net-kingdom/history
tegwick 745dffb8ac Security Layer Model v0.6 — type the engines, name the gate, hold actuation at zero
From the independent assessment of 2026-08-29, which found the model sound as a
layering constitution and incomplete as a self-healing one: cognition,
authority, and execution are specified, but the two verbs that close a healing
loop — observe in production, actuate through a deterministic surface — are
pending, and one is unstaffed.

Section numbers below §14 are unchanged; the estate cites them.

- §3.3 types the Engine layer: PDP, PIP, Evidence, Lifecycle, with a role column
  in §4. Collapsing them hid different failure modes — a PIP outage is input
  degradation, a PDP outage is consumer residue, an evidence-plane outage must
  not block the operation it records. A new engine is a PIP unless amended.
- §6.4 names the enforcement point. The standard was precise about the decision
  and silent about the gate, so enforcement lived in Staff runbooks. Four
  obligations: no side effect without a decision record, no local recaching of
  the verdict, a declared unreachable-engine stance, reconstructability.
- §9.2 replaced. Containment was marked pending against kings-guard, the right
  mark on the wrong repository: reduce, step-up, and isolate are
  authority-changing operations, so they are rendered by an Engine and enforced
  by a PEP. Actuation is an unowned Engine concept held at zero. Staff proposes
  containment and never performs it.
- §3.4 separates human and agent principals inside Staff — same permissions,
  different blast radius. No standing credential, conduit or engine API only,
  agent memory is not a state plane, every action reconstructable as the
  caller's.
- §9.7 puts time into the model: explicit lifetimes, revocation visibility
  deadlines, consumption as a state change never inferred from a decision
  record, and the three race modes named. §9.8 states what holds under
  partition.
- §17 requires the Taxonomy artifacts — claim, decision-record, gap-record, and
  emission-cadence schemas — without which §6.2 and §11 are reviewable but not
  compileable. Ownership proposed, not assigned.
- §18 composes the sibling standards, which had been cited in frontmatter and
  nowhere in the rules.
- §5 sunsets the uncatalogued-infrastructure carve-out. §5.3 declines a proposed
  fourth "operator of third-party Tooling" shape: it would convert a tracked gap
  into a permanent allowance, which is the relabelling failure this standard
  exists to prevent.
- §10 gains the six artifacts a layer change must carry, written from the
  zone-engine case, including a permission freeze during the cut.
- §2 lifts the observation rule so it cannot be lost in a summary. §13 separates
  its three normative rules from the table, now a snapshot due to move into
  maturity-engine. §16 decides the approval custody question: no. §19 records
  the fitness verdict.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 03:32:58 +02:00
..
2026-06-17-openbao-ssh-custody-and-bootstrap-assessment.md docs(NET-WP-0020): T5 automation ready; operator apply is next gate 2026-06-18 01:06:43 +02:00
2026-07-02-openbao-greenfield-init-unseal-proof.md NET-WP-0020 finished: attended-ceremony + auto-unseal-transit profiles, greenfield init/unseal proof 2026-07-02 22:08:33 +02:00
2026-08-23-key-cape-c1-c2b-composition.md feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
2026-08-23-keycape-exposure-dependency-map.md feat(privacyidea): add guarded resolver reconciliation helper 2026-08-23 14:43:39 +02:00
2026-08-23-posture-feedback-estate-baseline.md docs(posture): record repaired estate baseline 2026-08-23 13:28:08 +02:00
2026-08-23-scope-intent-gap-assessment.md feat(orchestration): compose KeyCape C1 and C2b 2026-08-23 13:24:55 +02:00
2026-08-29-layering-standard-assessment.md Security Layer Model v0.6 — type the engines, name the gate, hold actuation at zero 2026-08-29 03:32:58 +02:00