net-kingdom/canon/standards
tegwick 66eeabad38 Cut security-layer-model v0.8 (proposed) from gate-house's amendment set
Authored by gate-house under GH-WP-0003-T06; published here. v0.7 stays
accepted and unedited until v0.8 is accepted in its place.

Eleven changes across §6.4, §8, §9.5, §9.7.3, §11, §12, §13.1, §16 and
§17, each carrying the decision record that already governs its
implementers. Three correct a rule that was unsafe or unfalsifiable as
written — consume ordering, the volatility boundary, and a permissive
unknown. Three close gaps between rules already made. One corrects an
ownership paragraph that a later decision made false, and §11/§12 gain
the general form of that failure after six instances in one week.

Ten of the eleven were requested by another repository, seven by a
repository arguing against its own interest. §14 is therefore rewritten:
this version is circulated for review rather than accepted on the owner's
decision as v0.7 was, because it imposes costs on named repositories —
ops-warden acquires a non-conformant stance cell, approval-engine an
issue-time obligation — and a cost imposed without a review round is what
§12 exists to catch late.

Section numbering is unchanged; the estate cites it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 14:52:42 +02:00
..
credential-management_v0.2.md Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008 2026-05-20 22:51:20 +02:00
emission-cadence-security-profile_v0.1.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
iam-profile_v0.2.md Separate IAM Profile ids and mark v0.2 superseded 2026-08-19 01:09:18 +02:00
iam-profile_v0.3.md docs: refresh published security canon index 2026-08-31 21:17:38 +02:00
playbook-capability-contract_v0.1.md feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
posture-feedback_v0.1.md feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
security-layer-model_v0.1.md Security Layer Model v0.2 — accepted 2026-08-28 22:00:31 +02:00
security-layer-model_v0.2.md Security Layer Model v0.3 — assign approvals and maturity 2026-08-28 22:34:58 +02:00
security-layer-model_v0.3.md Security Layer Model v0.4 — audit-core assent and its corrections 2026-08-28 22:54:50 +02:00
security-layer-model_v0.4.md Security Layer Model v0.5 — four reviews, nine changes 2026-08-29 02:54:25 +02:00
security-layer-model_v0.5.md Security Layer Model v0.6 — type the engines, name the gate, hold actuation at zero 2026-08-29 03:32:58 +02:00
security-layer-model_v0.6.md Security Layer Model v0.7 — write the rule v0.6 only announced 2026-08-29 10:44:53 +02:00
security-layer-model_v0.7.md Accept the security layer model; companion v0.2 to the repository root 2026-08-29 11:28:49 +02:00
security-layer-model_v0.8.md Cut security-layer-model v0.8 (proposed) from gate-house's amendment set 2026-09-06 14:52:42 +02:00
security-scenario-composition_v0.1.md feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
security-zones_v0.1.md docs(canon): record security zone adoption 2026-08-22 15:43:52 +02:00
tenancy-posture_v0.1.md feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
tenant-engine-boundary-contract_v0.1.md docs(canon): reconcile workload and tenant grouping semantics 2026-08-22 14:53:31 +02:00
user-engine-boundary-contract_v0.1.md docs: persist user-engine vs net-kingdom integration assessment (new doc + cross-references in SCOPE, boundary contract, guidance, responsibility map, 0018/0019 workplans). Also updated user-engine integration doc to reference it. 2026-06-03 10:33:31 +02:00