net-kingdom/history/2026-08-29-layering-standard-assessment.md
tegwick 745dffb8ac Security Layer Model v0.6 — type the engines, name the gate, hold actuation at zero
From the independent assessment of 2026-08-29, which found the model sound as a
layering constitution and incomplete as a self-healing one: cognition,
authority, and execution are specified, but the two verbs that close a healing
loop — observe in production, actuate through a deterministic surface — are
pending, and one is unstaffed.

Section numbers below §14 are unchanged; the estate cites them.

- §3.3 types the Engine layer: PDP, PIP, Evidence, Lifecycle, with a role column
  in §4. Collapsing them hid different failure modes — a PIP outage is input
  degradation, a PDP outage is consumer residue, an evidence-plane outage must
  not block the operation it records. A new engine is a PIP unless amended.
- §6.4 names the enforcement point. The standard was precise about the decision
  and silent about the gate, so enforcement lived in Staff runbooks. Four
  obligations: no side effect without a decision record, no local recaching of
  the verdict, a declared unreachable-engine stance, reconstructability.
- §9.2 replaced. Containment was marked pending against kings-guard, the right
  mark on the wrong repository: reduce, step-up, and isolate are
  authority-changing operations, so they are rendered by an Engine and enforced
  by a PEP. Actuation is an unowned Engine concept held at zero. Staff proposes
  containment and never performs it.
- §3.4 separates human and agent principals inside Staff — same permissions,
  different blast radius. No standing credential, conduit or engine API only,
  agent memory is not a state plane, every action reconstructable as the
  caller's.
- §9.7 puts time into the model: explicit lifetimes, revocation visibility
  deadlines, consumption as a state change never inferred from a decision
  record, and the three race modes named. §9.8 states what holds under
  partition.
- §17 requires the Taxonomy artifacts — claim, decision-record, gap-record, and
  emission-cadence schemas — without which §6.2 and §11 are reviewable but not
  compileable. Ownership proposed, not assigned.
- §18 composes the sibling standards, which had been cited in frontmatter and
  nowhere in the rules.
- §5 sunsets the uncatalogued-infrastructure carve-out. §5.3 declines a proposed
  fourth "operator of third-party Tooling" shape: it would convert a tracked gap
  into a permanent allowance, which is the relabelling failure this standard
  exists to prevent.
- §10 gains the six artifacts a layer change must carry, written from the
  zone-engine case, including a permission freeze during the cut.
- §2 lifts the observation rule so it cannot be lost in a summary. §13 separates
  its three normative rules from the table, now a snapshot due to move into
  maturity-engine. §16 decides the approval custody question: no. §19 records
  the fitness verdict.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 03:32:58 +02:00

20 KiB
Raw Permalink Blame History

Task

I am exploring a dynamic, self healing and evolving it-security framework framework and the provided document is a layering model for it. Please review it intensely and provide a SWOT style analyses along with gaps you might see and a list of improvements to improve the framework layering model.

Document: security-layer-model_v0.5.md

Result

This is an unusually tight layering standard. It is not a Zero Trust slide deck and it is not an org chart. It is a repository constitution: determinism vs. non-determinism, one policy decision point, and an honest account of what audit evidence can and cannot prove. That last point is rarer than most security frameworks admit.

The analysis below treats v0.5 as a living constitution for a self-healing security estate, not as a finished product.


What the model actually is

Four layers, split by what they produce and whether the same inputs yield the same outputs:

Layer Job Deterministic?
Taxonomy Shared language and standards n/a
Tooling State and infrastructure yes
Engines Concept APIs; every enforcement boundary yes
Staff Judgment, ops, agents, change no

The load-bearing rules are:

  1. Staff never touches catalogued Tooling except as a declared diagnostic, a no-authority conduit, or a tracked gap.
  2. access-engine is the only policy decision point. Doctrine that affects an outcome must arrive as a request claim or a versioned policy rule.
  3. Adaptive systems may tighten authority. They may never manufacture it.
  4. An append-only archive proves alteration and truncation after arrival. It does not prove a source emitted the event. Absence is not non-occurrence.

