kings-guard/.repo-manager/index.json
tegwick 3d6025ae51 Assent to Staff placement; release control-plane vocabulary (KG-IN-0001)
Answers gate-house intake KG-IN-0001 / GH-DEC-2026-001 against the
NetKingdom Security Layer Model v0.1.

Assent to all three points, recorded as KG-DEC-2026-001:
- kings-guard declares layer Staff in INTENT.md;
- "control plane" released to the Engine layer across INTENT, SCOPE,
  README, AGENTS and the adjacent-system boundary;
- the posture asymmetry adopted as a repo invariant — already satisfied,
  every EffectorRequest carries an explicit authority_boundary.

Boundary corrections: key-cape and OpenBao are Tooling, so their evidence
is routed through user-engine/access-engine and secrets-engine rather
than read directly.

Finding on the invited challenge to §5: do not weaken the binding rule,
but §4 catalogs kings-guard as owning containment while no engine exposes
a containment surface — the charter is currently undischargeable. Two
rulings requested of gate-house. Three engine gaps declared in INTENT.md.

Residual handed off as KG-IN-0002 (vocabulary sweep of the architecture
spec).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014379@bnt-lap001
Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
2026-08-28 21:47:05 +02:00

149 lines
6 KiB
JSON

{
"schema": "repo_manager.index.v1",
"slug": "layer-model-assent",
"repo_root": "/home/worsch/kings-guard",
"head_sha": "7c8ef38ee0603c4ca23e69abaff689b86da752b4",
"observed_at": "2026-08-28T19:30:17.391432Z",
"source_fingerprint": "ff379cda32bd3d625590480dbf164739c18022680a8390e4cd6a48514324cc5c",
"source_files": [
".repo-classification.yaml",
"INTENT.md",
"intakes/intakes.md",
"workplans/KG-WP-0001-statehub-bootstrap.md",
"workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md"
],
"work_records": [
{
"kind": "workplan",
"id": "KG-WP-0001",
"status": "finished",
"title": "Bootstrap State Hub integration",
"source_path": "workplans/KG-WP-0001-statehub-bootstrap.md",
"uuid": "b7ff79b9-ae27-4a46-a782-49482392eb83",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "KG-WP-0001-T01",
"status": "done",
"title": "Review Generated Integration Files",
"source_path": "workplans/KG-WP-0001-statehub-bootstrap.md",
"uuid": "add34171-9f18-48b9-a88e-07ea34cb6382",
"parent_id": "KG-WP-0001",
"extra": {}
},
{
"kind": "task",
"id": "KG-WP-0001-T02",
"status": "done",
"title": "Verify Local Developer Workflow",
"source_path": "workplans/KG-WP-0001-statehub-bootstrap.md",
"uuid": "17fb3a0c-91c5-4b45-967e-962ef6c89ac5",
"parent_id": "KG-WP-0001",
"extra": {}
},
{
"kind": "task",
"id": "KG-WP-0001-T03",
"status": "done",
"title": "Seed First Real Workplan",
"source_path": "workplans/KG-WP-0001-statehub-bootstrap.md",
"uuid": "5b5f56d9-7e89-43b6-94c3-db4461e9eed4",
"parent_id": "KG-WP-0001",
"extra": {}
},
{
"kind": "workplan",
"id": "KG-WP-0002",
"status": "finished",
"title": "Canonical immune contracts and first posture pilot",
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
"uuid": "5c5c5a26-dfca-4d42-86a7-b87877677207",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "KG-WP-0002-T01",
"status": "done",
"title": "Task: Define canonical immune contracts",
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
"uuid": "9982a3b4-1e65-493a-9b61-322f23d4fd2d",
"parent_id": "KG-WP-0002",
"extra": {}
},
{
"kind": "task",
"id": "KG-WP-0002-T02",
"status": "done",
"title": "Task: Write adjacent-system boundary contract",
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
"uuid": "0c44035e-b1b8-4f5d-8a6c-e6514b4bc897",
"parent_id": "KG-WP-0002",
"extra": {}
},
{
"kind": "task",
"id": "KG-WP-0002-T03",
"status": "done",
"title": "Task: Scaffold a minimal posture loop",
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
"uuid": "c88a7da6-a9ff-4bd9-ba47-7c199321666b",
"parent_id": "KG-WP-0002",
"extra": {}
},
{
"kind": "task",
"id": "KG-WP-0002-T04",
"status": "done",
"title": "Task: Choose and specify the first pilot lane",
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
"uuid": "77e1dc69-9902-4381-8028-ce1cfac7e9d5",
"parent_id": "KG-WP-0002",
"extra": {}
},
{
"kind": "intake",
"id": "KG-IN-0001",
"status": "open",
"title": "Assent requested: Staff layer placement, control-plane vocabulary, and the posture asymmetry",
"source_path": "intakes/intakes.md",
"uuid": null,
"parent_id": null,
"extra": {
"record": {
"id": "KG-IN-0001",
"kind": "intake",
"title": "Assent requested: Staff layer placement, control-plane vocabulary, and the posture asymmetry",
"status": "open",
"origin": "cross-repo",
"origin_ref": "gate-house GH-DEC-2026-001",
"priority": "medium",
"owner": "kings-guard",
"requested_by": "gate-house",
"standard": "net-kingdom/canon/standards/security-layer-model_v0.1.md",
"description": "gate-house asks kings-guard to assent to its placement in the NetKingdom security layer model. (1) kings-guard is Staff \u2014 agentic and non-deterministic \u2014 not an Engine. Acting at runtime does not make a repository an Engine; being agentic makes it Staff. (2) Consequently its self-description as an adaptive security control plane needs revisiting: control plane is Engine-layer vocabulary (standard section 8). This is not a demotion \u2014 it is the reason kings-guard may contain a threat only by calling an engine, never by reaching into OpenBao or a cluster directly (the binding rule, standard section 5: Staff never touches Tooling directly). (3) The posture contract with gate-house and its asymmetry: adaptive systems may reduce authority, require step-up, or request containment; they must never probabilistically manufacture additional authority. kings-guard publishes posture, gate-house defines its authority meaning, access-engine renders it. If the binding rule is impractical for containment in a real incident, say so \u2014 that is exactly the kind of finding that should change the doctrine rather than be worked around.",
"created": "2026-08-28T19:30:17.201213Z",
"updated": "2026-08-28T19:30:17.201213Z"
}
}
}
],
"events": [
{
"type": "repo.command.applied",
"command": "repo.work.create_intake",
"operation": "create",
"correlation_id": "f9b8b130-71f6-41b9-9f06-e28d2abda2d4",
"kind": "intake",
"id": "KG-IN-0001",
"git_sha": "7c8ef38ee0603c4ca23e69abaff689b86da752b4",
"files_touched": [
"intakes/intakes.md"
],
"source": "repo-manager",
"emitted_at": "2026-08-28T19:30:17.391507Z"
}
]
}