# kings-guard Adaptive security contracts and posture-evaluation scaffold for NetKingdom's immune-architecture work. **Layer: Staff** (NetKingdom Security Layer Model v0.1). kings-guard publishes posture and requests bounded response through engine APIs; it never touches Tooling directly and never renders an authorization decision. ## Current slice This repository now contains four aligned pieces: - `INTENT.md` / `SCOPE.md` for the repo's stable boundary - `specs/NetKingdomImmuneArchitecture.md` for the reference architecture - `specs/ImmuneContracts.md` for the first canonical contract layer - `src/kings_guard/` plus `tests/` for a minimal posture loop scaffold The current implementation is intentionally narrow. It does **not** enforce anything. It provides: - typed contracts for security genome, phenotype, observation, posture, signal, effector request, and immune memory entry; - evidence-class and stream-completeness fields, so silence is a finding and record richness is not mistaken for a complete stream; - a posture evaluator that judges one observation and, separately, the stream it came from; - a `qonto-assistant` pilot that still has a fixture regression case and can also consume real events from that service's own AuditLogger. ## Repo layout - `specs/NetKingdomImmuneArchitecture.md` - `specs/ImmuneContracts.md` - `docs/AdjacentSystemBoundary.md` - `docs/pilots/QontoAssistantPosturePilot.md` - `src/kings_guard/` - `tests/` - `workplans/` ## Dev commands ```bash # preferred, if make + pip are available make install-dev make test make lint make run-demo # direct shell fallback used in minimal environments python3 -m pytest -q PYTHONPATH=src python3 -m kings_guard.main --pilot qonto-assistant ```