Complete KG-WP-0004-T05 and finish the architecture vocabulary sweep
Layer note is v0.7 Staff: propose containment, memory is not a state plane. §6 audit lists every decision-shaped object; none is a Staff allow/deny. Document version 0.2.0. KG-IN-0002 residual is closed. Assistant: grok Assistant-Session: 01a05ef1-9e5a-70f2-b0ff-0b05d6b38ae9
This commit is contained in:
parent
ac3aa1287e
commit
824fb1b966
6 changed files with 97 additions and 19 deletions
52
history/2026-09-02-architecture-decision-point-audit.md
Normal file
52
history/2026-09-02-architecture-decision-point-audit.md
Normal file
|
|
@ -0,0 +1,52 @@
|
|||
---
|
||||
title: "§6 audit — no Staff decision point in NetKingdomImmuneArchitecture.md"
|
||||
date: 2026-09-02
|
||||
repo: kings-guard
|
||||
author: kings-guard
|
||||
workplan: KG-WP-0004-T05
|
||||
standard: net-kingdom/canon/standards/security-layer-model_v0.7.md
|
||||
target: specs/NetKingdomImmuneArchitecture.md
|
||||
status: complete
|
||||
classification: Public
|
||||
---
|
||||
|
||||
# §6 audit — no Staff decision point
|
||||
|
||||
After T02–T04. Statute §6: `access-engine` is the only policy decision point.
|
||||
No Staff component may render or cache allow/deny. This list is every
|
||||
decision-shaped object from the T01 inventory §2.1, plus the §8/§9.6
|
||||
artifacts T02 introduced, and where each now lives.
|
||||
|
||||
| Object | Lives now | Staff renders allow/deny? |
|
||||
| --- | --- | --- |
|
||||
| §5 lymph node / adaptive "decision" | Staff judgment / posture; policy generation is doctrine + PDP package | no |
|
||||
| §8 former "Decision and Response Engine" | `access-engine` box in the Engine subgraph | no |
|
||||
| §8 former Regulation controller | split: Staff proposals vs PDP/PEP | no |
|
||||
| §9.2 `trust_posture` + `valid_until` | Staff publication; lifetime is an input claim to the PDP | no |
|
||||
| §9.4 observation `assessment` / `proposed_response` | removed from the observation; phenotype/posture/signal | no |
|
||||
| §9.5 `response authorization` signal | gone as a Staff type; PDP decision record | no |
|
||||
| §9.6 `immune_decision` | Engine artifact, `pdp: access-engine` | no |
|
||||
| §9.6 former `authority: tenant-immune-node` | `authority: access-engine`, `enforcement: pep` | no |
|
||||
| §10 `TN → TR` | coordination; effectors fire on a decision record or recorded stance | no |
|
||||
| §10.1 "local response decisions" | rewritten to proposals; decisions stay the one PDP | no |
|
||||
| §14.1 fast local loop | PEP under existing policy / stance (qonto-assistant) | no — PEP, not Staff |
|
||||
| §14.2 "select bounded response" | emit a bounded proposal | no |
|
||||
| §15 VSM System 3 | `access-engine` + PEP stance maps | no |
|
||||
| §16 isolate grant | issued to a PEP by `access-engine`, not to a Staff node | no |
|
||||
| §19 `DECISION` entity | `access-engine` only; posture/signal sit in front | no |
|
||||
| §20.2 policy decision reconstructability | PDP obligation | no |
|
||||
| §22.2 decision latency | labelled PDP; Staff has judgment latency | no |
|
||||
| §24 `immune-decision/` | replaced by `immune-judgment/` (Staff) | no |
|
||||
| §25.1 Decision Contract | owned by `access-engine` | no |
|
||||
| §25.2 `effector_request` | Staff proposal with origin; not a verdict | no |
|
||||
| §27 former two-hop authorize | posture claim → PDP → PEP | no |
|
||||
| §31 Phase 4 policy evaluation | recommendations; evaluation remains `access-engine` | no |
|
||||
| §33 AD-003 | observe → judge → propose; decide/act are Engine/PEP | no |
|
||||
| §34 Q2 autonomous authorization | recast as proposals + existing PEP stances | no |
|
||||
| §36 sequence | names proposal, decision, unowned actuation | no |
|
||||
|
||||
No remaining object is a Staff allow/deny. Caching a verdict is not described
|
||||
as a kings-guard behaviour. Actuation remains unowned (§9.2).
|
||||
|
||||
Control-plane grep after T03+T05: remaining hits are labelled Kubernetes /
|
||||
platform API planes, or an explicit denial that kings-guard is not one.
|
||||
Loading…
Add table
Add a link
Reference in a new issue