Security Layer Model v0.2 — accepted
All three repositories whose boundaries moved assented, each with a decision record (flex-auth FLEX-DEC-2026-001, kings-guard KG-DEC-2026-001, ops-warden ADR-0010), and each returned a finding. v0.2 carries the results and is accepted; v0.1 is marked superseded and retained because the twelve estate INTENT review notes cite it. - §5 restructured into three sanctioned shapes: read-only diagnostics, conduit (ops-warden's question, ruled), and declared engine gap (ops-warden's amendment, accepted). v0.1 offered only the first, which is narrower than the estate as it stands — a rule with no lane for a real sanctioned case gets satisfied by relabelling rather than by closing the gap. - §6.2 added: doctrine must reach the decision as an input claim or a versioned policy rule. This is §6.1 applied to gate-house on the same terms it applies to engines, drawn back by flex-auth. - §9 added: the catalog may not assign a capability the rules forbid discharging. Containment marked pending an engine surface; degraded-mode fallback ruled into access-engine rather than Staff. - §11: conformance now has three states, distinguishing a tracked gap from an undeclared violation. - §12 made normative, stating that an unsatisfiability finding is a success of the conformance loop. - §13 added: open gaps register, including the unowned approval storage and lifecycle capability — recorded, deliberately not assigned. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
parent
c42086d475
commit
27a31f3f8f
3 changed files with 406 additions and 2 deletions
|
|
@ -3,7 +3,7 @@ id: netkingdom-security-layer-model-v0.1
|
|||
type: standard
|
||||
title: "NetKingdom Security Layer Model v0.1"
|
||||
domain: netkingdom
|
||||
status: proposed
|
||||
status: superseded
|
||||
version: "0.1"
|
||||
owner: gate-house
|
||||
publication_owner: net-kingdom
|
||||
|
|
@ -13,6 +13,7 @@ last_reviewed: "2026-08-28"
|
|||
review_interval: 3m
|
||||
source_revision: "gate-house@7f13f72"
|
||||
standard_token: security-layer-model_v0.1
|
||||
superseded_by: canon/standards/security-layer-model_v0.2.md
|
||||
related:
|
||||
- canon/standards/security-zones_v0.1.md
|
||||
- canon/standards/tenancy-posture_v0.1.md
|
||||
|
|
@ -25,6 +26,13 @@ related:
|
|||
|
||||
# NetKingdom Security Layer Model v0.1
|
||||
|
||||
> **Superseded 2026-08-28 by [v0.2](security-layer-model_v0.2.md).** All three
|
||||
> repositories whose boundaries moved assented to this version and each returned
|
||||
> a finding; v0.2 carries the results. Retained because the twelve estate
|
||||
> `INTENT.md` review notes cite this file. Read v0.2 for the current rules —
|
||||
> §5 (sanctioned shapes), §6.2 (doctrine as input), and §9 (capability
|
||||
> assignment) changed materially.
|
||||
|
||||
## 1. Purpose
|
||||
|
||||
This standard states how NetKingdom's IT-security estate is layered, and what
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue