--- title: "Layer-vocabulary inventory of NetKingdomImmuneArchitecture.md" date: 2026-09-02 repo: kings-guard author: kings-guard workplan: KG-WP-0004-T01 standard: net-kingdom/canon/standards/security-layer-model_v0.7.md sections_read: ["3.4", "5", "6", "8", "9.2"] target: specs/NetKingdomImmuneArchitecture.md status: complete classification: Public --- # Layer-vocabulary inventory of NetKingdomImmuneArchitecture.md T01 of `KG-WP-0004`. Re-derived from the spec against Security Layer Model v0.7 §§3.4, 5, 6, 8, 9.2. The promotion table in the workplan is a snapshot; this file is the execution map for T02–T04. ## Method Every section of the spec was read. Each row is classified: | Action | Meaning | | --- | --- | | **keep** | Wording is already compatible, or is not a layer claim. | | **keep-label** | Phrase stays, but T03 must mark it as Engine / platform / Kubernetes so it cannot be read as kings-guard. | | **re-home** | The capability stays in the architecture; T02 assigns it to Engine, PEP, or Tooling rather than this Staff repository. | | **rewrite** | The claim is wrong for Staff. T02/T04 change the sentence, diagram, or example. | Layer of the *capability*, not of the sentence's current owner: - **Staff** — observe, judge, propose (`kings-guard`); doctrine (`gate-house`) - **Engine** — decide (`access-engine` PDP), facts (PIPs), lifecycle, evidence custody - **PEP** — cause a protected side effect; a shape, not a layer (§6.4) - **Tooling** — hold, attest, store (`key-cape`, OpenBao) - **platform/k8s** — a tenant or cluster control/management plane, not this repo Statute reminders used as the test: - §8: "control plane" belongs to the Engine layer, not a Staff self-description. - §6 / §6.3: one decision point, `access-engine`. No Staff repository hosts one. - §9.2: kings-guard proposes containment; it never performs it. Actuation is an Engine concept held at zero. - §3.4 rule 3: agent/immune memory is not a state plane. - §5: Staff never touches Tooling directly. --- ## 1. Every "control plane" occurrence Complete. `grep -nE 'control plane|control-plane|Control Plane'`. | Line | Text | Layer | Action | T0n | | --- | --- | --- | --- | --- | | 19–25 | Head note: read "control plane" as Engine-layer; sweep tracked as KG-IN-0002 | Staff note | **rewrite** — cite v0.7, drop the intake pointer, record the sweep date | T05 | | 436 | mermaid subgraph `CONTROL["Platform Immune Control Plane"]` | mixed, currently Staff-shaped | **rewrite** — split Staff observation/judgment from Engine decision/actuation; do not name a kings-guard control plane | T02 | | 681 | sentinel class `control-plane sentinel` | platform/k8s (observe the cluster API) | **keep-label** — this is a sentinel *of* a Kubernetes/platform control plane, not kings-guard being one | T03 | | 1018 | platform owns "cluster and control-plane security" | platform/k8s | **keep-label** | T03 | | 1055 | I3 Sovereign: "Dedicated account, keys, control plane and operations" | platform/k8s (tenant's own cloud) | **keep-label** | T03 | | 1873 | dedicated-tenant profile: "dedicated tenant control plane" | platform/k8s | **keep-label** | T03 | Near-miss, same defect, not the string "control plane": | Line | Text | Action | T0n | | --- | --- | --- | --- | | 56 | "recursive adaptive security **control system**" | **rewrite** — same overlap as control plane; INTENT dropped this | T02 | | 1053 | I2 Dedicated: "Tenant-specific **control and compute plane**" | **keep-label** | T03 | | 154, 650, 2083 | "management plane" / "management-plane separation" | **keep-label** — platform management plane | T03 | | 2276 | "recursive, multi-tenant **control architecture**" | **rewrite** | T02 / T05 | After T03, a grep for `control plane|control-plane|Control Plane` must have only labelled Engine/platform/k8s hits, or none. --- ## 2. Decision, response, and actuation claims These are the rows T02 and T04 execute. A Staff component must not render allow/deny, cache a verdict, or perform isolate/revoke/contain. ### 2.1 Decision-shaped objects | Location | Claim | Action | Notes for T02 | | --- | --- | --- | --- | | §5 table | Lymph node = "Local correlation and **decision**"; Adaptive immunity = "**Adaptive Decision** and Policy Generation" | **rewrite** | Lymph node → local judgment/posture. Policy generation is doctrine or Engine policy package, not Staff deciding. | | §8 diagram | `DECISION["Decision and Response Engine"]` inside the control-plane subgraph | **re-home** | This box is `access-engine` (decide) plus unowned actuation. Not a kings-guard engine. | | §8 diagram | `REGULATION["Safety, Tolerance and Escalation Controller"]` | **re-home** | Tolerance is Staff genome/contract. Escalation that changes authority is Engine/PEP. Split. | | §9.2 | `trust_posture` with `valid_until` and `status: constrained` | **re-home** | Computed posture is Staff. A lifetime that other layers consume is an input claim to the PDP, not a Staff verdict. | | §9.4 | observation carries `assessment` and `proposed_response.action: isolate` | **rewrite** | Observation is not interpretation (`ImmuneContracts` §2.1). Assessment/proposal belong on phenotype/posture/signal, not on the observation. Proposal itself is Staff-legal. | | §9.5 | signal type `response authorization` | **re-home** | Authorization is the PDP. Staff may emit `response request`. | | §9.6 | "Decision Plane evaluates observations and **determines response**" | **rewrite** | Determining response is §6. Plane is Engine. `immune_decision` YAML is an Engine artifact (`access-engine` decision record), never a kings-guard posture record. `authority: tenant-immune-node` is a Staff node given isolate — forbidden. | | §10 diagram | `TN["Tenant Immune Node"]` → `TR["Tenant Response Effectors"]` | **rewrite** | Node may propose. Effectors fire only on a decision record / recorded PEP stance. | | §10.1 | tenant system owns "**local response decisions**" | **rewrite** | Local *judgment* and *proposals*. Decisions stay the one PDP. A local PEP applying a prior decision is §6.4, not a second PDP. | | §14.2 | "select bounded response" | **rewrite** | Select a proposal / posture hint. | | §15 | VSM System 3 = "Tenant and platform **response controllers**"; System 5 = "response authority" | **re-home** | Controllers that change authority are Engine/PEP. System 5 policy authorship is gate-house + policy package, compiled by the PDP. | | §16.2 | `kg:authority:tenant-isolator` granted to `tenant-immune-node-a` with `permitted_actions: isolate, revoke-ephemeral-credential` | **rewrite** | Staff node does not receive isolate as a power it exercises. Authority grant, if it survives, is an Engine/PEP grant. | | §19.1 | `OBSERVATION → DECISION → RESPONSE_ACTION` (`authorizes`) | **keep** as estate data model, **re-home** the DECISION entity onto `access-engine` | Add posture/signal between observation and decision. | | §19.2 | separation includes "decision" and "response authorization" vs "action execution" | **keep** | This split is the statute. Name the owners. | | §20.2 | "Policy **decisions** must expose: effective policies, precedence…" | **re-home** | PDP reconstructability. Not a Staff API. | | §22.2 | "decision latency" as immune-system KPI | **re-home** | PDP metric; kings-guard may publish *judgment* latency separately. | | §24 | tree `immune-decision/` with `policy-evaluation/`, `decision-schema/` | **rewrite** | That tree is a second PDP. kings-guard owns posture/signal/proposal schemas already in `specs/ImmuneContracts.md`. | | §25.1 | required "Decision Contract" | **re-home** | Owned by `access-engine` (statute §17 moved the decision-record schema