Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014379@bnt-lap001 Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
71 lines
3.5 KiB
Markdown
71 lines
3.5 KiB
Markdown
# Intake records
|
|
|
|
## KG-IN-0001 — Assent requested: Staff layer placement, control-plane vocabulary, and the posture asymmetry
|
|
|
|
```yaml
|
|
id: KG-IN-0001
|
|
kind: intake
|
|
title: 'Assent requested: Staff layer placement, control-plane vocabulary, and the
|
|
posture asymmetry'
|
|
status: closed
|
|
outcome: absorbed
|
|
promoted_to: KG-DEC-2026-001
|
|
origin: cross-repo
|
|
origin_ref: gate-house GH-DEC-2026-001
|
|
priority: medium
|
|
owner: kings-guard
|
|
requested_by: gate-house
|
|
standard: net-kingdom/canon/standards/security-layer-model_v0.1.md
|
|
description: 'gate-house asks kings-guard to assent to its placement in the NetKingdom
|
|
security layer model. (1) kings-guard is Staff — agentic and non-deterministic —
|
|
not an Engine. Acting at runtime does not make a repository an Engine; being agentic
|
|
makes it Staff. (2) Consequently its self-description as an adaptive security control
|
|
plane needs revisiting: control plane is Engine-layer vocabulary (standard section
|
|
8). This is not a demotion — it is the reason kings-guard may contain a threat only
|
|
by calling an engine, never by reaching into OpenBao or a cluster directly (the
|
|
binding rule, standard section 5: Staff never touches Tooling directly). (3) The
|
|
posture contract with gate-house and its asymmetry: adaptive systems may reduce
|
|
authority, require step-up, or request containment; they must never probabilistically
|
|
manufacture additional authority. kings-guard publishes posture, gate-house defines
|
|
its authority meaning, access-engine renders it. If the binding rule is impractical
|
|
for containment in a real incident, say so — that is exactly the kind of finding
|
|
that should change the doctrine rather than be worked around.'
|
|
created: '2026-08-28T19:30:17.201213Z'
|
|
updated: '2026-08-28T19:30:17.201213Z'
|
|
closed: '2026-08-28'
|
|
resolution: 'Assent with finding. All three points assented and adopted in
|
|
INTENT.md, SCOPE.md, README.md, AGENTS.md, and docs/AdjacentSystemBoundary.md.
|
|
The invited challenge to the binding rule was taken up and answered: do not
|
|
weaken section 5 — but section 4 catalogs kings-guard as owning containment
|
|
while no engine exposes a containment surface, so the charter is currently
|
|
undischargeable. Two rulings requested of gate-house. Full record:
|
|
decisions/decisions.md KG-DEC-2026-001. Vocabulary sweep of the architecture
|
|
spec handed off as KG-IN-0002.'
|
|
state_hub_intake_id: "01a049ea-2e37-7dde-9772-fab7e788d8d7"
|
|
```
|
|
|
|
## KG-IN-0002 — Sweep "control plane" and layer vocabulary through NetKingdomImmuneArchitecture.md
|
|
|
|
```yaml
|
|
id: KG-IN-0002
|
|
kind: intake
|
|
title: Sweep "control plane" and layer vocabulary through NetKingdomImmuneArchitecture.md
|
|
status: open
|
|
origin: residual
|
|
origin_ref: KG-DEC-2026-001
|
|
priority: low
|
|
owner: kings-guard
|
|
standard: net-kingdom/canon/standards/security-layer-model_v0.1.md
|
|
description: 'specs/NetKingdomImmuneArchitecture.md (approx. 1900 lines) predates the
|
|
NetKingdom Security Layer Model and uses "control plane" in several places —
|
|
including a "Platform Immune Control Plane" subgraph — where the layer model
|
|
reserves that vocabulary for the Engine layer. A scoping note now sits at the head
|
|
of the document so no reading takes it as a kings-guard self-description, but the
|
|
body is not adapted. Sweep it: separate the components that are engine-layer
|
|
authorities from the observation-and-judgment surface kings-guard actually owns,
|
|
and check that no part of the architecture places a decision point in Staff
|
|
(layer model section 6).'
|
|
created: '2026-08-28'
|
|
updated: '2026-08-28'
|
|
state_hub_intake_id: "01a049ea-3a04-74b9-a9b1-e2630f8d5628"
|
|
```
|