That is a stronger epistemic stance than most “immutable audit log” claims.


SWOT

Strengths

Determinism as the layer cut. Most estates slice by network tier, team, or cloud account. This one slices by whether a component is allowed to judge. That is the right cut for an agentic Staff layer. A repository that infers is Staff even if it runs 24/7.

Single PDP, written as an invariant rather than a preference. §6 and §6.1 close the usual failure mode: a cache, registry, or compiled maturity level that decides early. That is the same failure NIST ZTA and XACML architectures spend a lot of ink on, and most estates still ship it as “just a lookup.”

Conformance that does not punish restraint. blocked-clean vs declared-gap vs undeclared violation is the best part of the standard. A repository that left a capability at zero is not graded below one that opened a quiet client. That is how you stop the model from being gamed by relabelling.

Evidence doctrine that matches physics. §9.6 plus the load-bearing / attributive split is estate-grade thinking. The local-outbox rule in §9.4 is the operational consequence: an audit outage must not block revocation.

Asymmetry under incomplete observation. If kings-guard can only reduce authority, a suppressed event can miss a tightening. It cannot invent privilege. That is the correct damage bound for an adaptive system fed by a stream it cannot prove complete.

The standard eats its own findings. Five versions exist because reviewing repositories used the loop. That is more valuable than a prettier first draft.

Scope honesty. Uncatalogued infrastructure is outside §5 rather than silently in violation. Painful, but correct: a rule that puts every Staff repo in breach on day one will be ignored.

Weaknesses

The self-healing loop is specified, not staffed. §12 step four is explicit aspiration. kings-guard has never observed a real event. Containment has no engine surface. So the estate can propose and decide, but it cannot yet watch or actuate as a closed loop. That is the gap between a layering model and a self-healing framework.

Engine proliferation without a role map. The catalog now has user, tenant, zone, secrets, audit, access, approval, and maturity engines. Several of those are Policy Information Points feeding one PDP, not peer decision points. The standard forbids a second decision surface, but it does not name the PEP / PIP / PAP split, so teams will keep inventing “just one more engine.”

Adoption is still a review note, not a declaration. Seven of sixteen estate-authored repos have declared in their own voice. The rest carry gate-house notes. The standard correctly refuses to count those as adoption. Until the remaining nine answer, the catalog is partly fiction.

Taxonomy is thin relative to its job. info-tech-canon and net-kingdom own language, but there is no versioned semantic contract between engines (claim schemas, decision-record shape, gap-record schema). Without that, “doctrine reaches the decision as an input” is a prose rule, not an interface.

The Tooling carve-out is a pressure valve that will grow. State Hub, llm-connect, and “similar” are out of §5 because Staff writes progress events. That is honest. It is also how a second persistence plane forms under the Staff layer — exactly what §3.4 forbids in spirit.

Cognitive load of the standard itself. v0.5 is dense, self-referential, and written for people who already live in the estate. That is fine as canon. It is a poor onboarding artifact for the nine undeclared repos, and a poor contract for agents that are supposed to conform to it.

Rename and dual-name debt. flex-auth / access-engine is still in flight. Dual names in a “ruled name” estate are themselves a taxonomy defect.

Opportunities

Make the model the control plane for agents, not only for git repos. Staff is already defined as agentic. The conduit shape (§5.2) plus “no privilege from cognition” is a ready-made autonomy gate: an agent may run the owners tool under the callers identity and nothing else. That is a better agent-security primitive than most 2026 control-plane writeups, which still centralize a gateway and hope.

Promote maturity-engine from seeded idea to the gap register. §13 already says the table should not outlive that engine. Doing that turn is how the standard stops being both rulebook and work tracker.

