Layer note is v0.7 Staff: propose containment, memory is not a state plane. §6 audit lists every decision-shaped object; none is a Staff allow/deny. Document version 0.2.0. KG-IN-0002 residual is closed. Assistant: grok Assistant-Session: 01a05ef1-9e5a-70f2-b0ff-0b05d6b38ae9
3.1 KiB
3.1 KiB
| title | date | repo | author | workplan | standard | target | status | classification |
|---|---|---|---|---|---|---|---|---|
| §6 audit — no Staff decision point in NetKingdomImmuneArchitecture.md | 2026-09-02 | kings-guard | kings-guard | KG-WP-0004-T05 | net-kingdom/canon/standards/security-layer-model_v0.7.md | specs/NetKingdomImmuneArchitecture.md | complete | Public |
§6 audit — no Staff decision point
After T02–T04. Statute §6: access-engine is the only policy decision point.
No Staff component may render or cache allow/deny. This list is every
decision-shaped object from the T01 inventory §2.1, plus the §8/§9.6
artifacts T02 introduced, and where each now lives.
| Object | Lives now | Staff renders allow/deny? |
|---|---|---|
| §5 lymph node / adaptive "decision" | Staff judgment / posture; policy generation is doctrine + PDP package | no |
| §8 former "Decision and Response Engine" | access-engine box in the Engine subgraph |
no |
| §8 former Regulation controller | split: Staff proposals vs PDP/PEP | no |
§9.2 trust_posture + valid_until |
Staff publication; lifetime is an input claim to the PDP | no |
§9.4 observation assessment / proposed_response |
removed from the observation; phenotype/posture/signal | no |
§9.5 response authorization signal |
gone as a Staff type; PDP decision record | no |
§9.6 immune_decision |
Engine artifact, pdp: access-engine |
no |
§9.6 former authority: tenant-immune-node |
authority: access-engine, enforcement: pep |
no |
§10 TN → TR |
coordination; effectors fire on a decision record or recorded stance | no |
| §10.1 "local response decisions" | rewritten to proposals; decisions stay the one PDP | no |
| §14.1 fast local loop | PEP under existing policy / stance (qonto-assistant) | no — PEP, not Staff |
| §14.2 "select bounded response" | emit a bounded proposal | no |
| §15 VSM System 3 | access-engine + PEP stance maps |
no |
| §16 isolate grant | issued to a PEP by access-engine, not to a Staff node |
no |
§19 DECISION entity |
access-engine only; posture/signal sit in front |
no |
| §20.2 policy decision reconstructability | PDP obligation | no |
| §22.2 decision latency | labelled PDP; Staff has judgment latency | no |
§24 immune-decision/ |
replaced by immune-judgment/ (Staff) |
no |
| §25.1 Decision Contract | owned by access-engine |
no |
§25.2 effector_request |
Staff proposal with origin; not a verdict | no |
| §27 former two-hop authorize | posture claim → PDP → PEP | no |
| §31 Phase 4 policy evaluation | recommendations; evaluation remains access-engine |
no |
| §33 AD-003 | observe → judge → propose; decide/act are Engine/PEP | no |
| §34 Q2 autonomous authorization | recast as proposals + existing PEP stances | no |
| §36 sequence | names proposal, decision, unowned actuation | no |
No remaining object is a Staff allow/deny. Caching a verdict is not described as a kings-guard behaviour. Actuation remains unowned (§9.2).
Control-plane grep after T03+T05: remaining hits are labelled Kubernetes / platform API planes, or an explicit denial that kings-guard is not one.