Adaptive immune security architecture for netkingdom
Find a file
tegwick 72c2a42d67 Declare layer machine-readably (§11); adopt v0.6 corrections
The standard moved v0.4 -> v0.6. All four findings from our v0.4 review
were adopted in v0.5, and v0.6 went further on two of them.

§11 now requires a machine-readable declaration — prose cannot
distinguish a declaration from a transcribed review. We had none.
Added layer.yaml (form adapted from ops-warden's reference
implementation), scripts/check_layer_conformance.py, and
tests/test_layer_conformance.py.

The check makes our central claim mechanical rather than asserted: no
direct Tooling client in src/. The test exercises the negative case on a
synthetic tree, so it fails if the checker goes blind. pyyaml is added as
a DEV dependency only — `dependencies = []` is load-bearing for the §5
claim and stays empty.

Adopted from v0.6:
- containment is no longer ours (§9.2). Actuation is an Engine concept,
  unowned and held at zero; kings-guard proposes containment and never
  performs it. The register row is now a dependency, not our gap.
- observation is scoped to Staff-reachable sources, with identity and
  secret observation pending — our finding 1, adopted near-verbatim.
- access-engine DECLINED the authentication-evidence gap; owner is now
  the identity layer plus audit-core, reproposed and unassented.
- §11 blocked-clean recorded, with the rule that it must not rank below
  conforming — our finding 2.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014379@bnt-lap001
Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
2026-08-29 10:20:39 +02:00
.repo-manager Repoint at Security Layer Model v0.4; assess and report to gate-house 2026-08-29 02:41:43 +02:00
decisions chore(registrar): assign State Hub identifiers 2026-08-28 21:48:08 +02:00
docs Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
history Register kings-guard with State Hub 2026-07-23 22:55:42 +02:00
intake Close absorbed qonto pilot intake 2026-07-24 00:34:52 +02:00
intakes repo.work.create_intake KG-IN-0003 2026-08-28 22:40:12 +02:00
scripts Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
specs Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
src/kings_guard Implement KG-WP-0002 posture pilot scaffold 2026-07-24 00:24:53 +02:00
tests Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
workplans Implement KG-WP-0002 posture pilot scaffold 2026-07-24 00:24:53 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-07-24 00:16:02 +02:00
.gitignore Implement KG-WP-0002 posture pilot scaffold 2026-07-24 00:24:53 +02:00
.repo-classification.yaml Register kings-guard with State Hub 2026-07-23 22:55:42 +02:00
AGENTS.md Assent to Staff placement; release control-plane vocabulary (KG-IN-0001) 2026-08-28 21:47:05 +02:00
INTENT.md Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
layer.yaml Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:28:01 +02:00
Makefile Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
pyproject.toml Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
README.md Assent to Staff placement; release control-plane vocabulary (KG-IN-0001) 2026-08-28 21:47:05 +02:00
SCOPE.md Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
WORK-RECORDS.md Refresh work-record index 2026-08-28 22:43:06 +02:00

kings-guard

Adaptive security contracts and posture-evaluation scaffold for NetKingdom's immune-architecture work.

Layer: Staff (NetKingdom Security Layer Model v0.1). kings-guard publishes posture and requests bounded response through engine APIs; it never touches Tooling directly and never renders an authorization decision.

Current slice

This repository now contains four aligned pieces:

  • INTENT.md / SCOPE.md for the repo's stable boundary
  • specs/NetKingdomImmuneArchitecture.md for the reference architecture
  • specs/ImmuneContracts.md for the first canonical contract layer
  • src/kings_guard/ plus tests/ for a minimal posture loop scaffold

The current implementation is intentionally narrow. It does not enforce anything. It provides:

  • typed contracts for security genome, phenotype, observation, posture, signal, effector request, and immune memory entry;
  • a minimal posture evaluator that turns a normalized observation into a posture assessment and bounded response hints;
  • a fixture-driven pilot based on qonto-assistant, chosen because it already exposes a security genome record, an audit stream, and a fast local loop.

Repo layout

  • specs/NetKingdomImmuneArchitecture.md
  • specs/ImmuneContracts.md
  • docs/AdjacentSystemBoundary.md
  • docs/pilots/QontoAssistantPosturePilot.md
  • src/kings_guard/
  • tests/
  • workplans/

Dev commands

# preferred, if make + pip are available
make install-dev
make test
make lint
make run-demo

# direct shell fallback used in minimal environments
python3 -m pytest -q
PYTHONPATH=src python3 -m kings_guard.main --pilot qonto-assistant