kings-guard/AGENTS.md
tegwick 3d6025ae51 Assent to Staff placement; release control-plane vocabulary (KG-IN-0001)
Answers gate-house intake KG-IN-0001 / GH-DEC-2026-001 against the
NetKingdom Security Layer Model v0.1.

Assent to all three points, recorded as KG-DEC-2026-001:
- kings-guard declares layer Staff in INTENT.md;
- "control plane" released to the Engine layer across INTENT, SCOPE,
  README, AGENTS and the adjacent-system boundary;
- the posture asymmetry adopted as a repo invariant — already satisfied,
  every EffectorRequest carries an explicit authority_boundary.

Boundary corrections: key-cape and OpenBao are Tooling, so their evidence
is routed through user-engine/access-engine and secrets-engine rather
than read directly.

Finding on the invited challenge to §5: do not weaken the binding rule,
but §4 catalogs kings-guard as owning containment while no engine exposes
a containment surface — the charter is currently undischargeable. Two
rulings requested of gate-house. Three engine gaps declared in INTENT.md.

Residual handed off as KG-IN-0002 (vocabulary sweep of the architecture
spec).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014379@bnt-lap001
Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
2026-08-28 21:47:05 +02:00

7.3 KiB

kings-guard — Agent Instructions

Repo Identity

Purpose: Adaptive immune defence for complex multi-tenant cloud environments.

Layer: Staff (NetKingdom Security Layer Model v0.1). Never open a direct client for a Tooling-layer system (OpenBao, key-cape components, a database, a cluster); route every such need through the owning engine and record the gap in INTENT.md. Never render or cache an authorization decision.

Domain: infotech Repo slug: kings-guard Topic ID: cee7bedf-2b48-46ef-8601-006474f2ad7a Workplan prefix: KG-WP-


State Hub Integration

The Custodian State Hub tracks work across all domains. Interact via HTTP REST — there is no MCP server for Codex agents.

Context URL
Local workstation http://127.0.0.1:8000
Remote (railiance01, in-cluster) http://10.43.68.154:8000
Optional local edge relay http://127.0.0.1:18080

When an operator has enabled the edge relay, set API_BASE to the relay URL. Queueable writes return an explicit queued receipt if the central hub is unreachable. Treat that as pending local evidence, then ask the operator to run statehub outbox status/replay after connectivity returns.

Orient at session start

# Offline brief — works without hub connection
cat .custodian-brief.md

# Active workplans for this domain
curl -s "http://127.0.0.1:8000/workplans/?topic_id=cee7bedf-2b48-46ef-8601-006474f2ad7a&status=active" \
  | python3 -m json.tool

# Check inbox
curl -s "http://127.0.0.1:8000/messages/?to_agent=kings-guard&unread_only=true" \
  | python3 -m json.tool

Mark a message read:

curl -s -X PATCH "http://127.0.0.1:8000/messages/<id>/read" \
  -H "Content-Type: application/json" -d '{}'

Log progress (required at session close)

curl -s -X POST http://127.0.0.1:8000/progress/ \
  -H "Content-Type: application/json" \
  -d '{
    "summary": "what was done",
    "event_type": "note",
    "author": "codex",
    "workplan_id": "<uuid>",
    "task_id": "<uuid>"
  }'

Omit workplan_id / task_id when not applicable.

Update task status

curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
  -H "Content-Type: application/json" \
  -d '{"status": "progress"}'
# values: wait | todo | progress | done | cancel

Flag a task for human review

curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
  -H "Content-Type: application/json" \
  -d '{"needs_human": true, "intervention_note": "reason"}'

Session Protocol

Start:

  1. cat .custodian-brief.md — domain goal and open workplans (offline-safe)
  2. Check inbox: GET /messages/?to_agent=kings-guard&unread_only=true; mark read
  3. Scan workplans: ls workplans/ — note status: ready, active, or blocked files and open tasks
  4. Check human-needed tasks: GET /tasks/?needs_human=true

During work:

  • Update task statuses in workplan files as tasks progress
  • Record significant decisions via POST /decisions/

Close:

  1. Update workplan file task statuses to reflect progress
  2. If finishing a workplan: hand off residuals as live work records first (intake with origin: residual + origin_ref: <WP-id>, or a next workplan / decision / engagement). Do not park leftovers only in prose or SCOPE.md. Canon: the-custodian/canon/standards/work-record-types_v0.1.md § Residuals.
  3. Log: POST /progress/ with a summary of what changed (name handoff ids)
  4. After workplan file changes, run:
    statehub fix-consistency
    
    Coding agents should run this directly; ask the operator only if the CLI or State Hub API is unavailable. This syncs task status from files into the hub DB.

