diff --git a/.claude/rules/architecture.md b/.claude/rules/architecture.md index 793ee95..8448622 100644 --- a/.claude/rules/architecture.md +++ b/.claude/rules/architecture.md @@ -6,14 +6,16 @@ convention). Layers: - `domain/` — tenant, grouping, capability-role, and plan-grant models; pure, no framework dependency. - `store/` — persistence for tenant records and the role/plan grant audit - trail. Starts in-memory/SQLite for early workplans; production backend TBD. + trail. In-memory and SQLite back development and tests; PostgreSQL is the + production store (`TEN-WP-0009`). - `api/` — three surfaces per the boundary contract: a cache-read API - (`key-cape` calls at token issuance), a live-lookup API (`flex-auth` calls - synchronously for high-stakes decisions — must fail closed, never open), - and a write API (grant/revoke/plan mutations, authorization-gated by - `flex-auth`, not self-authorized). -- `guardrail/` — reserved namespace, not implemented yet (spend limits, - entity/action counts). + (`key-cape` calls at token issuance), a live-lookup API (`access-engine` + calls synchronously for high-stakes decisions — must fail closed, never + open), and a write API (grant/revoke/plan mutations, authorization-gated + by `flex-auth`, not self-authorized). +- `guardrail/` — shipped (`TEN-WP-0006`/`0007`): spend / entity-count / + action-count ceilings resolved as a total function of grouping, plan, + override, and lifecycle. Contract: `docs/tenant-guardrail-policy.md`. Full ownership boundary and API contract: `net-kingdom/canon/standards/tenant-engine-boundary-contract_v0.1.md`. diff --git a/SCOPE.md b/SCOPE.md index b49928e..bd9385d 100644 --- a/SCOPE.md +++ b/SCOPE.md @@ -86,12 +86,12 @@ the decision, not a decision. ## Current State -Production service, not a bootstrap. Finished workplans `TEN-WP-0001` -through `TEN-WP-0007`, `TEN-WP-0009`, and `TEN-WP-0010` shipped the domain -model, the three boundary-contract APIs, the `flex-auth` write authorizer, -lifecycle, guardrails, PostgreSQL as the production store, and mutable -grouping. `TEN-WP-0008` (staged-promotion onboarding) is still `ready`, -not done. +Production service, not a bootstrap. Workplans `TEN-WP-0001` through +`TEN-WP-0011` are all `finished`: they shipped the domain model, the three +boundary-contract APIs, the `flex-auth` write authorizer, lifecycle, +guardrails, PostgreSQL as the production store, mutable grouping, +staged-promotion onboarding, and the security-layer conformance surfaces. +No workplan in this repo is currently open. | Surface | Shipped | Notes | | --- | --- | --- |