--- id: NK-WP-0035 type: workplan title: "Publish the NetKingdom emission-cadence security profile" domain: infotech repo: net-kingdom status: blocked owner: codex topic_slug: netkingdom planning_priority: P1 created: "2026-09-04" updated: "2026-09-05" related: - GH-DEC-2026-004 - canon/standards/security-layer-model_v0.7.md --- # NK-WP-0035 — NetKingdom emission-cadence security profile GH-DEC-2026-004 assigns the ecosystem-wide `EmissionCadenceDeclaration` contract to `info-tech-canon` and the importing NetKingdom security profile to this repository. This work accepts that split. It must not copy the generic schema drafted by `kings-guard` or make the observer the owner of source classifications. ## Define the importing security profile ```task id: NK-WP-0035-T01 status: done priority: high ``` Publish the NetKingdom MUST/SHOULD obligations over the generic contract: load-bearing classes declare cadence, attributive classes should, and rare load-bearing classes use heartbeat plus reconciliation with rate monitoring forbidden. Keep source classification owner-authored and preserve the residual that cadence detects omission only after the fact. Implemented as proposed canon at `canon/standards/emission-cadence-security-profile_v0.1.md`. The profile accepts the GH-DEC-2026-004 split, requires source-owned classification, distinguishes MUST from SHOULD coverage, and records that omission detection is after the fact rather than proof of completeness. ## Implement mechanical profile validation ```task id: NK-WP-0035-T02 status: done priority: high ``` Validate a declaration against an explicitly supplied InfoTechCanon JSON Schema before applying the NetKingdom overlay. The checker must not ship a fallback generic schema, infer evidence class or rarity from event contents, or treat a SHOULD finding as a MUST failure by default. Implemented at `tools/emission-cadence-profile/emission_cadence_profile.py`. It requires `--contract-schema`, performs generic validation first, then checks the NetKingdom overlay against caller-supplied source inventory assertions. No generic fallback schema or owner declaration instance was added here. ## Verify the boundary and failure cases ```task id: NK-WP-0035-T03 status: done priority: medium ``` Cover contract-first validation, missing and mismatched class declarations, the allowed high-volume load-bearing rate form, the forbidden rare-event rate form, both positive controls for rare load-bearing classes, duplicate classes, and advisory attributive coverage. Verification on 2026-09-04: eight focused tests pass; the 81-test root `tests/` + `tools/` regression suite passes; Ruff lint and format checks pass; Python compilation and `git diff --check` pass. ## Bind and hand off the published contract ```task id: NK-WP-0035-T04 status: wait priority: high ``` When `info-tech-canon` publishes its versioned contract and schema, replace the pending import locator with its canonical coordinates and digest, validate the owner-source instances, and notify `kings-guard` to replace its draft-shaped fixture. This task cannot be completed from NetKingdom without the upstream artifact and must not be worked around by copying the draft. 2026-09-05 review: the upstream publication blocker is resolved by InfoTechCanon 0.7.0 / contract 0.1.0. Bound the profile to the schema coordinates, revision and SHA-256; fixed the checker to read `extensions.netkingdom`, removed draft reconciliation aliases, and enforced unique source IDs. Fifteen focused tests pass, including direct integration with the published owner schema and CLI exit-policy coverage. The current owner instances (`approval-engine/cadence.yaml` and `qonto-assistant/specs/audit-emission-cadence.yaml`) were reviewed and checked; both still fail generic contract validation because they use draft envelopes. No source instance was rewritten by NetKingdom. T04 remains `wait` for each owner's migration and subsequent profile validation, followed by the King's Guard handoff. The profile remains proposed. Validation: `python3 -m pytest tests tools -q` passed 106 tests, including 18 privacyIDEA and 15 cadence cases. Ruff lint/format, shell syntax, embedded Python compilation and `git diff --check` passed. State Hub reconciliation was attempted with both the installed CLI and current checkout. Full reconciliation remains pending because API queries/writes timed out or returned connection-refused errors. Generated index/intake metadata was reviewed; the source files remain authoritative.