info-tech-canon/infospace/models/security/boundary-review.md
tegwick f7b17b83f2
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Declare concepts and review boundaries for the silent artifacts (T02)
Twelve of the thirteen artifacts that declared nothing now declare what they
define, together with the map-assigned concepts the Organization Model was
missing and the Landscape seed concepts the extractor cannot see because they
are listed rather than defined in prose. The ownership index grows from 164
entries to 750, undeclared prose definitions fall from 637 to 57, and there are
no ownership conflicts. The 57 that remain are overlaps this round assigned to
another owner: imports, each recorded in a boundary review.

The kernel map declares nothing, deliberately, because it assigns concepts to
owners rather than defining them. It is now the only silent artifact and the
suite asserts that, so an artifact added without declarations fails.

itc-org:Authority is declared, with Actor, Ownership, Membership, Role,
Responsibility and Accountability, which SecurityCanon and the identity model
already treat as organization-owned. The regression test that previously
asserted the blind spot now asserts that the kernel map's assignment and the
declaration agree.

Profile is deliberately left undeclared. The kernel map assigns it to Core, the
identity model owns it under accepted CUST-ADR-006, and Observability defines a
runtime performance profile. Three senses need a decision, not a declaration, so
it is recorded as open rather than forced.

Eleven boundary reviews are added beside the artifacts they describe, in the
shape the identity model has used since INFO-WP-0021. The largest finding is
that Core and the Information Space model restate eight provenance concepts in
nearly identical words; Core owns them and Information Space imports. Label,
Drift, Summary and Attribute are resolved by disambiguation rather than
transfer.

make check passes with 50 tests, clean validation, no stale generated assets.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3588@bnt-lap001
Assistant-Session: 24b80f66-e5a7-4e61-99fe-2d422e6d17da
2026-09-20 23:19:22 +02:00

16 lines
1.1 KiB
Markdown

# InfoTechCanon Security Model concept boundary review — 2026-09-20
Authority: INFO-WP-0027-T02, the declaration round that gave this artifact an
`owned_concepts` list. Resolutions cite the kernel map concept-owner table where
it assigns an owner, and are decided in this review where it does not. No concept
is renamed, moved or removed.
| Concept | Owner | Resolution | Decided by |
| --- | --- | --- | --- |
| `Alert` | model/observability | Assigned by the kernel map concept-owner table. | kernel map |
| `Exposure` | model/security | Security owns Exposure; it is one of the model purpose entities alongside threat, weakness and vulnerability. Network describes reachability that produces exposure and imports. | this review |
| `Investigation` | model/security | Security owns Investigation as part of response. The Observability sense is analysis activity over telemetry and imports. | this review |
Concepts this artifact declares are listed in its frontmatter. An overlap recorded
here means another artifact defines the same name; where the owner is another
artifact, this one imports the definition rather than restating it.