Answers gate-house intake KG-IN-0001 / GH-DEC-2026-001 against the NetKingdom Security Layer Model v0.1. Assent to all three points, recorded as KG-DEC-2026-001: - kings-guard declares layer Staff in INTENT.md; - "control plane" released to the Engine layer across INTENT, SCOPE, README, AGENTS and the adjacent-system boundary; - the posture asymmetry adopted as a repo invariant — already satisfied, every EffectorRequest carries an explicit authority_boundary. Boundary corrections: key-cape and OpenBao are Tooling, so their evidence is routed through user-engine/access-engine and secrets-engine rather than read directly. Finding on the invited challenge to §5: do not weaken the binding rule, but §4 catalogs kings-guard as owning containment while no engine exposes a containment surface — the charter is currently undischargeable. Two rulings requested of gate-house. Three engine gaps declared in INTENT.md. Residual handed off as KG-IN-0002 (vocabulary sweep of the architecture spec). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014379@bnt-lap001 Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
149 lines
6 KiB
JSON
149 lines
6 KiB
JSON
{
|
|
"schema": "repo_manager.index.v1",
|
|
"slug": "layer-model-assent",
|
|
"repo_root": "/home/worsch/kings-guard",
|
|
"head_sha": "7c8ef38ee0603c4ca23e69abaff689b86da752b4",
|
|
"observed_at": "2026-08-28T19:30:17.391432Z",
|
|
"source_fingerprint": "ff379cda32bd3d625590480dbf164739c18022680a8390e4cd6a48514324cc5c",
|
|
"source_files": [
|
|
".repo-classification.yaml",
|
|
"INTENT.md",
|
|
"intakes/intakes.md",
|
|
"workplans/KG-WP-0001-statehub-bootstrap.md",
|
|
"workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md"
|
|
],
|
|
"work_records": [
|
|
{
|
|
"kind": "workplan",
|
|
"id": "KG-WP-0001",
|
|
"status": "finished",
|
|
"title": "Bootstrap State Hub integration",
|
|
"source_path": "workplans/KG-WP-0001-statehub-bootstrap.md",
|
|
"uuid": "b7ff79b9-ae27-4a46-a782-49482392eb83",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "KG-WP-0001-T01",
|
|
"status": "done",
|
|
"title": "Review Generated Integration Files",
|
|
"source_path": "workplans/KG-WP-0001-statehub-bootstrap.md",
|
|
"uuid": "add34171-9f18-48b9-a88e-07ea34cb6382",
|
|
"parent_id": "KG-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "KG-WP-0001-T02",
|
|
"status": "done",
|
|
"title": "Verify Local Developer Workflow",
|
|
"source_path": "workplans/KG-WP-0001-statehub-bootstrap.md",
|
|
"uuid": "17fb3a0c-91c5-4b45-967e-962ef6c89ac5",
|
|
"parent_id": "KG-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "KG-WP-0001-T03",
|
|
"status": "done",
|
|
"title": "Seed First Real Workplan",
|
|
"source_path": "workplans/KG-WP-0001-statehub-bootstrap.md",
|
|
"uuid": "5b5f56d9-7e89-43b6-94c3-db4461e9eed4",
|
|
"parent_id": "KG-WP-0001",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "workplan",
|
|
"id": "KG-WP-0002",
|
|
"status": "finished",
|
|
"title": "Canonical immune contracts and first posture pilot",
|
|
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
|
|
"uuid": "5c5c5a26-dfca-4d42-86a7-b87877677207",
|
|
"parent_id": null,
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "KG-WP-0002-T01",
|
|
"status": "done",
|
|
"title": "Task: Define canonical immune contracts",
|
|
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
|
|
"uuid": "9982a3b4-1e65-493a-9b61-322f23d4fd2d",
|
|
"parent_id": "KG-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "KG-WP-0002-T02",
|
|
"status": "done",
|
|
"title": "Task: Write adjacent-system boundary contract",
|
|
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
|
|
"uuid": "0c44035e-b1b8-4f5d-8a6c-e6514b4bc897",
|
|
"parent_id": "KG-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "KG-WP-0002-T03",
|
|
"status": "done",
|
|
"title": "Task: Scaffold a minimal posture loop",
|
|
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
|
|
"uuid": "c88a7da6-a9ff-4bd9-ba47-7c199321666b",
|
|
"parent_id": "KG-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "task",
|
|
"id": "KG-WP-0002-T04",
|
|
"status": "done",
|
|
"title": "Task: Choose and specify the first pilot lane",
|
|
"source_path": "workplans/KG-WP-0002-canonical-immune-contracts-and-posture-pilot.md",
|
|
"uuid": "77e1dc69-9902-4381-8028-ce1cfac7e9d5",
|
|
"parent_id": "KG-WP-0002",
|
|
"extra": {}
|
|
},
|
|
{
|
|
"kind": "intake",
|
|
"id": "KG-IN-0001",
|
|
"status": "open",
|
|
"title": "Assent requested: Staff layer placement, control-plane vocabulary, and the posture asymmetry",
|
|
"source_path": "intakes/intakes.md",
|
|
"uuid": null,
|
|
"parent_id": null,
|
|
"extra": {
|
|
"record": {
|
|
"id": "KG-IN-0001",
|
|
"kind": "intake",
|
|
"title": "Assent requested: Staff layer placement, control-plane vocabulary, and the posture asymmetry",
|
|
"status": "open",
|
|
"origin": "cross-repo",
|
|
"origin_ref": "gate-house GH-DEC-2026-001",
|
|
"priority": "medium",
|
|
"owner": "kings-guard",
|
|
"requested_by": "gate-house",
|
|
"standard": "net-kingdom/canon/standards/security-layer-model_v0.1.md",
|
|
"description": "gate-house asks kings-guard to assent to its placement in the NetKingdom security layer model. (1) kings-guard is Staff \u2014 agentic and non-deterministic \u2014 not an Engine. Acting at runtime does not make a repository an Engine; being agentic makes it Staff. (2) Consequently its self-description as an adaptive security control plane needs revisiting: control plane is Engine-layer vocabulary (standard section 8). This is not a demotion \u2014 it is the reason kings-guard may contain a threat only by calling an engine, never by reaching into OpenBao or a cluster directly (the binding rule, standard section 5: Staff never touches Tooling directly). (3) The posture contract with gate-house and its asymmetry: adaptive systems may reduce authority, require step-up, or request containment; they must never probabilistically manufacture additional authority. kings-guard publishes posture, gate-house defines its authority meaning, access-engine renders it. If the binding rule is impractical for containment in a real incident, say so \u2014 that is exactly the kind of finding that should change the doctrine rather than be worked around.",
|
|
"created": "2026-08-28T19:30:17.201213Z",
|
|
"updated": "2026-08-28T19:30:17.201213Z"
|
|
}
|
|
}
|
|
}
|
|
],
|
|
"events": [
|
|
{
|
|
"type": "repo.command.applied",
|
|
"command": "repo.work.create_intake",
|
|
"operation": "create",
|
|
"correlation_id": "f9b8b130-71f6-41b9-9f06-e28d2abda2d4",
|
|
"kind": "intake",
|
|
"id": "KG-IN-0001",
|
|
"git_sha": "7c8ef38ee0603c4ca23e69abaff689b86da752b4",
|
|
"files_touched": [
|
|
"intakes/intakes.md"
|
|
],
|
|
"source": "repo-manager",
|
|
"emitted_at": "2026-08-28T19:30:17.391507Z"
|
|
}
|
|
]
|
|
}
|