Adaptive immune security architecture for netkingdom
Find a file
tegwick 4b37bb18a5 Commentary: the posture/maturity boundary is recomputability (KG-IN-0003)
gate-house asked kings-guard to check the posture/maturity boundary,
with the concern that a second grading authority would be the same shape
of mistake as a second decision point. Its proposed line was volatile
current state against slow progression.

Answered with a proposed revision, KG-DEC-2026-002, argued in
docs/PostureMaturityBoundary.md (KG-COM-0001).

Volatility is an observation about data, not a definition. It fails at
both edges and, more importantly, describes the two things without
partitioning them — every case left to argument is a route by which a
second grading authority arrives.

The discriminator is already in the statute. §9.5 requires maturity to
return the same level from the same criteria and evidence and calls that
determinism the thing that makes it an Engine; §3.3 makes inference Staff
by construction. So: recompute against the same criteria and evidence —
must get the same answer, it is maturity and belongs in an engine; cannot
promise the same answer, it is posture and belongs in Staff.

It is one rule read from both sides. §9.5 already says a criterion that
cannot be evaluated by rule is not yet a criterion; the mirror is that a
judgment that can be evaluated by rule is not posture but a criterion in
the wrong repository.

kings-guard accepts the constraint this puts on its own side: capability
readiness is not an input to posture, since feeding a deterministic value
into a non-deterministic one would blur the boundary from our door. That
also answers the incident-dependency half of the intake.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014379@bnt-lap001
Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
2026-08-29 17:44:24 +02:00
.repo-manager Repoint at Security Layer Model v0.4; assess and report to gate-house 2026-08-29 02:41:43 +02:00
decisions Commentary: the posture/maturity boundary is recomputability (KG-IN-0003) 2026-08-29 17:44:24 +02:00
docs Commentary: the posture/maturity boundary is recomputability (KG-IN-0003) 2026-08-29 17:44:24 +02:00
history Align with Security Layer Model v0.7; review scope vs intent; open KG-WP-0003 2026-08-29 14:42:34 +02:00
intake Close absorbed qonto pilot intake 2026-07-24 00:34:52 +02:00
intakes Commentary: the posture/maturity boundary is recomputability (KG-IN-0003) 2026-08-29 17:44:24 +02:00
scripts Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
specs Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
src/kings_guard Implement KG-WP-0002 posture pilot scaffold 2026-07-24 00:24:53 +02:00
tests Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
workplans chore(registrar): assign State Hub identifiers 2026-08-29 14:45:30 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-29 14:45:27 +02:00
.gitignore Implement KG-WP-0002 posture pilot scaffold 2026-07-24 00:24:53 +02:00
.repo-classification.yaml Register kings-guard with State Hub 2026-07-23 22:55:42 +02:00
AGENTS.md Assent to Staff placement; release control-plane vocabulary (KG-IN-0001) 2026-08-28 21:47:05 +02:00
INTENT.md Align with Security Layer Model v0.7; review scope vs intent; open KG-WP-0003 2026-08-29 14:42:34 +02:00
layer.yaml Align with Security Layer Model v0.7; review scope vs intent; open KG-WP-0003 2026-08-29 14:42:34 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:28:01 +02:00
Makefile Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
pyproject.toml Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
README.md Assent to Staff placement; release control-plane vocabulary (KG-IN-0001) 2026-08-28 21:47:05 +02:00
SCOPE.md Align with Security Layer Model v0.7; review scope vs intent; open KG-WP-0003 2026-08-29 14:42:34 +02:00
WORK-RECORDS.md chore(registrar): assign State Hub identifiers 2026-08-29 14:45:30 +02:00

kings-guard

Adaptive security contracts and posture-evaluation scaffold for NetKingdom's immune-architecture work.

Layer: Staff (NetKingdom Security Layer Model v0.1). kings-guard publishes posture and requests bounded response through engine APIs; it never touches Tooling directly and never renders an authorization decision.

Current slice

This repository now contains four aligned pieces:

  • INTENT.md / SCOPE.md for the repo's stable boundary
  • specs/NetKingdomImmuneArchitecture.md for the reference architecture
  • specs/ImmuneContracts.md for the first canonical contract layer
  • src/kings_guard/ plus tests/ for a minimal posture loop scaffold

The current implementation is intentionally narrow. It does not enforce anything. It provides:

  • typed contracts for security genome, phenotype, observation, posture, signal, effector request, and immune memory entry;
  • a minimal posture evaluator that turns a normalized observation into a posture assessment and bounded response hints;
  • a fixture-driven pilot based on qonto-assistant, chosen because it already exposes a security genome record, an audit stream, and a fast local loop.

Repo layout

  • specs/NetKingdomImmuneArchitecture.md
  • specs/ImmuneContracts.md
  • docs/AdjacentSystemBoundary.md
  • docs/pilots/QontoAssistantPosturePilot.md
  • src/kings_guard/
  • tests/
  • workplans/

Dev commands

# preferred, if make + pip are available
make install-dev
make test
make lint
make run-demo

# direct shell fallback used in minimal environments
python3 -m pytest -q
PYTHONPATH=src python3 -m kings_guard.main --pilot qonto-assistant