diff --git a/canon/standards/security-layer-model_v0.8.md b/canon/standards/security-layer-model_v0.8.md index 8061b8a..392b11c 100644 --- a/canon/standards/security-layer-model_v0.8.md +++ b/canon/standards/security-layer-model_v0.8.md @@ -1319,6 +1319,7 @@ register distinguishes proposed from assented. | Stance-map register had no implementation | declared-contact | ops-warden, access-engine | gate-house | resolved in §13.1 | | Registry-snapshot digest in decision provenance | declared-contact | flex-auth | flex-auth | self-declared | | Decision-record authenticity — a PEP cannot attribute a decision to `access-engine` (§6.4 obligation 1); unsigned envelope, plain-HTTP pins | declared-contact | flex-auth | flex-auth | self-declared (`FLEX-DEC-2026-010`, `FLEX-WP-0024`) | +| Human principal's tenant is unresolvable from the directory, so a client registration supplies it (`GH-DEC-2026-013`) | declared-contact | key-cape | directory adapter — unnamed | proposed | | Approval storage and lifecycle | — | flex-auth | approval-engine | assigned (§9.4) | | Approval evidence | — | gate-house | audit-core | **assented** (`AUDIT-IN-0001`) | | Approval evidence custody stronger than the shipped bound — WORM, object lock, transparency log | unowned-capability | audit-core | — | unassigned |