Refresh stale scope and architecture notes to match shipped state

SCOPE.md still said TEN-WP-0008 was "ready, not done" two paragraphs
above its own table listing staged promotion as shipped, and its list of
finished workplans omitted 0008 and 0011. All twelve workplans are
finished; say so once.

.claude/rules/architecture.md still described `guardrail/` as a reserved,
unimplemented namespace and the production store as TBD. Guardrails
shipped in TEN-WP-0006/0007 and PostgreSQL became the production store in
TEN-WP-0009. Also corrects the live-lookup caller to `access-engine`,
matching SCOPE.md and the boundary contract.

No behaviour change; 287 tests pass unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HHwvAEQfmzLHtrFGhXtVjq

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 823014@bnt-lap001
Assistant-Session: 2a0786b1-efea-4c38-959b-6e86a493f259
This commit is contained in:
tegwick 2026-09-07 00:21:03 +02:00
parent ba849e3fbe
commit ec41920be6
2 changed files with 15 additions and 13 deletions

View file

@ -6,14 +6,16 @@ convention). Layers:
- `domain/` — tenant, grouping, capability-role, and plan-grant models; pure,
no framework dependency.
- `store/` — persistence for tenant records and the role/plan grant audit
trail. Starts in-memory/SQLite for early workplans; production backend TBD.
trail. In-memory and SQLite back development and tests; PostgreSQL is the
production store (`TEN-WP-0009`).
- `api/` — three surfaces per the boundary contract: a cache-read API
(`key-cape` calls at token issuance), a live-lookup API (`flex-auth` calls
synchronously for high-stakes decisions — must fail closed, never open),
and a write API (grant/revoke/plan mutations, authorization-gated by
`flex-auth`, not self-authorized).
- `guardrail/` — reserved namespace, not implemented yet (spend limits,
entity/action counts).
(`key-cape` calls at token issuance), a live-lookup API (`access-engine`
calls synchronously for high-stakes decisions — must fail closed, never
open), and a write API (grant/revoke/plan mutations, authorization-gated
by `flex-auth`, not self-authorized).
- `guardrail/` — shipped (`TEN-WP-0006`/`0007`): spend / entity-count /
action-count ceilings resolved as a total function of grouping, plan,
override, and lifecycle. Contract: `docs/tenant-guardrail-policy.md`.
Full ownership boundary and API contract:
`net-kingdom/canon/standards/tenant-engine-boundary-contract_v0.1.md`.

View file

@ -86,12 +86,12 @@ the decision, not a decision.
## Current State
Production service, not a bootstrap. Finished workplans `TEN-WP-0001`
through `TEN-WP-0007`, `TEN-WP-0009`, and `TEN-WP-0010` shipped the domain
model, the three boundary-contract APIs, the `flex-auth` write authorizer,
lifecycle, guardrails, PostgreSQL as the production store, and mutable
grouping. `TEN-WP-0008` (staged-promotion onboarding) is still `ready`,
not done.
Production service, not a bootstrap. Workplans `TEN-WP-0001` through
`TEN-WP-0011` are all `finished`: they shipped the domain model, the three
boundary-contract APIs, the `flex-auth` write authorizer, lifecycle,
guardrails, PostgreSQL as the production store, mutable grouping,
staged-promotion onboarding, and the security-layer conformance surfaces.
No workplan in this repo is currently open.
| Surface | Shipped | Notes |
| --- | --- | --- |