docs: link Hub Core identity integration into retirement gates

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e715-b802-70f0-a8fa-590d9ee673a5
This commit is contained in:
tegwick 2026-09-28 10:41:58 +02:00
parent 20c367a0ef
commit f8389a810e

View file

@ -39,6 +39,7 @@ Parent foundation: **SHR-WP-0001**. Architecture freeze inputs: **SHR-ARCH-IA-00
| S5 activity-core ports | `activity-core` | **ACTIVITY-WP-0029** | proposed | Schedule/sink alignment to hub ports |
| S6 ops-hub extension | `ops-hub` | **OPS-WP-0003** | proposed | Manifest + extension contract conformance |
| S7 fin-hub fabric boundary | `fin-hub` + `railiance-fabric` | **FIN-WP-0003** | finished | Specialized Fabric authority; executable parity gate; hub projection deferred |
| S9 Identity and tenant integration | `hub-core` with NetKingdom and platform owners | **HUB-WP-0012** | proposed | Platform-root access, extension enforcement and later tenant delegation |
| S8 Project gates (evidence) | `prj-state-hub-retirement` | **SHR-WP-0001-T06** | todo | Baseline counts + retirement gates |
Secondary / support (no new WP required yet):
@ -197,3 +198,21 @@ Detailed measurable criteria: **SHR-WP-0001-T06**.
- [x] Dependencies and gates recorded without copying task lists
- [x] Predecessors identified
- [x] Child files created or confirmed present
## Security integration addition — 2026-09-28
`hub-core/workplans/HUB-WP-0012-netkingdom-platform-root-access.md` is the
single new implementation stream. Its architecture is
[`hub-core/docs/netkingdom-access-blueprint.md`](../../hub-core/docs/netkingdom-access-blueprint.md).
The first milestone grants the verified platform-root identity full platform
access, including extensions and Railiance, while denying other human users.
Fine-grained tenant delegation remains Phase 2 in the same workplan.
Add the per-surface identity, authorization, revocation and audit proof to
G-HUB/G-COMPAT/G-DISP; retain all data, writer, provenance and zero-traffic
retirement gates. HUB-WP-0011 retains inbox freshness and reader cutover;
STATE-WP-0079 retains strangler execution. Public exposure remains gated by
RAPPCOREHUB-WP-0002 and the new security acceptance, with explicit approval.
No authentication authority or new permanent feature belongs in State Hub or
Core Hub. The earlier stream status cells are historical foundation entries;
consult current owner files for status rather than inferring readiness here.