Commit graph

48 commits

Author SHA1 Message Date
c1b60f322e feat: publish Risk Nexus findings and methods
All checks were successful
Build and publish policy-nexus image / build-and-push (push) Successful in 1m10s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 01:56:46 +02:00
4c8a7b9666 docs: record governed source promotion
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 01:44:07 +02:00
49ab152da6 docs: record active source credential path
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 01:37:17 +02:00
1e6720b9ee test: isolate publication fixtures from release env
All checks were successful
Build and publish policy-nexus image / build-and-push (push) Successful in 56s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:38:44 +02:00
8ea8a4b41c fix: lock workflow checkout provenance
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 48s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:37:12 +02:00
a0e4964b46 fix: verify fetched source revisions from lock
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 54s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:35:33 +02:00
641eda8a37 docs: close PNEX fleet standards release
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-08-31 22:31:24 +02:00
5fbd44a703 feat: publish custodian fleet standards batch
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 0s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-08-31 22:24:25 +02:00
885c6bb1cb docs: close PNEX publication workplans
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-08-31 21:58:00 +02:00
93608c1f17 feat: publish reviewed architecture and ADR batch
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 19s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-08-31 21:34:23 +02:00
023badb512 fix(workplans): adopt PNEX workplan identities
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-08-31 21:34:20 +02:00
6515ed9ef8 fix(workplans): adopt ADR-007 derived identifiers for unregistered records
These workplans exist only in the retired local hub. Their random pre-ADR-007
identifiers are refused by C-06 as stale references, so they cannot be
registered. Deriving from the canonical record id takes no identity from
anything: central does not hold them and the old ids die with the cache.

Records central already holds were deliberately left untouched.

Refs CUST-WP-0068-T06

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 20:17:25 +02:00
custodian-sync
93ba8d28cd chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-25:
  - update .custodian-brief.md for policy-nexus

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 19:56:21 +02:00
repo-manager
91b2b4a080 chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 17:45:50 +02:00
custodian-sync
57489d24ea chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-25:
  - update .custodian-brief.md for policy-nexus

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 17:45:48 +02:00
32cea111eb Keep the architecture infospace out of the governing inventory
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 58s
Top-level canon/architecture/*.md is enough; pointer files are retrieval
only.
2026-08-19 01:14:20 +02:00
25dd59a7c6 Publish estate ADRs, platform ADRs, and IAM Profile v0.3
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 48s
T04 classifies the remaining corpus. Chapter 9 on the first-wave
arc42 stubs now matches what is published.
2026-08-19 01:09:41 +02:00
5cb88edf4d Ignore markitect AST cache and refresh work-records 2026-08-19 00:20:33 +02:00
7d608c0d57 Publish activity-core and ops-warden ADRs
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 55s
Harvest ops-warden's five ready records. Register ACT-ADR-001–005 after
publication metadata landed in activity-core. Markitect arc42-v1 and
the estate infospace are now the validation and retrieval path.
2026-08-19 00:17:13 +02:00
64b47d73b9 Refresh WORK-RECORDS for completed T05 tasks 2026-08-18 22:40:57 +02:00
af9f5996e2 Deliver ADR cleanup packets and publish first-wave arc42 stubs
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 48s
Packets go to seven owning repos by inbox and checklist. Railiance,
NetKingdom, and State Hub now have published architecture stubs.
2026-08-18 22:36:46 +02:00
b93928330e Refresh WORK-RECORDS after the conflict pass 2026-08-18 22:27:49 +02:00
d1f9ac6cd7 Record ADR conflicts and publish the estate arc42
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 39s
T03 writes a rulings overlay and a readable conflict list. T04 starts
relevance: five superseded, five live conflicts, estate and activity-core
ADRs marked publish-after-prefix. The Coulomb estate map is now a
published architecture document.
2026-08-18 22:27:05 +02:00
9c6a1d3ce0 Refresh WORK-RECORDS for active WP-0002 and WP-0003 2026-08-18 22:17:40 +02:00
custodian-sync
9a3476a14f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-18:
  - update .custodian-brief.md for policy-nexus
2026-08-18 22:17:20 +02:00
49fa6fa4eb Publish the policy-nexus arc42 stub
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 49s
Inventory now discovers docs/architecture and registers the local
first-wave stub at /architecture/policy-nexus/v0.1/.
2026-08-18 22:16:57 +02:00
a8fb62a3bc Start the arc42 contract and publish the first ADR set
Add the owner-facing publication contract, a regenerable ADR review
ledger, and publication entries for this repo's ADR-0001 plus the eight
ready railiance-master ADRs.
2026-08-18 22:16:02 +02:00
7a24e9107f Add workplans for the arc42 collection and ADR review
WP-0002 names the first-wave architecture documents and the
markitect/infospace split. WP-0003 reviews the inventoried ADRs for
conflicts, then publishes what still governs.
2026-08-18 21:54:22 +02:00
45c464e1bc Parse immutable registry digest safely
All checks were successful
Build and publish policy-nexus image / build-and-push (push) Successful in 46s
2026-08-18 13:40:11 +02:00
e737b74688 Use fetched sources for currency checks
All checks were successful
Build and publish policy-nexus image / build-and-push (push) Successful in 43s
2026-08-18 13:37:21 +02:00
e7b26ff158 Isolate fetched source override from tests
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 42s
2026-08-18 13:34:55 +02:00
e33b98a1e6 Transfer source checkout through Docker API
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 44s
2026-08-18 13:30:36 +02:00
093913719f Run source fetch in pinned CI container
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 5s
2026-08-18 13:27:33 +02:00
03a4fab9e0 Automate policy source freshness and inventory
Some checks failed
Build and publish policy-nexus image / build-and-push (push) Failing after 2s
2026-08-18 13:25:49 +02:00
custodian-sync
78d096bdd5 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-18:
  - update .custodian-brief.md for policy-nexus
2026-08-18 13:25:27 +02:00
ad34250ea1 Record Policy Nexus production verification 2026-08-18 12:55:14 +02:00
custodian-sync
d092487fb1 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-18:
  - update .custodian-brief.md for policy-nexus
2026-08-18 12:46:10 +02:00
custodian-sync
697bf197f6 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-18:
  - update .custodian-brief.md for policy-nexus
2026-08-18 12:17:47 +02:00
1cac793edb Reconcile remote stub without deleting policy history
All checks were successful
Build and publish policy-nexus image / build-and-push (push) Successful in 21s
2026-08-18 12:16:52 +02:00
e8035f3887 Build immutable policy publication artifact 2026-08-18 12:16:04 +02:00
ea270b0594 README.md aktualisiert 2026-08-18 08:15:41 +00:00
cac0301866 Owner is the-custodian; regulatory intake leaves for risk-nexus
Authority is three-way and stated rather than held by one repo: policy-nexus
owns the surface, the-custodian owns what counts as canon and when it is
ratified, railiance-platform owns the substrate. The middle one is the guard
against the real hazard here - a repo that reads every other repo is one step
from becoming the place where "what is current" is decided, and this says
plainly that it renders that judgement rather than making it.

