Adaptive immune security architecture for netkingdom
Find a file
tegwick 7b678e5d73 Apply GH-DEC-2026-020: print scope on every run, widen A12 detection.
The checker now prints the standard version and the run's scope first on
every run, pass or fail, and enforces A12 r2 over every key and value of
the INTENT.md frontmatter and layer.yaml, not only a key named
standard_version. Tests fail if a versioned standard: path or a
companion_version comes back. Neither declaration form changed.

KG-DEC-2026-005 records assent to A9, A10, A11 and A13 and returns A12 r2
revised, with one finding: "any value" reaches prose revision citations.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 09:38:27 +02:00
.repo-manager Repoint at Security Layer Model v0.4; assess and report to gate-house 2026-08-29 02:41:43 +02:00
decisions Apply GH-DEC-2026-020: print scope on every run, widen A12 detection. 2026-09-21 09:38:27 +02:00
docs Answer gate-house's v0.8 round and record the §11 declaration-form wait. 2026-09-21 02:10:39 +02:00
history Complete KG-WP-0004-T05 and finish the architecture vocabulary sweep 2026-09-02 10:06:53 +02:00
intake Close absorbed qonto pilot intake 2026-07-24 00:34:52 +02:00
intakes Apply GH-DEC-2026-017 to the layer declaration; close KG-IN-0007. 2026-09-21 07:35:40 +02:00
scripts Apply GH-DEC-2026-020: print scope on every run, widen A12 detection. 2026-09-21 09:38:27 +02:00
specs Admit source evidence snapshots and harden stream completeness 2026-09-05 00:42:19 +02:00
src/kings_guard Admit source evidence snapshots and harden stream completeness 2026-09-05 00:42:19 +02:00
tests Apply GH-DEC-2026-020: print scope on every run, widen A12 detection. 2026-09-21 09:38:27 +02:00
workplans chore(consistency): write back hub ids for KG-DEC-2026-004 and KG-IN-0006..0008 2026-09-21 02:14:16 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-21 02:13:57 +02:00
.gitignore Finish KG-WP-0003: stream completeness and live qonto observation 2026-09-02 00:11:57 +02:00
.repo-classification.yaml Register kings-guard with State Hub 2026-07-23 22:55:42 +02:00
AGENTS.md Assent to Staff placement; release control-plane vocabulary (KG-IN-0001) 2026-08-28 21:47:05 +02:00
INTENT.md Apply GH-DEC-2026-017 to the layer declaration; close KG-IN-0007. 2026-09-21 07:35:40 +02:00
layer.yaml Apply GH-DEC-2026-017 to the layer declaration; close KG-IN-0007. 2026-09-21 07:35:40 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:28:01 +02:00
Makefile Declare layer machine-readably (§11); adopt v0.6 corrections 2026-08-29 10:20:39 +02:00
pyproject.toml Admit source evidence snapshots and harden stream completeness 2026-09-05 00:42:19 +02:00
README.md Complete KG-WP-0004-T05 and finish the architecture vocabulary sweep 2026-09-02 10:06:53 +02:00
SCOPE.md Admit source evidence snapshots and harden stream completeness 2026-09-05 00:42:19 +02:00
WORK-RECORDS.md Refresh WORK-RECORDS.md after KG-IN-0007 closed. 2026-09-21 07:37:57 +02:00

kings-guard

Adaptive security contracts and posture-evaluation scaffold for NetKingdom's immune-architecture work.

Layer: Staff (NetKingdom Security Layer Model v0.7). kings-guard publishes posture and requests bounded response through engine APIs; it never touches Tooling directly and never renders an authorization decision. It proposes containment and does not perform it.

Current slice

This repository now contains four aligned pieces:

  • INTENT.md / SCOPE.md for the repo's stable boundary
  • specs/NetKingdomImmuneArchitecture.md for the reference architecture
  • specs/ImmuneContracts.md for the first canonical contract layer
  • src/kings_guard/ plus tests/ for a minimal posture loop scaffold

The current implementation is intentionally narrow. It does not enforce anything. It provides:

  • typed contracts for security genome, phenotype, observation, posture, signal, effector request, and immune memory entry;
  • evidence-class and stream-completeness fields, so silence is a finding and record richness is not mistaken for a complete stream;
  • a posture evaluator that judges one observation and, separately, the stream it came from;
  • a qonto-assistant pilot that still has a fixture regression case and can also consume real events from that service's own AuditLogger.

Repo layout

  • specs/NetKingdomImmuneArchitecture.md
  • specs/ImmuneContracts.md
  • docs/AdjacentSystemBoundary.md
  • docs/pilots/QontoAssistantPosturePilot.md
  • src/kings_guard/
  • tests/
  • workplans/

Dev commands

# preferred, if make + pip are available
make install-dev
make test
make lint
make run-demo

# direct shell fallback used in minimal environments
python3 -m pytest -q
PYTHONPATH=src python3 -m kings_guard.main --pilot qonto-assistant