Record the operator's A11 r2 / A12 r3 approval and the GH-DEC-2026-021 follow-ups.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-09-21 13:06:55 +02:00
parent 5764669645
commit a7f550c219

View file

@ -285,3 +285,14 @@ Each reading agrees with §4, and GH-DEC-2026-019's third closing condition is m
- **net-kingdom:** the canon repository carries runtime material, `identity-provisioner/` and `sso-mfa/k8s/`.
Still open: A11 r2 and A12 r3 assent, INFD-IN-0007 (the §3 cut, outside the §11 hold), and the role vocabulary after A9.
## Follow-ups, 2026-09-21
The operator approved A11 r2 and A12 r3. The approval was relayed to gate-house under GH-WP-0004-T09 as the return for the four round members that deferred to the operator: audit-core, access-engine, ops-warden and net-kingdom. It does not stand in for approval-engine, kings-guard, informed-decision or railiance-master.
GH-DEC-2026-021's immediate changes are applied:
- **tenant-engine** (`ff0712b`) and **flex-auth** (`067d93a`) now name the accepted v0.7 in `VALIDATED_AGAINST`, and both converged on the reference detector. flex-auth kept one exemption: an empty version key is not flagged. It is justified by a Go struct field rather than by the ruling, and no declaration carries such a key. It is a candidate for removal at flex-auth's next edit of the detector.
- **ops-warden** (`3979152`): the playbook is now titled as the estate reference detector. Prose citations are recorded as not reached, with a note of what widens if A12 r3 is rejected. `intent_version` is named as a key that must not be flagged.
The reference detector flags a versioned path to any document, not only one naming the standard. GH-DEC-2026-021 §3 accepts that. No declaration carries such a path today.