diff --git a/workplans/NK-WP-0027-reef-placement-reconciliation.md b/workplans/NK-WP-0027-reef-placement-reconciliation.md index dc492b6..c880c77 100644 --- a/workplans/NK-WP-0027-reef-placement-reconciliation.md +++ b/workplans/NK-WP-0027-reef-placement-reconciliation.md @@ -172,9 +172,11 @@ state_hub_task_id: "d60e209d-3090-59e7-afc4-0a3780507403" applications.** In the `security-zones_v0.1` publication review, require a stable workload identity and responsible party for operational/control-plane units, and a machine-readable join from credential/control resources to the -workload they serve. Do not require `rapp` packaging merely to gain identity, -and do not infer the join from path strings or repository ownership. Coordinate -the declaration boundary with `zone-engine`, `repo-manager`, and the affected +workload they serve. Require the authoritative rapp declaration for managed +deployables, but do not invent a workload or rapp for native non-workload +subjects or independently governed units that are not managed deployables. Do +not infer the join from path strings or repository ownership. Coordinate the +declaration boundary with `zone-engine`, `repo-manager`, and the affected control owners. **Done 2026-08-22.** Tenancy Posture draft-12 Decision 5.6.2 and its schema now