ops-warden/wiki
tegwick 94f32bd160
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Review layer model v0.6; publish the PEP stance map §6.4 requires
All three v0.4 findings were acted on — §9.1 split into pending/declared-gap and
§5's scope rule adopted as recommended and credited, and §9.6 ruled via the
load-bearing/attributive distinction with ops-warden's `# audit must not block
signing` named as the estate's live example.

Checked the favourable ruling rather than accepting it. §9.6's test is "no
control branches on its presence": the only consumer of audit.jsonl is `warden
activity`, which displays. Nothing gates on a signing record, so the lane is
genuinely attributive. AuditTrail.md now records the ruling instead of the open
question, and states that the trade must be revisited if a control ever gates on
the trail.

CONFORMANCE ACTION. §6.4 obligation 3 requires a stance map "published rather
than held in code", and requires every PEP-shaped consumer to publish one so the
maps can be inventoried — naming ADR-0009 as the reference shape. ops-warden was
not doing it: the map lived in PolicyConfig.failure_modes, a dataclass default.
Not a code comment, but not published either.

pep-stance.yaml publishes it, and the test asserts the published map EQUALS the
shipped default. A published map that may drift from the code is worse than no
map, because it invites reliance it cannot support.

Two findings sent to gate-house, in history/2026-08-29-layer-model-v06-review.md:
§6.4 obligation 1 (no side effect without a decision record) contradicts
obligation 3 and §9.3, with ops-warden's blessed fail-open stance as the
instance; and §6.4 mandates a stance-map inventory in §13 that §13 does not
implement — where ops-warden is currently the only PEP to have published one.

402 tests pass, ruff clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014535@bnt-lap001
Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2026-08-29 10:20:49 +02:00
..
playbooks Add NetKingdom SSO credential routing lanes 2026-08-23 21:43:12 +02:00
AccessManagementDirective.md Initial Commit 2026-03-28 00:45:43 +00:00
AccessRouting.md Scale the blocker window by lane risk, converging with risk-nexus 2026-08-21 13:29:29 +02:00
ActorInventoryPatterns.md WARDEN-WP-0006: NetKingdom stewardship docs and alignment 2026-06-17 08:22:45 +02:00
AuditTrail.md Review layer model v0.6; publish the PEP stance map §6.4 requires 2026-08-29 10:20:49 +02:00
CertCommandInterface.md Retire CoulombCore references; correct the 16443 diagnosis 2026-08-19 19:31:41 +02:00
CredentialRouting.md Add NetKingdom SSO credential routing lanes 2026-08-23 21:43:12 +02:00
InterHubBootstrapAccessLane.md feat(WP-0012): add inter-hub-bootstrap-ssh catalog entry and align wiki 2026-06-24 12:45:23 +02:00
NetKingdomSecurityMap.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
OpenBaoSshEngineChecklist.md WARDEN-WP-0006: NetKingdom stewardship docs and alignment 2026-06-17 08:22:45 +02:00
OperatorAccessAssist.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
OpsWardenConfig.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
OpsWardenMemory.md Enable implicit phase-memory activation on every warden command. 2026-07-03 00:49:36 +02:00
PolicyGatedSigning.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
WorkloadSecurityPosture.md feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00