net-kingdom/canon/standards
tegwick 101e659725 Tenancy Posture: question 3 has an owner
whitehat-security takes the adversarial evidence artifacts - the framework's
highest-severity gap, unowned since it was drafted. audit-core and tenant-engine
were right to decline it as fleet-scope work; the answer was a home of its own
rather than a volunteer.

Recorded here with the part that bears on this document: the facility is
deliberately not owned by NetKingdom, which owns this framework. Verifying
conformance to a standard while reporting to the standard's owner is
self-grading one level up.

Two consequences land back on the framework. Cadence becomes a security
parameter rather than a schedule, since for a detection-based control the
interval between runs is the exposure window. And a passing suite is proof that
the attacks attempted did not work, not proof of isolation - recording a green
run as "E2 verified" would be exactly the overclaim section 6 prohibits.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 16:41:56 +02:00
..
credential-management_v0.2.md Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008 2026-05-20 22:51:20 +02:00
iam-profile_v0.2.md Ratify tenant grouping identifiers 2026-07-27 20:39:12 +02:00
iam-profile_v0.3.md ADR-0014 + tenant-engine boundary contract + IAM Profile v0.3 2026-07-23 21:45:37 +02:00
playbook-capability-contract_v0.1.md Implement NK-WP-0013 playbook capability contract 2026-05-22 14:49:25 +02:00
tenancy-posture_v0.1.md Tenancy Posture: question 3 has an owner 2026-08-17 16:41:56 +02:00
tenant-engine-boundary-contract_v0.1.md ADR-0014 + tenant-engine boundary contract + IAM Profile v0.3 2026-07-23 21:45:37 +02:00
user-engine-boundary-contract_v0.1.md docs: persist user-engine vs net-kingdom integration assessment (new doc + cross-references in SCOPE, boundary contract, guidance, responsibility map, 0018/0019 workplans). Also updated user-engine integration doc to reference it. 2026-06-03 10:33:31 +02:00