diff --git a/intakes/intakes.md b/intakes/intakes.md index 7d1586b..9f00364 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -69,3 +69,38 @@ created: '2026-08-28' updated: '2026-08-28' state_hub_intake_id: "01a049ea-3a04-74b9-a9b1-e2630f8d5628" ``` + +## KG-IN-0003 — Review requested: security layer model v0.3 (maturity-engine, and the posture/maturity boundary) + +```yaml +id: KG-IN-0003 +kind: intake +title: 'Review requested: security layer model v0.3 (maturity-engine, and the posture/maturity + boundary)' +status: open +origin: cross-repo +origin_ref: net-kingdom security-layer-model_v0.3 +priority: medium +owner: kings-guard +requested_by: gate-house +description: 'v0.3 is proposed and changes sections 4, 9 and 13 only; the v0.2 assent + record stands. It responds directly to KG-DEC-2026-001. Section 9.5 assigns graded + progression to a new maturity-engine, which now owns the gap register with intended_owner, + blocked_on and review dates, and capability readiness — so your three declared engine + gaps and the pending containment claim become queryable facts rather than footnotes + in a standard. Your finding also produced 9.1 in v0.2, and v0.3 applies it to gate-house + itself: gate-house was catalogued as owning conformance review with no engine to + act through, exactly the defect you named for containment, and it now acts through + maturity-engine. THE QUESTION FOR YOU is a boundary we have not drawn: posture and + maturity are both graded, and we do not want two engines grading the same subject. + Our reading is that posture is volatile current security state about an actor, published + by kings-guard and rendered by access-engine, while maturity is slow progression + of a capability against declared criteria. If that line is wrong, or if maturity-engine + would absorb something you consider posture, say so now — a second grading authority + would be the same shape of mistake as a second decision point. Also worth your view: + does capability readiness for containment belong in maturity-engine, or does tracking + your own gaps there create a dependency you would rather not carry during an incident? + Assent, revision, or rejection acceptable.' +created: '2026-08-28T20:40:12.260389Z' +updated: '2026-08-28T20:40:12.260389Z' +```