Accept the security layer model; companion v0.2 to the repository root
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

The standard is accepted at v0.7 on the owner's decision. §14 keeps two things
apart, as ops-warden asked: boundary assent, given by four repositories at the
version named in each record and undisturbed since; and revision review, where
all four reviewed v0.6 and every change in v0.7 is the adopted remedy of a
finding they raised. What is not claimed: nobody has reviewed v0.7 as text.

Accepting a standard nobody has re-read is deliberate. The estate will learn
more from using it than from another round of prose, and the v0.7 changes were
requested rather than invented. Findings against the accepted text stay
welcome — that is §12's normal business, not an exception.

The companion moves from canon/standards to the repository root as
SECURITY-COMPANION.md and becomes v0.2, so onboarding starts at the front door
rather than three directories down. One copy, not two: a second copy of a fact
is how the estate gets two sources for it.

v0.2 closes the gap access-engine found in v0.1 — it said publish your stance
map without saying where, and omitted the inventory obligation, so a repository
could satisfy it faithfully and no register would learn of its stance. It also
carries what v0.7 added: the corrected PEP obligations, the evidence threat
decomposition with its stated residual, cadence as MUST for load-bearing
sources with heartbeat for rare ones, the four agent rules and the glas-harness
seam, and the Railiance axes with their unsettled mapping.

It points readers at ops-warden for how to get things done. The companion says
what the rules are; ops-warden stewards the paths through them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
This commit is contained in:
tegwick 2026-08-29 11:28:49 +02:00
parent ce2554fdc9
commit 66dc491dc0
4 changed files with 246 additions and 214 deletions

View file

@ -3,7 +3,7 @@ id: netkingdom-security-layer-model-v0.7
type: standard
title: "NetKingdom Security Layer Model v0.7"
domain: netkingdom
status: proposed
status: accepted
version: "0.7"
supersedes: canon/standards/security-layer-model_v0.6.md
owner: gate-house
@ -986,9 +986,21 @@ do while the register is nearly empty.
## 14. Adoption
Status is **proposed** — the frontmatter is authoritative, and v0.2 was the last
version to reach `accepted`. Four repositories have assented, each with a record,
and all four returned findings on the versions since:
Status is **accepted**, on the owner's decision of 2026-08-29.
Two things that acceptance does and does not mean, kept apart because
`ops-warden` asked for the distinction:
| | |
| --- | --- |
| **Boundary assent** | given by the four repositories below, at the version named in each record, and undisturbed since |
| **Revision review** | each of the four reviewed v0.6 and returned findings; **every change in v0.7 is the adopted remedy of a finding they raised** |
| **Not claimed** | no repository has reviewed v0.7 *as text*. The first revision review will confirm or correct it |
Accepting a standard nobody has re-read is a deliberate call: the estate learns
more from using it than from another round of prose refinement, and the changes
in v0.7 were requested rather than invented. Findings against the accepted text
remain welcome and are §12's normal business, not an exception.
| Repository | Record | Outcome |
| --- | --- | --- |
@ -1218,14 +1230,11 @@ v0.3 → v0.4:
text it grades. Raised by `access-engine`. Its two substantive points remain
live: observation in production is unstaffed (§12) and actuation has no surface
(§9.2).
- The **agent companion** (`security-layer-model-companion_v0.1.md`) is the
operative form of this statute. The statute governs on disagreement, and a
disagreement is a finding. Its §5.3 omits where a stance map is published and
omits the §6.4 inventory obligation entirely — a repository could satisfy the
companion faithfully, publish into its own repo, believe itself conforming, and
no register would learn of it. Raised by `access-engine` in answer to the
question of what would show the companion insufficient. To be fixed in
companion v0.2.
- The **working companion** (`net-kingdom/SECURITY-COMPANION.md`, v0.2, root of
the repository for onboarding) is the operative form of this statute. The statute governs on disagreement, and a
disagreement is a finding. The v0.1 gap `access-engine` found — publish
your stance map, but nowhere saying where, and no inventory obligation — is
fixed in v0.2 §5.3.
- How the Railiance operational axes meet this model beyond §20's first
statement, which is deliberately minimal.