Compare commits
3 commits
061b4b35f9
...
7c8ef38ee0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7c8ef38ee0 | ||
| 3617f7e9c8 | |||
| 2075b75180 |
2 changed files with 48 additions and 0 deletions
15
INTENT.md
15
INTENT.md
|
|
@ -1,5 +1,20 @@
|
|||
# INTENT
|
||||
|
||||
> **NetKingdom layering review — 2026-08-28.** This repository's role was reviewed
|
||||
> against the NetKingdom IT-security layer model: **Taxonomy → Tooling → Engines →
|
||||
> Staff**, layered by determinism and by the kind of artifact each layer produces.
|
||||
> Findings and the argument behind them:
|
||||
> `gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md`.
|
||||
> The model is `net-kingdom/canon/standards/security-layer-model_v0.1.md` (proposed),
|
||||
> ratified by `gate-house/decisions/decisions.md` GH-DEC-2026-001.
|
||||
>
|
||||
> The layer rule that binds every repository: **Staff never touches tooling
|
||||
> directly. It acts only through engine APIs.**
|
||||
>
|
||||
> **This repository is Staff — interactive, non-deterministic; adaptive defence.** Add the layer label. The self-description **"adaptive security control plane"** needs revisiting: control-plane vocabulary belongs to the Engine layer, and kings-guard is agentic and therefore Staff. This is not a demotion — it is the reason kings-guard may contain a threat only by calling an engine, never by reaching into OpenBao or a cluster directly. Also state the posture contract with gate-house and its asymmetry: **adaptive systems may reduce authority, require step-up, or request containment; they must never probabilistically manufacture additional authority.**
|
||||
>
|
||||
> *This note records what should change. The body below is not yet adapted.*
|
||||
|
||||
> This file captures **why this repository exists**, the **direction it is
|
||||
> moving toward**, and the **kind of system it is meant to become**.
|
||||
> It is intentionally **aspirational and stable**, not a description of
|
||||
|
|
|
|||
33
intakes/intakes.md
Normal file
33
intakes/intakes.md
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
# Intake records
|
||||
|
||||
## KG-IN-0001 — Assent requested: Staff layer placement, control-plane vocabulary, and the posture asymmetry
|
||||
|
||||
```yaml
|
||||
id: KG-IN-0001
|
||||
kind: intake
|
||||
title: 'Assent requested: Staff layer placement, control-plane vocabulary, and the
|
||||
posture asymmetry'
|
||||
status: open
|
||||
origin: cross-repo
|
||||
origin_ref: gate-house GH-DEC-2026-001
|
||||
priority: medium
|
||||
owner: kings-guard
|
||||
requested_by: gate-house
|
||||
standard: net-kingdom/canon/standards/security-layer-model_v0.1.md
|
||||
description: 'gate-house asks kings-guard to assent to its placement in the NetKingdom
|
||||
security layer model. (1) kings-guard is Staff — agentic and non-deterministic —
|
||||
not an Engine. Acting at runtime does not make a repository an Engine; being agentic
|
||||
makes it Staff. (2) Consequently its self-description as an adaptive security control
|
||||
plane needs revisiting: control plane is Engine-layer vocabulary (standard section
|
||||
8). This is not a demotion — it is the reason kings-guard may contain a threat only
|
||||
by calling an engine, never by reaching into OpenBao or a cluster directly (the
|
||||
binding rule, standard section 5: Staff never touches Tooling directly). (3) The
|
||||
posture contract with gate-house and its asymmetry: adaptive systems may reduce
|
||||
authority, require step-up, or request containment; they must never probabilistically
|
||||
manufacture additional authority. kings-guard publishes posture, gate-house defines
|
||||
its authority meaning, access-engine renders it. If the binding rule is impractical
|
||||
for containment in a real incident, say so — that is exactly the kind of finding
|
||||
that should change the doctrine rather than be worked around.'
|
||||
created: '2026-08-28T19:30:17.201213Z'
|
||||
updated: '2026-08-28T19:30:17.201213Z'
|
||||
```
|
||||
Loading…
Add table
Add a link
Reference in a new issue