there). | | §27 | participant `D as Decision Engine` then `D->>D: Compare…` then `D->>R: Propose…` then `R->>E: Authorize isolation` | **rewrite** | Two decision-shaped hops. Correct loop: sentinel/PEP may block locally under existing policy; kings-guard publishes posture; `access-engine` decides; PEP isolates. | | §31 Phase 4 | "policy evaluation" as a tenant-immune-node deliverable | **rewrite** | Correlation and recommendations, not evaluation-as-PDP. | | §33 AD-003 | "observation, **decision**, response, recovery and learning pattern" as the Kings Guard pattern | **rewrite** | Staff pattern is observe → judge → propose. Decide and act sit in Engine/PEP. | | §34 Q2 | "Which response actions may be **authorized autonomously** at each recursive level?" | **rewrite** | Autonomy here is a second decision point. Recast as: which *proposals* may Staff emit, and which PEP stances exist, at each level. | | §36 | sequence includes assessment then implied response as one architecture | **rewrite** | Sequence must name propose vs decide vs act. | ### 2.2 Actuation / containment claims (T04) Places that imply kings-guard, a "tenant immune node", or this architecture *performs* isolate / contain / revoke / restore. | Location | Claim | Action | Notes for T04 | | --- | --- | --- | --- | | §1 item 2 | architecture "identify and **contain** disturbances near their origin" | **rewrite** | Estate goal. kings-guard identifies and *proposes* containment. | | §4.9 | Effector = "component **authorized to perform** a concrete defensive action" (isolate, revoke, terminate…) | **re-home** | Effector is PEP-shaped. Staff emits `effector_request` as a proposal (`ImmuneContracts` / WP-0003-T06). | | §6.4 | "Local components **receive bounded authority**" and escalate | **rewrite** | Local PEPs receive a decision or a declared stance, not a standing isolate grant from this architecture. | | §6.7 | every critical capability must have "**containment**" | **keep** as estate requirement, **re-home** who performs it | Engine/PEP; unowned today (§9.2). | | §8 diagram | `EFFECTORS` / `PEFFECTORS` fed by `REGULATION` | **re-home** | Effectors are PEPs. Regulation that authorizes is the PDP. | | §9.3 | membrane "response hooks" | **keep** | Hooks are PEP-shaped integration, not Staff actuation. | | §9.7 | "**Response Plane executes** defensive actions"; ladder R1–R9 | **rewrite** | Ladder can stay as the *kinds of proposal / kinds of PEP action*. Plane execution is Engine+PEP. R0 Observe is Staff. | | §9.7 safety envelope | "Every **automated action** requires authorized issuer…" | **re-home** | Correct envelope for a PEP/actuation surface that does not exist yet. Do not hang it on kings-guard. | | §9.8 | Recovery plane executes redeploy, rotation, evacuation | **re-home** | Recovery is Engine/runtime. Staff may request reconstitution. | | §14.1 | Purpose: "**immediate containment**"; example "**isolate a process**" | **re-home** | Fast local loop is PEP-shaped (live example: qonto-assistant deny-escalation). Not kings-guard. Keep the loop. | | §14.2 | examples: revoke session, isolate workload group, rotate credentials | **rewrite** | Those are proposals from Staff or PEP actions under a decision. | | §14.3 | "coordinate platform response" / "validate containment" | **re-home** | Platform coordination may be Staff; containment validation is of a PEP outcome. | | §16 entire | Response Authority Model granting isolate to a Staff node | **rewrite** | See 2.1. T04 owns the grant example. | | §23.3 | KPIs: mean time to isolate, containment success rate | **keep** as estate KPIs, **re-home** | They measure the actuation surface, which is unowned. Do not imply kings-guard reports them as its own discharge. | | §24 | `immune-response/effectors/`, `authority-control/` | **rewrite** | Not a kings-guard