The tell that the split is right is that T01 and T04 need different
competences. T01 asks what supersession means and what a permanent URL
promises; T04 is DNS and ingress. One owner would be weak at one of them.

T06 withdrawn. Regulatory intake is risk work, not publishing work, and it
wanted a different owner and a different skill from everything else in this
workplan. risk-nexus publishes through here, arriving as another manifest
source rather than as a second content type this repo curates.

The consequence is the point: this repo now does one thing, which is what made
its ownership answerable.

Domain corrected from government, a leftover from when this looked like a civic
policy site.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:56:05 +02:00
54779f5eb7 Finish the retarget: no stale ADR-008 references remain
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:42:24 +02:00
dd127578c4 Retarget references after the framework moved to NetKingdom
The forcing case is now tenancy-posture_v0.1, not Custodian ADR-008, and the
renderer is tools/render.py rather than a path in another repo.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:42:11 +02:00
06be56fdff Take over the renderer; defer controlled disclosure to a risk service
The renderer and its stylesheet moved in from the-custodian with a make build
target, so T02 generalises something that works rather than starting from
scratch. Publication tooling belongs to the repo that owns publication.

Disclosure is resolved for now: full public is fine in build mode, where there
are no users to expose and no attacker with anything to gain. Recorded as
deferred rather than closed, because it stops being true at production - the
same blast-radius disclosure that a consumer must read becomes a map once real
tenant data exists.

Controlled disclosure is deliberately not this repo's job. Publication is about
permanence and currency; embargo is about severity, remediation and timing, and
building it here would put risk judgement in the repo least qualified to make
it. It likely wants a service of its own - a risk-nexus - with this repo as its
publication surface rather than its brain.

The only cost today is one line in T01: the addressing scheme must not assume
every document is public from birth, so that adding an embargo state later is a
new status rather than a URL migration.

First publication retargeted - the framework relocated to NetKingdom canon and
is now tenancy-posture_v0.1, five axes rather than five planes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:42:00 +02:00
1843ba40c9 Scope: canon and ADRs outward, estate-bearing regulation inward
Operator answered the two blocking questions, so T06 is now specifiable and
T03 has a bounded corpus: two canon trees and roughly 68 ADRs across 18
repositories. Workplans, evidence and runbooks are out - a site that publishes
everything publishes nothing in particular.

T06 gains an inclusion test (does the rule constrain something the estate
actually does), a record format, and a candidate register drawn from what the
estate demonstrably touches rather than from a list of well-known regulations -
data protection and erasure, residency, procurement via vergabe-teilnahme,
identity assurance via the aal2 class, and the agentic tenant grouping. The
register is to confirm, not to assume.

The hard rule is now in the format itself: a record states what a source said
and when. Interpretation belongs to the repo making the decision. The estate
has no legal function and this repo must not grow one by accident.

Rewrote the README, which described a broader civic corpus than the repo is
scoped to and would have attracted the wrong contributions.

One question got sharper rather than resolved: publishing every ADR across 18
repos puts the estate's architecture, known gaps and residual risks in one
indexed public place. That is right for a document consumers must read, and it
is a decision to take deliberately rather than inherit from a default.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:27:02 +02:00
db5b310853 Add INTENT and WP-0001: permanent publication surface
policy.coulomb.social replaces disposable artifact-page publication. The repo
has two halves - publishing estate policy outward, and gathering external
policy inward - and one standing constraint: it reads from the repos that own
policy and never writes back, so it cannot become a second source of truth.

WP-0001 is scoped by a forcing case. ADR-008 needs review from six repos and
is currently served from a private URL that may not resolve later. It is both
the first publication and the acceptance test: if the site cannot carry five
ladders, a threat matrix, an E x P grid and twelve owner-attributed questions,
the site is not finished.

T01 fixes addressing and the permanence promise before anything is built,
because changing it later breaks the one thing this repo exists to guarantee.
T02 takes over the renderer that already exists in the-custodian rather than
reimplementing it - stdlib-only is an acceptance criterion, not a preference.
T06 is deliberately last and carries a hard rule: a gathered record says what
a source said and when, never what the estate must therefore do.

Four questions left open for the operator, including who owns this and whether
"government policies" in the README means regulation bearing on the estate or
a broader public corpus. T06 cannot be specified until that is answered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:12:15 +02:00
60876c5d4b Initial commit 2026-08-17 13:03:13 +00:00