Finish KG-WP-0003: stream completeness and live qonto observation

Classify evidence as load-bearing or attributive, draft the emission-cadence
declaration for Taxonomy, treat silence as a stream finding, keep completeness
separate from record richness, forbid immune memory as a state plane, and make
containment proposals reconstructable to their origin. Observe real
qonto-assistant audit events; deny-class completeness stays unknown until the
source publishes a heartbeat.

Assistant: grok
Assistant-Session: 01a05ef1-9e5a-70f2-b0ff-0b05d6b38ae9
This commit is contained in:
tegwick 2026-09-02 00:11:57 +02:00
parent c85646dc3c
commit 9daea96c43
35 changed files with 2023 additions and 138 deletions

View file

@ -37,6 +37,15 @@ The following rules apply to every integration below:
the lane stays fixture-driven and the gap is declared in `INTENT.md`.
6. `kings-guard` never renders or caches an authorization decision.
`access-engine` is the estate's only decision point (layer model §6).
7. Every containment **proposal** carries the originating observation and
signal identity, the stream-completeness state, and a restrictive
direction. It does not carry credentials, secret values, or a direct
actuation instruction. The receiving Engine (today: `access-engine` as
decision point; actuation still unowned) MUST retain those origin
references on the eventual decision record so a containment action is
reconstructable as a decision, not a side channel (statute §9.2;
`gate-house/docs/contracts/posture-findings-return.md`). Origin linkage
does not widen authority.
## 3. System-by-System Boundary
@ -97,4 +106,7 @@ Mechanically checkable, per layer model §10:
no OpenBao client, no Kubernetes client;
- every `EffectorRequest` carries an explicit `authority_boundary`, and the
values in use are `advisory_only` and `metadata_only`;
- every `EffectorRequest` also carries `originating_observation_id` and
`originating_signal_id` so a later decision record can name what was
proposed and against which observation;
- no module exposes an authorization decision surface.

View file

@ -73,6 +73,7 @@ client request
| `deny_reason` | `deny_reason` | Pilot currently exercises `credential_exfil` |
| derived constant | `identity_binding` | `self_asserted` until key-cape integration lands |
| derived constant | `egress_destination` | `qonto-thirdparty-api` for this pilot |
| genome `evidence_sources` | `evidence_class` / `event_class` | Copied from the source declaration. `audit.deny` is load-bearing; `audit.allow` is attributive. Not inferred from `decision`. |
## 6. Output Shape