tree. Point at Engine/PEP when they exist. | | §25.2 | `effector_request` with `decision_ref` then `action: isolate`; no observation/signal origin; no `authority_boundary` | **rewrite** | Match WP-0003-T06: originating observation/signal, explicit `authority_boundary`, restrictive direction, no widened authority. `effector_result` is a PEP/Engine artifact. | | §27 | `E->>W: Isolate workload`; "tenant compartment **contains** the possible compromise" | **rewrite** | Isolation is PEP after a decision. Result sentence: compartment *is the unit of* containment, performed by Engine/PEP, not by the node. | | §31 Phase 5 | title "Bounded **Automated Response**"; success = "**contained automatically**" | **rewrite** | INTENT stage 3: complete when proposals are well-formed and reconstructable, not when anything is contained. Actuation unowned. | | §32 | deliverables `ResponseAuthorityStandard.md`, `EffectorInterfaceSpecification.md` as kings-guard repo contents | **rewrite** | Proposal contract lives here. Authority/effector *execution* specs belong with the Engine/PEP owner. | | §33 AD-005 | "Every **automated action** is limited by…" | **rewrite** | Staff: every *proposal* is bounded. Automated *action* is Engine/PEP, currently zero. | | §34 Q2 | autonomous authorization of response | **rewrite** | See 2.1. | | §35 | "local disturbances can be **contained locally**" | **rewrite** | Estate success criterion. Name Engine/PEP as the actor; Staff as the proposer. | | §36 | "control architecture" closing the loop through response | **rewrite** | Propose, do not close the act. | --- ## 3. Section-by-section map Frontmatter through §36. "Own" means who the section should describe after the sweep, not who currently speaks. | Section | Own after sweep | Action | What T02–T05 do | | --- | --- | --- | --- | | Frontmatter | Staff spec | **rewrite** | Version bump, date, owners. T05. | | Head layer note | Staff | **rewrite** | v0.7; propose-not-act; memory not a state plane; sweep complete, not KG-IN-0002. T05. | | §1 Purpose | Staff describing an estate architecture | **rewrite** | "Contain" → identify and *propose* containment near origin. This file is the immune *architecture*, not a claim that `kings-guard` is the whole loop. | | §2 Proposition | Staff | **rewrite** | Drop "control system". Cycle: observe → judge → propose; decide/act are Engine/PEP and currently half-missing (actuation at zero). | | §3.1 In scope | mixed | **rewrite** | Identities, authz, admission, enforcement, "local and global security decisions", "automated response" are Engine/PEP/Tooling. In-scope *for this spec as estate map* may list them if each is layered. In-scope *for the kings-guard repository* must not. Split the two. | | §3.2 Out of scope | keep | **keep** | Product-neutrality is still right. | | §4.1–4.8 Organism…Signal | Staff contracts | **keep** | Align names with `ImmuneContracts.md` if they drift; no layer defect. | | §4.2 "management plane" example | platform | **keep-label** | T03. | | §4.9 Effector | PEP | **re-home** | T04. | | §4.10 Immune Memory | Staff | **rewrite** | Add §3.4 rule 3: not a runtime input for other layers. T05 (and T02 if the plane text moves). | | §4.11–4.13 Tolerance, Inflammation, Reconstitution | Staff concepts; reconstitution is Engine/runtime | **re-home** reconstitution | Tolerance/inflammation stay Staff. | | §5 Analogy table | mixed | **rewrite** | Lymph node / adaptive decision / complement=effectors rows. | | §6.1–6.3, 6.5, 6.8–6.12 Principles | Staff | **keep** | Intent-before-anomaly, evidence-before-judgment, memory governance already match INTENT. | | §6.4 Local response first | PEP + Staff proposal | **rewrite** | Bounded *proposal* locally; execution is PEP under a decision. | | §6.6 Reversible automation | Engine/PEP | **re-home** | Principle