kings-guard/SCOPE.md

69 lines
2.2 KiB
Markdown

# SCOPE
> Lightweight boundary for agents and contributors.
---
## One-liner
Adaptive security assessment and bounded-response layer for multi-tenant cloud
platforms.
---
## Core Idea
`kings-guard` turns declared healthy intent plus observed runtime behavior into
posture judgments, typed security signals, and bounded response requests. It
consumes evidence from identity, authorization, secret, and runtime systems
without replacing those systems' primary authority.
---
## In Scope
- Canonical terminology and contracts for security genome, phenotype,
observation, signal, effector, tolerance, inflammation, and immune memory.
- Reference architecture and boundary documents for adaptive defense in
multi-tenant and agent-active environments.
- Minimal posture-evaluation loop design: ingest observations, compare against
intended healthy state, and emit typed posture/signal results.
- Integration seams to adjacent security systems such as `key-cape`,
`flex-auth`, `secrets-engine`, `ops-warden`, and the Railiance runtime
layers.
- Non-secret evidence, workplans, and repo-operational metadata.
---
## Out of Scope
- Identity issuance, login, MFA, or token minting.
- Authorization policy administration or final resource allow/deny decisions.
- Secret custody, lease issuance, or raw secret-value delivery.
- Infrastructure provisioning, workload deployment, or cluster/platform
operations.
- Generic SIEM ownership, ticket tracking, or live work coordination beyond
this repo's own workplans.
---
## Current State
- Canon now includes `specs/ImmuneContracts.md`,
`docs/AdjacentSystemBoundary.md`, and
`docs/pilots/QontoAssistantPosturePilot.md`.
- A minimal Python reference scaffold exists under `src/kings_guard/` with
fixture-driven tests under `tests/`.
- The implementation currently evaluates normalized observations and emits
posture/signal results for one bounded pilot lane; it is not yet a running
control plane or integrated enforcement service.
---
## Getting Oriented
- Start with: `INTENT.md`
- Architecture draft: `specs/NetKingdomImmuneArchitecture.md`
- Exploration notes: `history/InitialExploration.md`
- Agent instructions: `AGENTS.md`
- Workplans: `workplans/`