Assent to Staff placement; release control-plane vocabulary (KG-IN-0001)

Answers gate-house intake KG-IN-0001 / GH-DEC-2026-001 against the
NetKingdom Security Layer Model v0.1.

Assent to all three points, recorded as KG-DEC-2026-001:
- kings-guard declares layer Staff in INTENT.md;
- "control plane" released to the Engine layer across INTENT, SCOPE,
  README, AGENTS and the adjacent-system boundary;
- the posture asymmetry adopted as a repo invariant — already satisfied,
  every EffectorRequest carries an explicit authority_boundary.

Boundary corrections: key-cape and OpenBao are Tooling, so their evidence
is routed through user-engine/access-engine and secrets-engine rather
than read directly.

Finding on the invited challenge to §5: do not weaken the binding rule,
but §4 catalogs kings-guard as owning containment while no engine exposes
a containment surface — the charter is currently undischargeable. Two
rulings requested of gate-house. Three engine gaps declared in INTENT.md.

Residual handed off as KG-IN-0002 (vocabulary sweep of the architecture
spec).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014379@bnt-lap001
Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
This commit is contained in:
tegwick 2026-08-28 21:47:05 +02:00
parent f78bca1586
commit 3d6025ae51
9 changed files with 457 additions and 31 deletions

View file

@ -14,6 +14,16 @@ classification: Public
# NetKingdom Immune Architecture
> **Layer note (2026-08-28).** kings-guard is a **Staff**-layer repository
> under the NetKingdom Security Layer Model v0.1 (assented in
> `decisions/decisions.md` KG-DEC-2026-001). Where this document uses "control
> plane", read it as naming an **estate-wide, Engine-layer** arrangement of
> deterministic authorities — never as a self-description of `kings-guard`,
> which publishes posture and requests bounded response through engine APIs.
> The parts of this architecture that render decisions or hold state belong to
> engines; kings-guard owns observation, judgment, and the request. A full
> vocabulary sweep of this document is tracked as intake KG-IN-0002.
## 1. Purpose
This document defines the reference architecture for **Kings Guard Security**, implemented in the `kings-guard` repository and positioned within the wider **NetKingdom** ecosystem.