there are
no ownership conflicts. The 57 that remain are overlaps this round assigned to
another owner: imports, each recorded in a boundary review.

The kernel map declares nothing, deliberately, because it assigns concepts to
owners rather than defining them. It is now the only silent artifact and the
suite asserts that, so an artifact added without declarations fails.

itc-org:Authority is declared, with Actor, Ownership, Membership, Role,
Responsibility and Accountability, which SecurityCanon and the identity model
already treat as organization-owned. The regression test that previously
asserted the blind spot now asserts that the kernel map's assignment and the
declaration agree.

Profile is deliberately left undeclared. The kernel map assigns it to Core, the
identity model owns it under accepted CUST-ADR-006, and Observability defines a
runtime performance profile. Three senses need a decision, not a declaration, so
it is recorded as open rather than forced.

Eleven boundary reviews are added beside the artifacts they describe, in the
shape the identity model has used since INFO-WP-0021. The largest finding is
that Core and the Information Space model restate eight provenance concepts in
nearly identical words; Core owns them and Information Space imports. Label,
Drift, Summary and Attribute are resolved by disambiguation rather than
transfer.

make check passes with 50 tests, clean validation, no stale generated assets.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3588@bnt-lap001
Assistant-Session: 24b80f66-e5a7-4e61-99fe-2d422e6d17da
2026-09-20 23:19:22 +02:00

107 lines
2 KiB
Markdown

---
id: agent-brief/model-network
artifact_id: model/network
source_path: models/network/InfoTechCanonNetworkModel.md
source_kind: model
generated: true
---
<!-- GENERATED by info_tech_canon; do not edit by hand. -->
# Agent Brief: InfoTechCanon Network Model
- Artifact ID: `model/network`
- Kind: `model`
- Canonical path: `models/network/InfoTechCanonNetworkModel.md`
- Full source: `models/network/InfoTechCanonNetworkModel.md`
- Summary: Domain model used by canon profiles and standards: InfoTechCanon Network Model.
## Retrieval Hints
Imports and anchors:
- `kernel/itc-core`
- `model/evidence`
- `model/security`
## Owned Concepts
- `ACL`
- `AddressFamily`
- `AllowedFlow`
- `AppliedNetworkState`
- `AssessedNetworkState`
- `AttackSurfaceReference`
- `Circuit`
- `ConnectivityService`
- `DNSRecord`
- `DNSZone`
- `DeclaredNetworkState`
- `DeniedFlow`
- `EgressEndpoint`
- `Endpoint`
- `Firewall`
- `FirewallRule`
- `Gateway`
- `HistoricalNetworkState`
- `Hostname`
- `IPAddress`
- `IPAllocation`
- `InfoTechCanon Network Model`
- `IngressEndpoint`
- `IntendedNetworkState`
- `Interface`
- `KubernetesNetworkPolicy`
- `LoadBalancer`
- `ManagementEndpoint`
- `Microsegment`
- `NAT`
- `NetworkACL`
- `NetworkConfiguration`
- `NetworkDevice`
- `NetworkDomain`
- `NetworkEntity`
- `NetworkFabric`
- `NetworkFlow`
- `NetworkIntent`
- `NetworkNode`
- `NetworkPolicy`
- `NetworkRegion`
- `NetworkSegment`
- `NetworkSite`
- `NetworkTenant`
- `NetworkZone`
- `NextHop`
- `ObservedFlow`
- `ObservedNetworkState`
- `OverlayNetwork`
- `Path`
- `Peering`
- `Port`
- `Prefix`
- `PrivateEndpoint`
- `Proxy`
- `PublicEndpoint`
- `ReachabilityClaim`
- `ReachabilityTest`
- `ReconciliationResult`
- `Route`
- `RouteTable`
- `Router`
- `SecurityGroup`
- `SecurityZone`
- `ServiceEndpoint`
- `ServiceMeshPolicy`
- `ServiceName`
- `Subnet`
- `Switch`
- `TerminationPoint`
- `TrafficPolicy`
- `TrustZoneReference`
- `UnderlayNetwork`
- `VLAN`
- `VRF`
- `WorkloadEndpoint`
## Related Distinctions
No common distinction is anchored directly on this artifact.