Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ea3-7939-7b63-8125-699f8b50bedd
75 lines
3.4 KiB
Markdown
75 lines
3.4 KiB
Markdown
# Intake records
|
|
|
|
## NET-IN-0001 — Declaration requested: state this repository's layer in INTENT.md (security layer model §11)
|
|
|
|
```yaml
|
|
id: NET-IN-0001
|
|
kind: intake
|
|
title: 'Declaration requested: state this repository''s layer in INTENT.md (security
|
|
layer model §11)'
|
|
status: open
|
|
origin: cross-repo
|
|
origin_ref: net-kingdom security-layer-model_v0.4 §11
|
|
priority: low
|
|
owner: net-kingdom
|
|
requested_by: gate-house
|
|
proposed_layer: Taxonomy
|
|
description: 'A conformance sweep on 2026-08-28 found this repository has no layer
|
|
declaration of its own. It carries a layering review note gate-house wrote into
|
|
the top of its INTENT.md on 2026-08-24, and that note names a layer — but the words
|
|
are gate-house''s, sitting above a line admitting the body is unadapted. Section
|
|
11 has since been amended to say so explicitly: a layer stated about a repository
|
|
by another repository is not a declaration; only the repository''s own file, in
|
|
its own voice, conforms. Seven of fifteen estate-authored repositories have declared;
|
|
this is one of the eight that have not, and the standard does not claim adoption
|
|
on the basis of notes gate-house wrote. REQUESTED: state the layer in INTENT.md
|
|
in your own voice, or contest it. PROPOSED LAYER: Taxonomy. NetKingdom standards
|
|
of record and publication. Note this repository publishes the layer model but has
|
|
not declared its own place in it. Contesting is a real option and costs nothing
|
|
— the three repositories that reviewed this model each returned a correction, two
|
|
of which changed the standard. If the proposed layer is wrong for what this repository
|
|
actually does, that is more useful to us than a label added to close a checkbox.
|
|
Standard: net-kingdom/canon/standards/security-layer-model_v0.4.md.'
|
|
created: '2026-08-28T21:01:51.894396Z'
|
|
updated: '2026-08-28T21:01:51.894396Z'
|
|
state_hub_intake_id: "01a06eb9-8b32-7f2a-aae5-0887b1083137"
|
|
```
|
|
|
|
## NET-IN-0002 — Amend tenant-engine-boundary-contract_v0.1 for Engine/PIP, shipped guardrails, and PEP-shaped writes
|
|
|
|
```yaml
|
|
id: NET-IN-0002
|
|
kind: intake
|
|
title: 'Amend tenant-engine-boundary-contract_v0.1 for Engine/PIP, shipped guardrails, and PEP-shaped writes'
|
|
status: open
|
|
origin: cross-repo
|
|
origin_ref: TEN-WP-0011-T06
|
|
priority: medium
|
|
owner: net-kingdom
|
|
requested_by: tenant-engine
|
|
description: >
|
|
tenant-engine has declared Engine / PIP under security-layer-model v0.7
|
|
(TEN-DEC-2026-001) and shipped guardrail/quota policy (TEN-WP-0006).
|
|
canon/standards/tenant-engine-boundary-contract_v0.1.md still says
|
|
guardrail/quota policy is "reserved, not yet implemented" and that
|
|
tenant-engine is "not a policy enforcement point". Both sentences now
|
|
mislead: guardrails are owned and served as PIP ceilings
|
|
(tenant-engine/docs/tenant-guardrail-policy.md), and writes are
|
|
PEP-shaped even though this repo is not a PDP.
|
|
|
|
Requested amendments, without forking the contract into tenant-engine:
|
|
|
|
1. Mark guardrail/quota policy as owned and implemented; point at
|
|
tenant-engine/docs/tenant-guardrail-policy.md.
|
|
2. Restate the authorization contract: data source / PIP for decisions;
|
|
PEP-shaped for its own protected writes; never a second PDP.
|
|
3. Mention Engine / PIP and security-layer-model_v0.7 next to the
|
|
existing IAM Profile / ADR-0013 / ADR-0014 references.
|
|
|
|
Do not assign approval lifecycle to tenant-engine (TEN-DEC-2026-001
|
|
contested that placement).
|
|
created: '2026-08-29'
|
|
updated: '2026-08-29'
|
|
state_hub_intake_id: "01a06eb9-c4af-7a9e-8ff5-1bc5f845eb38"
|
|
```
|
|
|