stands for whoever actuates. Staff does not automate isolate. | | §6.7 Recovery / containment as required capabilities | estate | **re-home** actors | T04. | | §6.11 Fail securely | Engine §9.3 stance | **re-home** | Degraded mode is the PDP/PEP stance map, not a Staff fail-open. | | §7 Recursive model | estate | **keep** | Recursion is fine. Each level still has only one PDP. | | §8 Top-level diagram | mixed | **rewrite** | T02 load-bearing task. Split CONTROL subgraph. | | §9 intro (nine planes) | mixed | **rewrite** | Each plane states its layer. | | §9.1 Genome plane | Staff consumes; owners produce | **re-home** "maintain canonical" | kings-guard does not run the intent registry. Contract stays. | | §9.2 Identity plane | Tooling `key-cape` + Engine `user-engine` | **re-home** | Trust-posture *publication* is Staff; issuance is not. | | §9.3 Membrane plane | Engine/PEP/runtime | **re-home** | "policy enforcement" is PEP. | | §9.4 Sentinel/evidence plane | Staff observes Staff-reachable sources; many sentinels are PEP/runtime | **rewrite** observation contract; **keep-label** control-plane sentinel | Identity/secret sentinels stay pending (blocked-clean). T02 + T03. | | §9.5 Signal plane | Staff + coordination | **re-home** `response authorization` | T02. | | §9.6 Decision plane | Engine PDP | **rewrite** | T02. Entire plane is not Staff. | | §9.7 Response plane | Engine + PEP; actuation unowned | **rewrite** | T04. | | §9.8 Recovery plane | Engine/runtime | **re-home** | T04. | | §9.9 Memory plane | Staff | **rewrite** | Not a state plane; engines/PEPs must not read it as runtime input. | | §10 Tenant architecture | mixed | **rewrite** | Immune node ≠ PDP. Effectors ≠ Staff. "local response decisions" out. | | §10.2 "cluster and control-plane security" | platform/k8s | **keep-label** | T03. | | §10.3 "contain platform-level incidents" | Engine/PEP | **re-home** | Platform *may request / may decide to* override; it does not give kings-guard isolate. | | §11 Isolation profiles | platform | **keep-label** I2/I3 control plane | T03. | | §12 Brokerage | Engine/platform | **keep** | Not a Staff decision point. | | §13 Admission | Engine/PEP (admission controller) | **re-home** | Genome is an input. Admission verdict is a decision. | | §14.1 Fast local loop | PEP | **re-home** | T04. Keep; name qonto-assistant as the live Staff-adjacent PEP example. | | §14.2 Tenant adaptive loop | Staff propose + Engine/PEP act | **rewrite** | T04. | | §14.3 Platform loop | mixed | **re-home** containment validation | T04. | | §14.4 Strategic learning | Staff + Taxonomy | **keep** | | | §15 VSM mapping | mixed | **re-home** Systems 3 and 5 | T02. | | §16 Authority model | Engine/PEP | **rewrite** | T04. Dimensions can stay as bounds on a future actuation surface. | | §17 Posture model | Staff publishes; gate-house meaning; access-engine renders | **rewrite** | Align names with `PostureLevel` (`healthy`/`elevated`/`inflamed`/`compromised`) or explicitly map Green/Blue/Amber/Red. Do not let posture look like a privilege source. | | §18 Pathologies | Staff + estate | **keep** | Autoimmunity/immunodeficiency still useful. "disabled effectors" is PEP health. | | §19 Data model | estate | **re-home** DECISION | T02. Insert posture/signal. | | §20 Policy architecture | Engine + gate-house doctrine | **re-home** | Constitutional policy is Taxonomy/gate-house. Resolution is the PDP. | | §21 Evidence | Engine `audit-core` | **re-home** | Custody is not Staff. Completeness bound §9.6 is already in the scaffold. | | §22 Observability | mixed | **re-home** decision/response latency | T02. | | §23 KPIs | estate | **re-home** containment KPIs | T04. Evidence completeness KPI stays relevant to Staff. | | §24 Capability tree | Staff vs not | **rewrite** | Drop or re-home `identity-immunity`, `compartment-control`, `immune-decision`, `immune-response`, `immune-recovery` as other repos. Keep genome, sentinel consumption, coordination, memory (governed), regulation-as-safety-of-proposals. T02 + T04. | | §25 Contracts | mixed | **re-home** Decision; **rewrite** Effector | T02 + T04. Observation/signal/genome/memory already have `ImmuneContracts.md`. | | §26.1–26.2 k8s profiles | platform | **keep** | | | §26.3 "dedicated tenant control plane" | platform/k8s | **keep-label** | T03. | | §26.4–26.5 Sovereign / edge | platform | **keep** | | | §27 Incident flow | mixed | **rewrite** | T02 (decision hops) + T04 (isolate actor). | | §28 Federation | Staff memory publication | **keep** | Quarantine-before-enforcement is PEP/PDP, not Staff enforcing. | | §29 Implementation independence | keep | **keep** | | | §30 Assurance | mixed | **re-home** "policy enforcement" / "response authority" | Continuous assurance of those is Engine/PEP. | | §31 Phase 1–2 | Engine/Tooling/platform | **re-home** | Not kings-guard deliverables. | | §31 Phase 3 | Staff observation + source-published streams | **keep** as Staff slice | Matches WP-0003. | | §31 Phase 4 | Staff judgment | **rewrite** | Recommendations, not policy evaluation. | | §31 Phase 5 | Staff proposals; actuation unowned | **rewrite** | T04 load-bearing. | | §31 Phase 6 | Engine/runtime | **re-home** | | | §31 Phase 7 | Staff memory | **rewrite** | Federated memory must not become a state plane (INTENT stage 5). | | §31 Phase 8 | Staff + Taxonomy | **keep** | | | §32 Repo deliverables | Staff | **rewrite** | Align with files that exist (`INTENT`, this spec, `ImmuneContracts`, pilots). Do not list identity/attestation/effector-execution specs as this repo's. | | §33 AD-001–002, 004, 006–009 | keep | **keep** | | | §33 AD-003, AD-005 | Staff vs Engine | **rewrite** | T04 / T05. | | §34 Open questions | mixed | **rewrite** Q2, **keep** Q12 | Q12 is this workplan's question; T05 can answer: kings-guard owns observation, judgment, proposal, governed memory; not identity, PDP, secrets, actuation. | | §35 Success | estate | **rewrite** containment actor | T04 / T05. | | §36 Summary | Staff | **rewrite** | Drop control-architecture; name propose/decide/act. | --- ## 4. How T02–T04 execute from this map Do not re-discover the file. Use these slices: **T02 — diagram and planes** §5 analogy, §8 diagram, §9 intro through §9.6 and §9.9, §10 node/effectors, §15 VSM, §19 data model, §20.2, §22.2, §24 `immune-decision/`, §25.1 Decision Contract, §27 decision hops, §31 Phase 4. **T03 — remaining control-plane strings** The six rows in §1 of this file, plus I2 "control and compute plane" and management-plane near-misses. Label or remove. Then grep. **T04 — containment / Phase 5 / effector** §2.2 of this file in full, especially §4.9, §9.7, §14, §16, §25.2, §27, §31 Phase 5, §33 AD-005. **T05 — §6 audit and layer note** Walk every **rewrite** row in §2.1 after T02–T04 land. Refresh the head note to v0.7. Answer §34 Q12. Confirm `make test` / `make check-layer` still pass. --- ## 5. Explicitly not mismatches Listed so T02 does not "fix" them: - Product-neutral out-of-scope (§3.2, §29). - Genome / observation / signal / phenotype / tolerance / inflammation as vocabulary — already the Staff contract set. - Tenant isolation as an estate property (membranes, profiles I0–I4). - Evidence treated as a protected asset (§21) — custody is Engine; the *requirement* is fine. - Recursion (§7) and VSM as a reading aid, once Systems 3 and 5 are re-homed. - Asymmetry of posture (reduce / step-up / request containment, never manufacture authority) — already in INTENT; §17 should cite it, not invent a privilege source. - WP-0003 scaffold (`contracts.py`, stream completeness, origin-linked proposals). This inventory does not ask for code changes.