kings-guard/history/2026-09-02-architecture-decision-point-audit.md
tegwick 824fb1b966 Complete KG-WP-0004-T05 and finish the architecture vocabulary sweep
Layer note is v0.7 Staff: propose containment, memory is not a state plane.
§6 audit lists every decision-shaped object; none is a Staff allow/deny.
Document version 0.2.0. KG-IN-0002 residual is closed.

Assistant: grok
Assistant-Session: 01a05ef1-9e5a-70f2-b0ff-0b05d6b38ae9
2026-09-02 10:06:53 +02:00

52 lines
3.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
title: "§6 audit — no Staff decision point in NetKingdomImmuneArchitecture.md"
date: 2026-09-02
repo: kings-guard
author: kings-guard
workplan: KG-WP-0004-T05
standard: net-kingdom/canon/standards/security-layer-model_v0.7.md
target: specs/NetKingdomImmuneArchitecture.md
status: complete
classification: Public
---
# §6 audit — no Staff decision point
After T02T04. Statute §6: `access-engine` is the only policy decision point.
No Staff component may render or cache allow/deny. This list is every
decision-shaped object from the T01 inventory §2.1, plus the §8/§9.6
artifacts T02 introduced, and where each now lives.
| Object | Lives now | Staff renders allow/deny? |
| --- | --- | --- |
| §5 lymph node / adaptive "decision" | Staff judgment / posture; policy generation is doctrine + PDP package | no |
| §8 former "Decision and Response Engine" | `access-engine` box in the Engine subgraph | no |
| §8 former Regulation controller | split: Staff proposals vs PDP/PEP | no |
| §9.2 `trust_posture` + `valid_until` | Staff publication; lifetime is an input claim to the PDP | no |
| §9.4 observation `assessment` / `proposed_response` | removed from the observation; phenotype/posture/signal | no |
| §9.5 `response authorization` signal | gone as a Staff type; PDP decision record | no |
| §9.6 `immune_decision` | Engine artifact, `pdp: access-engine` | no |
| §9.6 former `authority: tenant-immune-node` | `authority: access-engine`, `enforcement: pep` | no |
| §10 `TN → TR` | coordination; effectors fire on a decision record or recorded stance | no |
| §10.1 "local response decisions" | rewritten to proposals; decisions stay the one PDP | no |
| §14.1 fast local loop | PEP under existing policy / stance (qonto-assistant) | no — PEP, not Staff |
| §14.2 "select bounded response" | emit a bounded proposal | no |
| §15 VSM System 3 | `access-engine` + PEP stance maps | no |
| §16 isolate grant | issued to a PEP by `access-engine`, not to a Staff node | no |
| §19 `DECISION` entity | `access-engine` only; posture/signal sit in front | no |
| §20.2 policy decision reconstructability | PDP obligation | no |
| §22.2 decision latency | labelled PDP; Staff has judgment latency | no |
| §24 `immune-decision/` | replaced by `immune-judgment/` (Staff) | no |
| §25.1 Decision Contract | owned by `access-engine` | no |
| §25.2 `effector_request` | Staff proposal with origin; not a verdict | no |
| §27 former two-hop authorize | posture claim → PDP → PEP | no |
| §31 Phase 4 policy evaluation | recommendations; evaluation remains `access-engine` | no |
| §33 AD-003 | observe → judge → propose; decide/act are Engine/PEP | no |
| §34 Q2 autonomous authorization | recast as proposals + existing PEP stances | no |
| §36 sequence | names proposal, decision, unowned actuation | no |
No remaining object is a Staff allow/deny. Caching a verdict is not described
as a kings-guard behaviour. Actuation remains unowned (§9.2).
Control-plane grep after T03+T05: remaining hits are labelled Kubernetes /
platform API planes, or an explicit denial that kings-guard is not one.