ops-warden/workplans
tegwick a70f559d40
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Apply GH-DEC-2026-017: INTENT.md governs, the sidecar is derived, no version
Verified against gate-house's own committed files before editing, not the inbox
message: GH-DEC-2026-017 in decisions/decisions.md at gate-house@def0af2,
amendments A9-A13 in docs/amendments/v0.8-section-11-declaration-amendments.md,
and sections 3, 4 and 11 of net-kingdom's security-layer-model_v0.8.md. The
ruling and docs/layer-declaration-precedence.md's secondary account agreed.

INTENT.md's frontmatter is the declaration; layer.yaml is a derived artifact,
now marked derived: true / derived_from: INTENT.md, and it does not govern.

standard_version is removed from BOTH forms. The ruling's general form is that a
layer declaration must not carry a standard version, and INTENT.md is the
declaration, so removing it from the sidecar alone would have left the field in
the only file that actually declares. INTENT.md's version-pinned `standard:`
path is de-versioned for the same reason: a pinned path reads as a validity
condition. The version ops-warden assented at stays with the assent, ADR-0010.

NO LAYER VALUE IS CHANGED. INTENT.md still says Staff and layer.yaml still says
staff. Section 3's vocabulary is closed, four tokens, and case-insensitive: the
two forms were never in disagreement about a layer, and the ruling asked nobody
to re-spell anything. The comment marking the divergence is rewritten from
"unruled, do not touch" to "ruled, folding case is the checker's job".

check_layer_conformance.py would have rejected the conforming declaration this
ruling produces -- it listed standard_version as a required key. It now reads
INTENT.md as the governing form, ASCII-folds before comparing, validates both
values against the closed four-token vocabulary (Taxonomy included; omitting it
is the defect A9 records against the estate's other validator), requires the
derived marking, rejects a returning standard_version in either file, and
reports a post-fold disagreement between the forms as a finding rather than
resolving it away by precedence.

The test asserts the fold, not equality. An equality assertion here would be
this repository quietly performing the re-spelling the ruling declined to order;
the fold still fails on a real layer divergence.

pep-stance.yaml is untouched. A stance map is not a layer declaration, and the
sidecar schema beyond the derived marking and the version is explicitly not
ruled.

layer.yaml is the form seven repositories copied, so the adopter change set is
written out in wiki/playbooks/netkingdom-layer-declaration.md -- including the
trap that an adopter which also copied the checker turns a conforming
declaration into MALFORMED exit 2 by removing the field alone. No other
repository is edited here.

Still open: where the removed version lives. A12 says the derived conformance
record "already MUST" carry it; ops-warden has a re-runnable checker that emits
nothing durable. Asked of gate-house in message 4220413a, unanswered, and left
open rather than answered by choosing. Nothing above depends on it.

Carries WARDEN-WP-0034-T06 to done.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:38:55 +02:00
..
archived repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-06-27.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-06-29.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-08-11.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-08-17.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-09-08.md chore: record hub ids for 2026-09-08 workplans 2026-09-08 14:57:42 +02:00
WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md feat(WARDEN-WP-0016): ops-bridge cert_command readiness gate + handoff 2026-06-27 19:50:28 +02:00
WARDEN-WP-0017-access-front-door-discoverability.md feat(WARDEN-WP-0018): activate whynot-design npm publish lane + resolvable flag 2026-06-29 00:32:00 +02:00
WARDEN-WP-0018-whynot-design-npm-lane-activation.md chore(WARDEN-WP-0018): stamp state_hub task ids from consistency sync 2026-06-29 00:36:35 +02:00
WARDEN-WP-0019-route-to-secrets-engine.md chore(WARDEN-WP-0019): stamp state_hub ids from consistency sync 2026-06-29 17:43:44 +02:00
WARDEN-WP-0020-ops-warden-worker.md feat(WARDEN-WP-0020): T4 scheduling tick + T5 SCOPE — worker complete 2026-06-30 00:41:04 +02:00
WARDEN-WP-0021-enable-scheduled-worker-tick.md feat(WARDEN-WP-0021): T3-T5 — visibility, approve loop, runbook (scheduled worker complete) 2026-06-30 15:24:10 +02:00
WARDEN-WP-0022-audit-trail-and-activity.md Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
WARDEN-WP-0023-intent-scope-alignment-closeout.md Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
WARDEN-WP-0024-experiential-memory-and-agent-sessions.md Implement WARDEN-WP-0024 experiential memory and agent sessions. 2026-07-02 23:40:45 +02:00
WARDEN-WP-0025-forgejo-admin-api-token-lane.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0026-credential-disclosure-hygiene.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0027-credential-governance-lockdown.md Classify open workplans with flavor (CUST-WP-0072). 2026-09-14 15:50:43 +02:00
WARDEN-WP-0028-tenant-secret-custody.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0029-policy-front-door-and-founder-surface.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0030-delegation-register.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0031-policy-caller-identity.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0032-security-zones.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0033-native-lane-handoff.md WARDEN-WP-0033 finished — key-cape accepted the issuance question five days ago 2026-08-28 22:00:09 +02:00
WARDEN-WP-0034-layer-model-v07-conformance.md Apply GH-DEC-2026-017: INTENT.md governs, the sidecar is derived, no version 2026-09-21 02:38:55 +02:00
WARDEN-WP-0035-policy-nexus-forgejo-source-read-route.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
WARDEN-WP-0036-attended-login-openbao-output.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
WARDEN-WP-0037-whynot-design-forgejo-npm-lane.md Revert the npm field, re-measure coverage, and hold the layer divergence 2026-09-21 02:16:33 +02:00
WARDEN-WP-0038-plan-mutation-intent.md feat: refuse to answer a write with a read (WARDEN-WP-0038) 2026-09-10 08:02:10 +02:00
WARDEN-WP-0039-explicit-policy-refusal.md Classify open workplans with flavor (CUST-WP-0072). 2026-09-14 15:50:43 +02:00
WARDEN-WP-0040-unknown-zone-fail-closed-adoption.md Classify open workplans with flavor (CUST-WP-0072). 2026-09-14 15:50:43 +02:00