feat(posture): add deterministic feedback proposals
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
This commit is contained in:
parent
dc8da422f8
commit
cfc9e7d0cb
19 changed files with 1428 additions and 16 deletions
|
|
@ -145,3 +145,13 @@ deterministic provider pins, trust ordering, responsibility mapping, and
|
|||
readiness handoff without executing provider actions. G1 remains open for the
|
||||
lightweight SSO path until the KeyCape/Railiance owners publish conformant C1
|
||||
and C2 declarations.
|
||||
|
||||
NK-WP-0031 subsequently implemented the first bounded G2 increment: proposed
|
||||
Posture Feedback v0.1 canon and a deterministic evaluator that turns explicit
|
||||
review dates, evidence freshness, implemented-but-unevidenced controls, and
|
||||
declared gaps into owner-routed remediation proposals. Time is an explicit
|
||||
input; missing ownership or freshness resolves to `unknown`; and the report
|
||||
forbids external, declaration, and policy writes. G2 remains open because the
|
||||
tool does not create work, change policy, close remediation, or consume runtime
|
||||
telemetry autonomously. Those powers require separate authority, rollback, and
|
||||
review decisions.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue