ADR-011 decision 7 keys derivation on (namespace, identifier), which
separates forks but not collisions inside one namespace. The ecosystem is at
N1, a single implied namespace, and a 2026-08-21 fleet scan finds 20 reused
identifiers across 48 files all inside it. So ADR-011 alone does not satisfy
decision 2's uniqueness prerequisite.
Ruled: C2 derives for live records only; archived records keep frozen minted
identifiers. This reconciles Migration option 2 with the uniqueness
derivation needs, and cuts the remediation surface from 48 files to 11.
Records the two consequences that follow -- un-archiving is a collision
hazard, and derivation is not retroactive -- and why treating a repository as
the namespace was rejected.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Complete contents of the suggestion-backlog capability at retirement: 10
suggestions, 10 notes, 5 relevance bumps, raised 2026-07-06 to 2026-07-16.
All closed as declined in the 2026-07-21 intake migration; none promoted.
Kept here rather than in state-hub because state-hub is being archived and
this record must outlive it -- same reasoning as retired-legacy-interfaces.md.
Mutations already 410 since CUST-WP-0061-T06; reads were held open only to
keep this history reachable. This file is what makes removing them safe
(slice E1, STATE-WP-0079-T05).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Fleet-level record of legacy interfaces retired under the State Hub
retirement program. Kept here rather than in state-hub because state-hub is
being archived -- once it is read-only its legacy-meter tables stop being
queryable in practice, and this needs to outlive that.
Records the 15 workstream->workplan aliases retired on 2026-08-20 under
STATE-WP-0079-T05 slice E2, the one retired earlier, and the 4 still held
with the reason each is held. Documents the retirement standard including
the volume-scaled quiet ladder and why it exists.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Reworks federation from binary rules into the plane/ladder/posture form from
ADR-008 (Four Planes), reusing its vocabulary rather than adding a second
maturity language to the canon.
Four planes: Namespace, Autonomy, Reconciliation, Substrate, each with a
ladder. Draft-1's 'records fork, effects do not' becomes the S ladder.
Posture is declared in the repo per ADR-010 decision 4; the ecosystem's own
posture is recorded honestly as N1 U1 R1 S1.
Key additions: conformance is accuracy not altitude; an anti-overclaim rule
stating that namespace qualification is N-plane movement only and does not
make anything federation-capable, with a commercial clause for
instance-per-client claims; the reconciliation tier is now DERIVED from
participants' postures (any S3 entails T3), so rejoining cost is computable
before a fork exists rather than discovered during reconciliation; evidence
definitions per level; and guard via rmgr conform.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Multi-tenancy is part of the IT-security framework NetKingdom provides, so it
belongs beside the IAM Profile and the tenant-engine boundary contract rather
than in the work-factory canon. Operator decision.
Relocation surfaced two things a review would have caught embarrassingly late.
NetKingdom's accepted platform-identity-security-architecture has used the word
plane since July for a trust and deployment layer - bootstrap, platform
control, tenant. This framework was using the same word for an independent
dimension of concern. Two senses of one word in one canon is precisely the
concept-ownership collision the estate is careful about, and the newcomer
yields: they are now axes. The rename is also just better, since a posture
vector is a point in five-dimensional space.
That same document also disproves the framework's opening line. It has
described the trust model, the tenant model and a capability progression since
2026-07-23, so the claim that the estate had never written down what it was
building was wrong. The accurate and narrower claim is that nothing said how
far a given service had got, or could hold several answers at once.
Stub left behind so the ADR-008 identifier resolves. The renderer moved to
policy-nexus, which owns publication.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The page and the ADR had already diverged once. They are now one source: the
markdown is authoritative and the page is generated, never hand-edited.
The renderer recognises conventions the document already uses rather than
requiring extra markup, so the source stays a readable document. A table whose
first column is **X0**/**X1** becomes a level ladder; a table headed Threat
becomes the threat matrix; a table with a Kind column gets mechanical and
adversarial chips; a table headed "E \ P" becomes the two-axis grid; ## N.
headings build the section rail.
Stdlib only, per the structure-not-tooling stance. A publishing step that needs
its own toolchain is a publishing step that stops being run - the same
reasoning tenant-engine used for its pin check.
One real consequence beyond deduplication: the E x P matrix had existed only on
the page, so the canonical document did not contain its own central diagram.
It is now a table in the markdown, which is where it should always have been.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>