Finish KG-WP-0003: stream completeness and live qonto observation

Classify evidence as load-bearing or attributive, draft the emission-cadence
declaration for Taxonomy, treat silence as a stream finding, keep completeness
separate from record richness, forbid immune memory as a state plane, and make
containment proposals reconstructable to their origin. Observe real
qonto-assistant audit events; deny-class completeness stays unknown until the
source publishes a heartbeat.

Assistant: grok
Assistant-Session: 01a05ef1-9e5a-70f2-b0ff-0b05d6b38ae9
This commit is contained in:
tegwick 2026-09-02 00:11:57 +02:00
parent c85646dc3c
commit 9daea96c43
35 changed files with 2023 additions and 138 deletions

View file

@ -21,10 +21,12 @@ anything. It provides:
- typed contracts for security genome, phenotype, observation, posture,
signal, effector request, and immune memory entry;
- a minimal posture evaluator that turns a normalized observation into a
posture assessment and bounded response hints;
- a fixture-driven pilot based on `qonto-assistant`, chosen because it already
exposes a security genome record, an audit stream, and a fast local loop.
- evidence-class and stream-completeness fields, so silence is a finding and
record richness is not mistaken for a complete stream;
- a posture evaluator that judges one observation and, separately, the stream
it came from;
- a `qonto-assistant` pilot that still has a fixture regression case and can
also consume real events from that service's own AuditLogger.
## Repo layout