Silence-as-signal. Expected emission cadence as a first-class finding does not need a Tooling client or an engine gap. It is the cheapest completeness control the estate can add, and it is the one adaptive systems actually need.

Export the layering cut beyond security repos. §16 already asks this. If non-security Staff also cannot hold runtime-dependent state, the estate gets one constitution instead of a security ghetto.

Map onto the PDP / PEP / PIP vocabulary without surrendering the determinism cut. The NetKingdom cut is stricter and should stay primary. The IETF/NIST terms are how you talk to the rest of the industry and how you stop PEPs from quietly becoming PDPs.

Threats

Convenience second decision points. The failure mode is already quoted from zone-engine: it arrives as a small convenience. Maturity levels in a registry, approval-validity queries on audit-core, posture caches in kings-guard, “just this once” SSH signing — all of these are the same threat.

Optimistic bias in the adaptive layer. §9.6 already states it. If observation stays fixture-based, posture will look healthy because the stream is well-formed and incomplete. Confidence scores computed from richness of the record in hand will lie.

Consumer fail-open as undeclared policy. §9.3 correctly says unreachable-engine behaviour is the consumers, and must be declared, total, and auditable. The threat is drift: z0z2 open plus “unknown” open becomes the real policy of the estate, and nobody compiled it into the versioned package.

Staff agents plus uncatalogued infra. Progress-event writers today are State Hub and llm-connect. Tomorrow they are agent memory stores, tool-call traces, and prompt caches. Those are state other layers will start to depend on.

Relabelling under pressure. The standard exists because a rule with no lane for a real case gets satisfied by renaming. Incident week is when that pressure returns. “Engine unreachable is not grounds for a Staff break-glass path around a reachable engine” will be the sentence someone tries to stretch.

Supply chain of third-party Tooling. OpenBao is catalogued; its operator, plugins, and lease semantics are not. A layering model that treats vendored Tooling as a row in a table will miss the place where most secret-plane incidents actually start.


Gaps

These are gaps in the layering model, not a punch list of missing products. Several are already named in §16; they are restated only where the model, not the backlog, is incomplete.

1. No Policy Enforcement Point

The standard is precise about the decision and almost silent about the gate. NIST ZTA splits PDP (decide) from PEP (open, monitor, tear down). Here, ops-mason builds routes, ops-warden issues certs, and “the consumer” fails open or closed — but nothing is catalogued as the component that must refuse to proceed without a decision record. Without a PEP rule, enforcement will keep living inside Staff runbooks.

2. Engines are not typed

access-engine is a PDP. user-engine, tenant-engine, zone-engine, approval-engine, maturity-engine are PIPs (or object stores with deterministic APIs). audit-core is an evidence plane, and §9.4 already forbids it from becoming a decision plane. secrets-engine is a lifecycle API over Tooling. Collapsing all of that under “Engine” hides different failure modes: a PIP outage is input degradation (§9.3); a PDP outage is consumer residue; an evidence-plane outage must not block revocation.

3. Actuation is unnamed

Self-healing needs four verbs: observe, evaluate, decide, actuate. Observation is kings-guard (unstaffed). Evaluation is maturity-engine (seeded). Decision is access-engine. Actuation — reduce authority, step-up, isolate a workload — is “containment, pending.” A layering model for a self-healing framework that has no actuation surface is a diagnosis machine, not a healing machine.

4. Human Staff vs agent Staff

§3.4 treats Staff as one layer because both are non-deterministic. That is right for permissions. It is wrong for blast radius. An agent that can open a conduit, write progress events, and propose doctrine is a different principal from a human with a workplan. There is no agent identity, agent mandate, or agent-memory rule.

5. Time, races, and consumption

§16 already flags who marks an approval consumed, and that the decision precedes the action which precedes consumption. The layering model has no temporal law: decision TTL, revocation visibility, replay windows, and “allow rendered then never consumed.” Those are not engine details. They are what stops the single PDP from deciding on stale claims.

