143 lines
6.4 KiB
Markdown
143 lines
6.4 KiB
Markdown
|
|
---
|
||
|
|
title: "Commentary — the posture/maturity boundary"
|
||
|
|
document_id: KG-COM-0001
|
||
|
|
version: 1.0.0
|
||
|
|
status: Published
|
||
|
|
date: 2026-08-29
|
||
|
|
repo: kings-guard
|
||
|
|
kind: commentary
|
||
|
|
commentary_on: net-kingdom/canon/standards/security-layer-model_v0.7.md
|
||
|
|
sections: ["8", "9.5", "3.3"]
|
||
|
|
answers: KG-IN-0003
|
||
|
|
classification: Public
|
||
|
|
---
|
||
|
|
|
||
|
|
# Commentary — the posture/maturity boundary
|
||
|
|
|
||
|
|
A commentary, not a proposed edit. `gate-house` owns the rules (statute §2);
|
||
|
|
this is `kings-guard`'s reading of a boundary it asked us to check, offered in
|
||
|
|
the form the conformance loop expects. Adopt, revise, or reject.
|
||
|
|
|
||
|
|
## The question
|
||
|
|
|
||
|
|
`KG-IN-0003` asks us to check a line `gate-house` had not drawn:
|
||
|
|
|
||
|
|
> posture is volatile current security state about an actor, published by
|
||
|
|
> kings-guard and rendered by access-engine, while maturity is slow progression
|
||
|
|
> of a capability against declared criteria
|
||
|
|
|
||
|
|
with the concern stated plainly: *a second grading authority would be the same
|
||
|
|
shape of mistake as a second decision point.*
|
||
|
|
|
||
|
|
That concern is correct and it is the reason the line has to be exact.
|
||
|
|
|
||
|
|
## The line is nearly right and drawn on the wrong axis
|
||
|
|
|
||
|
|
Volatility is the wrong discriminator. Rate of change is an observation about
|
||
|
|
the data, not a definition of it, and it fails at both edges: a maturity
|
||
|
|
criterion can move quickly when evidence lands in a burst, and a posture can sit
|
||
|
|
unchanged for months on a subject that stays healthy. A boundary that has to
|
||
|
|
hold under §6 cannot rest on how fast a value happens to move, because nothing
|
||
|
|
prevents the value from moving at a different speed tomorrow.
|
||
|
|
|
||
|
|
Worse, "volatile versus slow" describes the two things without partitioning
|
||
|
|
them. Every case it does not obviously cover is an argument, and arguments at a
|
||
|
|
boundary are how a second grading authority arrives — gradually, and each time
|
||
|
|
for a good local reason.
|
||
|
|
|
||
|
|
## The line the statute already draws
|
||
|
|
|
||
|
|
The discriminator is in §9.5 and does not need to be invented:
|
||
|
|
|
||
|
|
> Given the same criteria and the same evidence it MUST return the same level;
|
||
|
|
> that determinism is what makes it an Engine rather than an opinion.
|
||
|
|
|
||
|
|
And in §3.3, generally:
|
||
|
|
|
||
|
|
> A repository whose core function is inference or judgment fails this test by
|
||
|
|
> construction and is Staff, however much of its work happens at runtime.
|
||
|
|
|
||
|
|
So the test is **recomputability**:
|
||
|
|
|
||
|
|
> Given the same criteria and the same evidence, recompute. If you must get the
|
||
|
|
> same answer, it is **maturity** and it belongs in an engine. If you cannot
|
||
|
|
> promise the same answer, it is **posture** and it belongs in Staff.
|
||
|
|
|
||
|
|
This is the statute's own organizing principle — determinism — applied to the
|
||
|
|
one boundary where it had not yet been used. It is not a new rule. It is the
|
||
|
|
existing rule read at a place it had not been pointed.
|
||
|
|
|
||
|
|
## It is one rule read from opposite sides
|
||
|
|
|
||
|
|
§9.5 already states the maturity half: *a criterion that cannot be evaluated by
|
||
|
|
rule is not yet a criterion.* That is maturity refusing to absorb inference.
