34 lines
1.7 KiB
Markdown
34 lines
1.7 KiB
Markdown
|
|
# Intake records
|
||
|
|
|
||
|
|
## KG-IN-0001 — Assent requested: Staff layer placement, control-plane vocabulary, and the posture asymmetry
|
||
|
|
|
||
|
|
```yaml
|
||
|
|
id: KG-IN-0001
|
||
|
|
kind: intake
|
||
|
|
title: 'Assent requested: Staff layer placement, control-plane vocabulary, and the
|
||
|
|
posture asymmetry'
|
||
|
|
status: open
|
||
|
|
origin: cross-repo
|
||
|
|
origin_ref: gate-house GH-DEC-2026-001
|
||
|
|
priority: medium
|
||
|
|
owner: kings-guard
|
||
|
|
requested_by: gate-house
|
||
|
|
standard: net-kingdom/canon/standards/security-layer-model_v0.1.md
|
||
|
|
description: 'gate-house asks kings-guard to assent to its placement in the NetKingdom
|
||
|
|
security layer model. (1) kings-guard is Staff — agentic and non-deterministic —
|
||
|
|
not an Engine. Acting at runtime does not make a repository an Engine; being agentic
|
||
|
|
makes it Staff. (2) Consequently its self-description as an adaptive security control
|
||
|
|
plane needs revisiting: control plane is Engine-layer vocabulary (standard section
|
||
|
|
8). This is not a demotion — it is the reason kings-guard may contain a threat only
|
||
|
|
by calling an engine, never by reaching into OpenBao or a cluster directly (the
|
||
|
|
binding rule, standard section 5: Staff never touches Tooling directly). (3) The
|
||
|
|
posture contract with gate-house and its asymmetry: adaptive systems may reduce
|
||
|
|
authority, require step-up, or request containment; they must never probabilistically
|
||
|
|
manufacture additional authority. kings-guard publishes posture, gate-house defines
|
||
|
|
its authority meaning, access-engine renders it. If the binding rule is impractical
|
||
|
|
for containment in a real incident, say so — that is exactly the kind of finding
|
||
|
|
that should change the doctrine rather than be worked around.'
|
||
|
|
created: '2026-08-28T19:30:17.201213Z'
|
||
|
|
updated: '2026-08-28T19:30:17.201213Z'
|
||
|
|
```
|