The standard moved v0.1 -> v0.4 after our assent. Reviewed; assent stands
unchanged. §9.1/§9.2/§9.3 adopt the KG-DEC-2026-001 finding and generalise
it estate-wide, and §12 now states that an unsatisfiability finding is a
success of the conformance loop.
Docs repointed at v0.4 (INTENT, SCOPE, AdjacentSystemBoundary, the
architecture spec note). KG-DEC-2026-001 still cites v0.1 deliberately —
it records what was assented to at the time.
INTENT gap table reshaped to §5.3's field names (capability,
intended_owner, blocked_on, review) so one register can hold both kinds,
with review dates set to 2026-11-28, and marked explicitly as unowned
capabilities rather than §5.3 declared contacts — kings-guard makes no
Tooling contact and is Conforming under §11.
Four findings sent to gate-house: §9.1 not carried through to the
observation claim; §13 conflating declared contacts with unowned
capabilities ahead of the maturity-engine migration; §9.6's unstated
consequence for posture (suppression biases posture optimistic and our
confidence score cannot express the doubt); and disclosure that §12's
fourth step is unstaffed while the pilot remains fixture-only.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014379@bnt-lap001
Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
Regenerated by fix-consistency; adds the inbound v0.3 review intake.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Answers gate-house intake KG-IN-0001 / GH-DEC-2026-001 against the
NetKingdom Security Layer Model v0.1.
Assent to all three points, recorded as KG-DEC-2026-001:
- kings-guard declares layer Staff in INTENT.md;
- "control plane" released to the Engine layer across INTENT, SCOPE,
README, AGENTS and the adjacent-system boundary;
- the posture asymmetry adopted as a repo invariant — already satisfied,
every EffectorRequest carries an explicit authority_boundary.
Boundary corrections: key-cape and OpenBao are Tooling, so their evidence
is routed through user-engine/access-engine and secrets-engine rather
than read directly.
Finding on the invited challenge to §5: do not weaken the binding rule,
but §4 catalogs kings-guard as owning containment while no engine exposes
a containment surface — the charter is currently undischargeable. Two
rulings requested of gate-house. Three engine gaps declared in INTENT.md.
Residual handed off as KG-IN-0002 (vocabulary sweep of the architecture
spec).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014379@bnt-lap001
Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
Regenerated by fix-consistency; adds the inbound assent intake.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
The layer model is now published as
net-kingdom/canon/standards/security-layer-model_v0.1.md (proposed) and
ratified by gate-house GH-DEC-2026-001. The note previously said the
standard was not yet written.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Records this repository's layer in the NetKingdom IT-security layer model
(Taxonomy / Tooling / Engines / Staff) and what should change in this INTENT
as a result. Links to the review that established the model:
gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md
The note flags pending adaptation only; the body is unchanged.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
The remote row pointed at 127.0.0.1:18000, a reverse tunnel back to the
workstation. On railiance01 the State Hub runs in the cluster on that same
machine, so the request left the box and came back to reach a local service.
Refs CUST-WP-0067-T07
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
Maintainer decision, 2026-07-29: adopts TRSL V1C1 as this repo's
preliminary governing license, per target-revenue's
workplans/TREV-WP-0008-governance-and-pilot-rollout.md T05. Full
specialist legal review is deferred until out of beta (target-revenue
SCOPE.md §1). No Phase is yet declared for this repo.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
qonto-assistant is the first fleet service that must be both
internet-reachable and hold a real bank credential -- a concrete,
higher-stakes candidate for the first posture pilot than the
currently-listed order (ops-warden/secrets-engine/Railiance
reconstitution). It already ships an audit stream shaped like an
Immune Observation, a Security Genome record, and a working Fast
Local Loop (deny-escalation lockout), all without any kings-guard
component existing -- registered as intake 019f90c8 against
KG-WP-0002 so T04's pilot-lane selection can weigh it.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>