From 2075b751804ff6a043dcb8feae6c3ed44cff0ef4 Mon Sep 17 00:00:00 2001 From: tegwick Date: Fri, 28 Aug 2026 20:33:43 +0200 Subject: [PATCH 1/3] Note NetKingdom layering review in INTENT Records this repository's layer in the NetKingdom IT-security layer model (Taxonomy / Tooling / Engines / Staff) and what should change in this INTENT as a result. Links to the review that established the model: gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md The note flags pending adaptation only; the body is unchanged. Co-Authored-By: Claude Opus 5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- INTENT.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/INTENT.md b/INTENT.md index 7050575..0ab7ae1 100644 --- a/INTENT.md +++ b/INTENT.md @@ -1,5 +1,20 @@ # INTENT +> **NetKingdom layering review — 2026-08-28.** This repository's role was reviewed +> against the NetKingdom IT-security layer model: **Taxonomy → Tooling → Engines → +> Staff**, layered by determinism and by the kind of artifact each layer produces. +> Findings and the argument behind them: +> `gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md`. +> The model as currently stated is `gate-house/INTENT.md` § "Where Gate House Sits"; +> it is ruled to become a `net-kingdom/canon/standards/` standard, not yet written. +> +> The layer rule that binds every repository: **Staff never touches tooling +> directly. It acts only through engine APIs.** +> +> **This repository is Staff — interactive, non-deterministic; adaptive defence.** Add the layer label. The self-description **"adaptive security control plane"** needs revisiting: control-plane vocabulary belongs to the Engine layer, and kings-guard is agentic and therefore Staff. This is not a demotion — it is the reason kings-guard may contain a threat only by calling an engine, never by reaching into OpenBao or a cluster directly. Also state the posture contract with gate-house and its asymmetry: **adaptive systems may reduce authority, require step-up, or request containment; they must never probabilistically manufacture additional authority.** +> +> *This note records what should change. The body below is not yet adapted.* + > This file captures **why this repository exists**, the **direction it is > moving toward**, and the **kind of system it is meant to become**. > It is intentionally **aspirational and stable**, not a description of From 3617f7e9c856dbcb5dc5910a26d1e2d585251a04 Mon Sep 17 00:00:00 2001 From: tegwick Date: Fri, 28 Aug 2026 21:21:08 +0200 Subject: [PATCH 2/3] Point layering note at the published standard The layer model is now published as net-kingdom/canon/standards/security-layer-model_v0.1.md (proposed) and ratified by gate-house GH-DEC-2026-001. The note previously said the standard was not yet written. Co-Authored-By: Claude Opus 5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- INTENT.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/INTENT.md b/INTENT.md index 0ab7ae1..02acec6 100644 --- a/INTENT.md +++ b/INTENT.md @@ -5,8 +5,8 @@ > Staff**, layered by determinism and by the kind of artifact each layer produces. > Findings and the argument behind them: > `gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md`. -> The model as currently stated is `gate-house/INTENT.md` § "Where Gate House Sits"; -> it is ruled to become a `net-kingdom/canon/standards/` standard, not yet written. +> The model is `net-kingdom/canon/standards/security-layer-model_v0.1.md` (proposed), +> ratified by `gate-house/decisions/decisions.md` GH-DEC-2026-001. > > The layer rule that binds every repository: **Staff never touches tooling > directly. It acts only through engine APIs.** From 7c8ef38ee0603c4ca23e69abaff689b86da752b4 Mon Sep 17 00:00:00 2001 From: repo-manager Date: Fri, 28 Aug 2026 21:30:17 +0200 Subject: [PATCH 3/3] repo.work.create_intake KG-IN-0001 correlation_id: f9b8b130-71f6-41b9-9f06-e28d2abda2d4 reason: Request assent for GH-DEC-2026-001 boundaries source: repo-manager Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- intakes/intakes.md | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 intakes/intakes.md diff --git a/intakes/intakes.md b/intakes/intakes.md new file mode 100644 index 0000000..4a15a2a --- /dev/null +++ b/intakes/intakes.md @@ -0,0 +1,33 @@ +# Intake records + +## KG-IN-0001 — Assent requested: Staff layer placement, control-plane vocabulary, and the posture asymmetry + +```yaml +id: KG-IN-0001 +kind: intake +title: 'Assent requested: Staff layer placement, control-plane vocabulary, and the + posture asymmetry' +status: open +origin: cross-repo +origin_ref: gate-house GH-DEC-2026-001 +priority: medium +owner: kings-guard +requested_by: gate-house +standard: net-kingdom/canon/standards/security-layer-model_v0.1.md +description: 'gate-house asks kings-guard to assent to its placement in the NetKingdom + security layer model. (1) kings-guard is Staff — agentic and non-deterministic — + not an Engine. Acting at runtime does not make a repository an Engine; being agentic + makes it Staff. (2) Consequently its self-description as an adaptive security control + plane needs revisiting: control plane is Engine-layer vocabulary (standard section + 8). This is not a demotion — it is the reason kings-guard may contain a threat only + by calling an engine, never by reaching into OpenBao or a cluster directly (the + binding rule, standard section 5: Staff never touches Tooling directly). (3) The + posture contract with gate-house and its asymmetry: adaptive systems may reduce + authority, require step-up, or request containment; they must never probabilistically + manufacture additional authority. kings-guard publishes posture, gate-house defines + its authority meaning, access-engine renders it. If the binding rule is impractical + for containment in a real incident, say so — that is exactly the kind of finding + that should change the doctrine rather than be worked around.' +created: '2026-08-28T19:30:17.201213Z' +updated: '2026-08-28T19:30:17.201213Z' +```