## Repo boundary This repo owns the **secrets-engine** Lifecycle engine only (NetKingdom security layer model v0.7: Engine / Lifecycle). It does not own: - Secret custody, policy, lease, and audit backend → OpenBao / railiance-platform - SSH certificate issuance (Staff PEP) → ops-warden (`warden sign`) - Tunnels and remote transport → ops-bridge - Authorization decisions → access-engine (`flex-auth`) - Approval objects → approval-engine - Evidence custody and integrity → audit-core - Identity and claim lifecycle → user-engine / key-cape - Security doctrine and the layer model → gate-house / net-kingdom canon - Cross-system security boundary doc → net-kingdom/docs/ - Request history and progress index → State Hub (read model)