6. Partition and unreachability are one-dimensional

§9.3 handles “engine not reachable.” It does not handle split brain, partial PIP reachability, clock skew, or two consumers with different declared stances seeing different worlds. A self-healing estate will spend most of its incident time in that grey band.

7. Information flow and data classes are absent

Layers constrain who may own a concept. They do not constrain which facts may flow where. Zone stance, tenant facts, secret metadata, and approval objects all cross the Staff/Engine boundary as claims. Without a claim-schema and classification rule, §6.2 is unenforceable by construction.

8. Layer change is underspecified

§10 says record a decision, update INTENT, get assent, no gradual practice. It does not say what happens to live state, clients, or declared gaps during the cut. zone-engine already changed layer in practice. That is the case the procedure should have been written from.

9. Publication integrity of Taxonomy

Canon is the layer that defines the other layers. There is no rule for how a standard itself is hashed, assented, frozen, or rolled back. The frontmatter is careful; the publication path is not a layer concern yet. For a framework that claims reconstructability, the standard-of-record should be an artifact with the same provenance discipline it demands of decisions.

10. The conformance loop has no stop condition

A finding that a rule is unsatisfiable is a success. Good. There is no rule for when a contested clause stays proposed, when veto is in-scope, or when two assented repos disagree after adoption. v0.4 §9.3 colliding with shipped ADR-0009 is the preview.

security-zones, tenancy-posture, and credential-management appear in frontmatter and almost nowhere in the rules. The layering model does not say how a zone stance or a tenancy posture enters a decision as a claim. That is the composition gap between “we have standards” and “the PDP can see them.”

12. Third-party Tooling has no operator layer

OpenBao is Tooling. The humans and agents who operate it, rotate it, and plugin-extend it are Staff. The standard forbids Staff from holding a direct client — except the declared SSH-CA gap, which is the production path. The model needs a first-class “operator of third-party Tooling” shape, or every operational necessity will look like a gap.


Improvements

Priority is what would make this a self-healing and evolving framework rather than a better catalog.

A. Split the Engine layer into roles, keep one decision point

Keep the four layers. Add a role column inside Engines:

  • PDPaccess-engine only
  • PIP / object engines — user, tenant, zone, approval, maturity, secrets-as-facts
  • Evidence engineaudit-core
  • PEP contract — not a new repo by default; a shape any runtime must implement: no side effect without a decision record, declared unreachable-engine stance, no local recaching of the verdict

This preserves §6 and stops “we should write an engine for X” from meaning “X now decides.”

B. Add an Actuation surface as a first-class pending capability

Do not assign containment to kings-guard in §4. Assign a containment API as an engine concept (likely a small surface on access-engine plus runtime PEPs): reduce, step-up, isolate, with the same reconstructability rules as any other decision. Until that exists, the framework cannot heal. Mark it pending and keep the capability at zero. That is already the standards own medicine.

C. Distinguish Staff-human and Staff-agent in §3.4 / §5

Same layer, different principal:

  • Agents get no standing credential.
  • Agent tool use is only §5.2 conduit or an Engine API.
  • Agent memory and traces are not Tooling other layers may depend on unless catalogued.
  • Every agent action is reconstructable as the callers action, with the same §9.6 bound.

That is how “no privilege from cognition” survives an autonomous Staff layer.

D. Make Taxonomy operational: versioned claim and decision schemas

Add a single ruled artifact, owned by Taxonomy:

  • request-claim schema (identity, zone, posture, approval, maturity, assurance)
  • decision-record schema (policy package digest, input-claim digests, verdict, obligations)
  • gap-record schema (the §5.3 fields, already almost there)
  • emission-cadence declaration (silence-as-signal)

Then §6.2 and §11 “mechanically checkable” become compileable instead of reviewable.

