From f157a9169f0bb79c56db7846541fe293d448f763 Mon Sep 17 00:00:00 2001 From: tegwick Date: Fri, 28 Aug 2026 20:33:43 +0200 Subject: [PATCH 1/3] Note NetKingdom layering review in INTENT Records this repository's layer in the NetKingdom IT-security layer model (Taxonomy / Tooling / Engines / Staff) and what should change in this INTENT as a result. Links to the review that established the model: gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md The note flags pending adaptation only; the body is unchanged. Co-Authored-By: Claude Opus 5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- INTENT.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/INTENT.md b/INTENT.md index 52ba97c..0757273 100644 --- a/INTENT.md +++ b/INTENT.md @@ -1,5 +1,20 @@ # INTENT +> **NetKingdom layering review — 2026-08-28.** This repository's role was reviewed +> against the NetKingdom IT-security layer model: **Taxonomy → Tooling → Engines → +> Staff**, layered by determinism and by the kind of artifact each layer produces. +> Findings and the argument behind them: +> `gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md`. +> The model as currently stated is `gate-house/INTENT.md` § "Where Gate House Sits"; +> it is ruled to become a `net-kingdom/canon/standards/` standard, not yet written. +> +> The layer rule that binds every repository: **Staff never touches tooling +> directly. It acts only through engine APIs.** +> +> **This repository is Staff — interactive, non-deterministic; builds and tears down.** Add the layer label and the Staff invariant: ops-mason acts through engine APIs, never against tooling directly. Record the demarcation this repository is half of: **ops-mason and ops-warden own access routes and lanes — how a worker reaches a host; access-engine owns access rules — whether they may.** The perimeter doctrine ops-mason builds to is gate-house's; the building is ops-mason's. +> +> *This note records what should change. The body below is not yet adapted.* + > This file captures **why this repository exists**, the **direction it is > moving toward**, and the **kind of system it is meant to become**. It is > intentionally aspirational and stable, not a description of current From 718df758dcdae1abfd2ae7db7c6066d0c4352899 Mon Sep 17 00:00:00 2001 From: tegwick Date: Fri, 28 Aug 2026 21:21:08 +0200 Subject: [PATCH 2/3] Point layering note at the published standard The layer model is now published as net-kingdom/canon/standards/security-layer-model_v0.1.md (proposed) and ratified by gate-house GH-DEC-2026-001. The note previously said the standard was not yet written. Co-Authored-By: Claude Opus 5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- INTENT.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/INTENT.md b/INTENT.md index 0757273..61e44c1 100644 --- a/INTENT.md +++ b/INTENT.md @@ -5,8 +5,8 @@ > Staff**, layered by determinism and by the kind of artifact each layer produces. > Findings and the argument behind them: > `gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md`. -> The model as currently stated is `gate-house/INTENT.md` § "Where Gate House Sits"; -> it is ruled to become a `net-kingdom/canon/standards/` standard, not yet written. +> The model is `net-kingdom/canon/standards/security-layer-model_v0.1.md` (proposed), +> ratified by `gate-house/decisions/decisions.md` GH-DEC-2026-001. > > The layer rule that binds every repository: **Staff never touches tooling > directly. It acts only through engine APIs.** From 77a2eadd28626a088075f42de433d5ab9d719fd7 Mon Sep 17 00:00:00 2001 From: repo-manager Date: Fri, 28 Aug 2026 23:03:29 +0200 Subject: [PATCH 3/3] repo.work.create_intake MASON-IN-0002 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit correlation_id: 8a9408fd-c863-4b65-ad0a-d514f7d10c13 reason: Request own-voice layer declaration under §11 source: repo-manager Assistant: claude-code Assistant-Model: opus Assistant-Process: 2564823@bnt-lap001 Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9 --- intakes/intakes.md | 35 +++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) diff --git a/intakes/intakes.md b/intakes/intakes.md index 93bfa75..2e267fe 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -28,3 +28,38 @@ created: '2026-08-22T09:33:08.629717Z' updated: '2026-08-22T21:19:02Z' state_hub_intake_id: "01a028d1-c4af-7a06-adb5-c90399721872" ``` + +## MASON-IN-0002 — Declaration requested: state this repository's layer in INTENT.md (security layer model §11) + +```yaml +id: MASON-IN-0002 +kind: intake +title: 'Declaration requested: state this repository''s layer in INTENT.md (security + layer model §11)' +status: open +origin: cross-repo +origin_ref: net-kingdom security-layer-model_v0.4 §11 +priority: low +owner: ops-mason +requested_by: gate-house +proposed_layer: Staff +description: 'A conformance sweep on 2026-08-28 found this repository has no layer + declaration of its own. It carries a layering review note gate-house wrote into + the top of its INTENT.md on 2026-08-24, and that note names a layer — but the words + are gate-house''s, sitting above a line admitting the body is unadapted. Section + 11 has since been amended to say so explicitly: a layer stated about a repository + by another repository is not a declaration; only the repository''s own file, in + its own voice, conforms. Seven of fifteen estate-authored repositories have declared; + this is one of the eight that have not. REQUESTED: state the layer in INTENT.md + in your own voice, or contest it. PROPOSED LAYER: Staff. Builds and tears down access + routes, credentials, and perimeters. Two things to state in your words: the Staff + binding rule (you act through Engine APIs, never directly against Tooling — a grep + of your own source is the check, as ops-warden did and found one), and the demarcation + you are half of: ops-mason and ops-warden own access lanes, access-engine owns access + rules. Contesting is a real option and costs nothing — the three repositories that + reviewed this model each returned a correction, two of which changed the standard. + If the proposed layer is wrong for what this repository actually does, that is more + useful to us than a label added to close a checkbox. Standard: net-kingdom/canon/standards/security-layer-model_v0.4.md.' +created: '2026-08-28T21:03:29.920563Z' +updated: '2026-08-28T21:03:29.920563Z' +```