{CREDENTIAL_ROUTING}

Repo-Specific Notes

This repo is no longer docs-only. It now has a small Python 3.12 scaffold for contract modeling and posture evaluation. It is a Staff-layer repository: not a long-running enforcement service, and not a control plane.

Working Set

Start with these files:

cat INTENT.md
cat SCOPE.md
sed -n '1,260p' specs/NetKingdomImmuneArchitecture.md
sed -n '1,260p' specs/ImmuneContracts.md
sed -n '1,260p' docs/AdjacentSystemBoundary.md
sed -n '1,260p' docs/pilots/QontoAssistantPosturePilot.md
find src tests -maxdepth 3 -type f | sort
ls workplans/

Verification

Use the repo-local scaffold commands:

# Preferred, if make + pip are available
make install-dev

# Test and lint the scaffold
make test
make lint

# Demo the current pilot path
make run-demo

# Direct shell fallback used in minimal environments
python3 -m pytest -q
PYTHONPATH=src python3 -m kings_guard.main --pilot qonto-assistant

# Check markdown/frontmatter edits too
git diff --check

# Sync workplan/task state into State Hub after workplan changes
cd /home/worsch/state-hub && ./.venv/bin/statehub fix-consistency --repo kings-guard

Workplan Convention (ADR-001)

Work items originate as files in this repo — not in the hub. The hub is a read/cache/index layer that rebuilds from files.

File location: workplans/KG-WP-NNNN-<slug>.md

Archived location: finished workplans may move to workplans/archived/YYMMDD-KG-WP-NNNN-<slug>.md. The YYMMDD prefix is the completion/archive date; the frontmatter id does not change.

Ad Hoc Tasks: small opportunistic fixes discovered during a session use workplans/ADHOC-YYYY-MM-DD.md with task ids ADHOC-YYYY-MM-DD-T01, etc. Use this only for low-risk work completed directly; create a normal workplan for anything needing analysis, design, approval, dependencies, or multiple phases.

Frontmatter:

---
id: KG-WP-NNNN
type: workplan
title: "..."
domain: infotech
repo: kings-guard
status: proposed | ready | active | blocked | backlog | finished | archived
owner: codex
topic_slug: ...
created: "YYYY-MM-DD"
updated: "YYYY-MM-DD"
state_hub_workstream_id: "<uuid>"   # fix-consistency — do not edit (legacy field name; workplan UUID)
---

Use proposed for a new draft, ready after review against current repo state, and finished after implementation. stalled and needs_review are derived health labels, not frontmatter statuses.

Terminology: workplan is the fleet term; workstream appears only in legacy API/MCP/frontmatter bridges until STATE-WP-0069 retires them — see the-custodian/canon/standards/workplan-terminology-fleet_v0.1.md.

Task block format (one per ## section):

## Task Title

` ` `task
id: KG-WP-NNNN-T01
status: wait | todo | progress | done | cancel
priority: high | medium | low
state_hub_task_id: "<uuid>"         # written by fix-consistency — do not edit
` ` `

Task description text.

Status progression: todoprogressdone; use wait for waiting/blocked work and cancel for stopped work.

Residuals when finishing: actionable leftovers become live work records before status: finished — usually an intake (origin: residual, origin_ref: KG-WP-NNNN) or a spawned workplan. Residual is a role, not a kind. Fleet list lives on State Hub, not in SCOPE.md.

To create a new workplan:

  1. Write the file following the format above
  2. Run statehub fix-consistency locally; ask the operator only if the CLI or State Hub API is unavailable.