E. Close the observation hole without pretending it is closed

Two concrete rules, both already implied:

  1. No estate argument may cite “kings-guard observed X in operation” until that repo reports a real-event test. §12 already says this; lift it into §2 authority so it cannot be forgotten in a slide.
  2. Every source that emits load-bearing or adaptive-relevant events MUST publish an expected cadence. A drop is a finding. That gives the adaptive layer a completeness signal that does not require a Tooling client.

F. Put time into the model

Add a short § on decision lifetime:

  • every allow has an explicit TTL or binding to a session/obligation
  • revocation and supersession have a visibility SLA at the PDP and at PEPs
  • consumption of an approval is a state change in approval-engine, never inferred from a decision record
  • racing double-consume and allow-without-consume are named failure modes with owners

This is the missing law for the approval race already flagged in §16.

G. Catalogue PEPs unreachable-engine stances as a single register

ADR-0009 is the reference. Promote the shape (total per-zone map, no implicit default, no per-call discretion) to the standard, and require every PEP-shaped consumer to publish one. Track those maps in maturity-engine once it exists. That turns §9.3 from a ruling into an inventory.

H. Shrink §13 out of the standard

Move the gap register into maturity-engine as soon as it can store state. Leave in the standard only: the two marks (pending / declared-gap), the owner-status rule (proposed ≠ assigned), and the scoring rule (blocked-clean MUST NOT rank below conforming). A standard that is also a backlog will keep attracting findings that belong in the register.

I. Tighten the uncatalogued-infra valve

Keep the carve-out. Add a sunset:

  • every non-Tooling client MUST be listed
  • after N review intervals, an uncatalogued store that other layers read is either catalogued as Tooling or declared a gap
  • Staff-owned event buses cannot become the de facto state plane

Otherwise the binding rule dies at the edges.

J. Write the layer-change procedure from the zone-engine case

Required artifacts: before/after INTENT, client inventory, gap inventory, assent list, state-migration decision, and a freeze on new permissions until the cut is complete. “No gradual practice” needs a check, not a sentence.

K. Compose the sibling standards in one paragraph each

In this document, not in theirs:

  • how a zone stance becomes a claim
  • how tenancy posture becomes a claim
  • how a credential lifecycle event becomes an input rather than a side channel

If those sentences cannot be written, the related-standards list is decoration.

L. Add a two-page “agent-readable” companion

Same rules, no change log, no review archaeology. Machine-readable layer key, sanctioned shapes, one decision point, evidence bound, four conformance states. v0.5 is the statute. The companion is what the nine undeclared repos and the Staff agents can actually satisfy.

M. Decide the open custody question on purpose

Either approvals warrant stronger custody than other sources, or they do not. Leaving it open while calling the evidence half “load-bearing” creates a slogan the archive cannot cash. If the answer is “same bound as every source,” say that and stop implying a future WORM plane. If the answer is “stronger,” assign an owner outside audit-cores current store — that is the only way the bound changes.


Verdict on fitness for a self-healing, evolving framework

As a layering constitution, v0.5 is already ahead of most enterprise security models: it knows the difference between deciding and recording, between a gap and a lie, and between a missed tightening and an invented privilege.

As a self-healing system, it is incomplete in a specific way. Cognition (Staff) and authority (access-engine) are specified. Execution (Tooling) is specified. The two verbs that make a loop heal — observe in production, actuate through a deterministic surface — are pending and, in one case, explicitly unstaffed. Evolution works: the version history is the proof. Healing does not, yet.

The highest-leverage next version is not another finding-driven prose refinement. It is:

  1. type the engines (PDP / PIP / evidence / PEP contract),
  2. keep containment at zero until an actuation API exists,
  3. put claim schemas in Taxonomy,
  4. staff or retract the observation step,
  5. move the gap register out of the statute.

Do those five and the model stops describing an estate that intends to heal and starts describing one that can.

Assessment and Research by Grok Expert

xxx