net-kingdom/canon/standards
tegwick 1c3a9b46e3 Add NetKingdom Security Layer Model v0.1 (proposed)
States how the security estate is layered — Taxonomy, Tooling, Engines,
Staff — distinguished by determinism and by the artifact each layer
produces, and what each layer may own.

Carries two normative rules. §5: Staff never touches Tooling directly; it
acts only through Engine APIs — the architectural form of "no privilege
from cognition", and mechanically checkable. §6: access-engine is the only
policy decision point, generalizing to the whole estate the ruling first
drawn in zone-engine/INTENT.md §5, and barring any Staff repository from
hosting a decision point.

Also fixes the vocabulary the estate has used for more than one thing:
access lane vs access rule, doctrine vs runbook, control plane as Engine
vocabulary, and the posture asymmetry.

Owner gate-house, published by net-kingdom. Status proposed: the two
adaptations carrying the most weight — flex-auth's reframing and rename to
access-engine, and kings-guard and ops-warden releasing vocabulary — are
not yet assented by their owners.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-28 20:59:00 +02:00
..
credential-management_v0.2.md Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008 2026-05-20 22:51:20 +02:00
iam-profile_v0.2.md Separate IAM Profile ids and mark v0.2 superseded 2026-08-19 01:09:18 +02:00
iam-profile_v0.3.md docs(canon): reconcile workload and tenant grouping semantics 2026-08-22 14:53:31 +02:00
playbook-capability-contract_v0.1.md feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
posture-feedback_v0.1.md feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
security-layer-model_v0.1.md Add NetKingdom Security Layer Model v0.1 (proposed) 2026-08-28 20:59:00 +02:00
security-scenario-composition_v0.1.md feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
security-zones_v0.1.md docs(canon): record security zone adoption 2026-08-22 15:43:52 +02:00
tenancy-posture_v0.1.md feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
tenant-engine-boundary-contract_v0.1.md docs(canon): reconcile workload and tenant grouping semantics 2026-08-22 14:53:31 +02:00
user-engine-boundary-contract_v0.1.md docs: persist user-engine vs net-kingdom integration assessment (new doc + cross-references in SCOPE, boundary contract, guidance, responsibility map, 0018/0019 workplans). Also updated user-engine integration doc to reference it. 2026-06-03 10:33:31 +02:00