|
||
|
|
|
||
|
|
The posture half is its mirror, and stating it completes the pair: **a judgment
|
||
|
|
that can be evaluated by rule is not posture — it is a criterion sitting in the
|
||
|
|
wrong repository.**
|
||
|
|
|
||
|
|
Together they partition rather than describe. There is no case the pair leaves
|
||
|
|
to argument, which is exactly what "volatile versus slow" cannot offer.
|
||
|
|
|
||
|
|
## Three consequences
|
||
|
|
|
||
|
|
**1. The migration direction is defined, permanently.** Anything currently
|
||
|
|
called posture that turns out to be recomputable should move to
|
||
|
|
`maturity-engine` as a criterion. Anything in `maturity-engine` that needs
|
||
|
|
judgment is not yet a criterion and moves back to Staff. The boundary maintains
|
||
|
|
itself under change instead of needing to be re-adjudicated, because the test is
|
||
|
|
mechanical and applies to each item rather than to the category.
|
||
|
|
|
||
|
|
**2. The second-grading-authority failure is structurally prevented, not
|
||
|
|
conventionally avoided.** `gate-house`'s worry is answered by the shape of the
|
||
|
|
test rather than by both parties agreeing to stay on their own side. Two
|
||
|
|
authorities cannot grade the same subject on this line, because a single subject
|
||
|
|
property is either recomputable or it is not, and that fact is not a matter of
|
||
|
|
which repository claims it.
|
||
|
|
|
||
|
|
**3. Capability readiness must not be an input to posture.** This is the
|
||
|
|
constraint the test imposes on *us*, and we accept it. Readiness is
|
||
|
|
deterministic; posture is not. If readiness fed posture, posture would become
|
||
|
|
partly recomputable and the boundary would blur from the kings-guard side — the
|
||
|
|
same failure, arriving through the door we own.
|
||
|
|
|
||
|
|
This also answers the second half of `KG-IN-0003`. Tracking our gaps in
|
||
|
|
`maturity-engine` creates no dependency we would rather not carry during an
|
||
|
|
incident, because we never consult our own readiness to judge an observation. If
|
||
|
|
`maturity-engine` is unreachable mid-incident, nothing about posture evaluation
|
||
|
|
changes. The dependency would only exist if we had already made the mistake this
|
||
|
|
consequence forbids.
|
||
|
|
|
||
|
|
## A caution about the word
|
||
|
|
|
||
|
|
`posture` has the drift profile that `control plane` had: it sounds specific,
|
||
|
|
and it quietly absorbs whatever sits next to it. That is how this repository
|
||
|
|
came to describe itself as a control plane in the first place, and §8 exists
|
||
|
|
because the estate has been bitten by exactly this.
|
||
|
|
|
||
|
|
The recomputability test is a defence against that drift, because it is
|
||
|
|
mechanical and can be applied to a candidate before the word is stretched to
|
||
|
|
cover it. We would rather be held to it than trusted about it.
|
||
|
|
|
||
|
|
## What this commentary does not claim
|
||
|
|
|
||
|
|
- It does not touch §8's three-way split. `kings-guard` publishes posture,
|
||
|
|
`gate-house` defines its authority meaning, `access-engine` renders it. That
|
||
|
|
division is unaffected and we are not asking to widen our half.
|
||
|
|
- It does not make posture an engine concept. Posture stays non-deterministic
|
||
|
|
and stays Staff. The test explains *why*, which is what was missing.
|
||
|
|
- It proposes no §4 catalog change.
|
||
|
|
|
||
|
|
## An honest limit
|
||
|
|
|
||
|
|
The test says "the same evidence", and that phrase is not yet well defined
|
||
|
|
anywhere in the estate. Until §17's request-claim and gap-record schemas exist,
|
||
|
|
two parties can disagree about whether they hold the same evidence, and
|
||
|
|
recomputability is a thought experiment rather than a check.
|
||
|
|
|
||
|
|
That is a real limit and it is not an argument against the line — a boundary
|
||
|
|
that is correct but not yet mechanically checkable is still better than one that
|
||
|
|
is checkable and wrong. It does mean §17 is load-bearing for this commentary,
|
||
|
|
and `kings-guard` has the emission-cadence half of that work under
|
||
|
|
`KG-WP-0003-T02`.
|