the-custodian/canon/architecture
codex 1674ea550d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
ADR-008: relocate the multi-tenancy framework to NetKingdom canon
Multi-tenancy is part of the IT-security framework NetKingdom provides, so it
belongs beside the IAM Profile and the tenant-engine boundary contract rather
than in the work-factory canon. Operator decision.

Relocation surfaced two things a review would have caught embarrassingly late.

NetKingdom's accepted platform-identity-security-architecture has used the word
plane since July for a trust and deployment layer - bootstrap, platform
control, tenant. This framework was using the same word for an independent
dimension of concern. Two senses of one word in one canon is precisely the
concept-ownership collision the estate is careful about, and the newcomer
yields: they are now axes. The rename is also just better, since a posture
vector is a point in five-dimensional space.

That same document also disproves the framework's opening line. It has
described the trust model, the tenant model and a capability progression since
2026-07-23, so the claim that the estate had never written down what it was
building was wrong. The accurate and narrower claim is that nothing said how
far a given service had got, or could hold several answers at once.

Stub left behind so the ADR-008 identifier resolves. The renderer moved to
policy-nexus, which owns publication.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:40:59 +02:00
..
adr-001-workplans-as-repo-artefacts.md feat(terminology): prose sweep tool and custodian workplan cleanup (CUST-WP-0055 T04) 2026-07-08 16:35:37 +02:00
adr-002-custodian-agent-runtime-design.md feat(CUST-WP-0001): implement Custodian Agent Runtime bootstrap 2026-03-12 22:36:24 +01:00
adr-003-materialized-derived-state.md docs(adr): ADR-003 — Materialized Derived State with Fingerprint Invalidation 2026-03-20 01:54:21 +01:00
adr-004-connectivity-first-network-posture.md ADR and Runbook artefacts 2026-03-27 00:16:09 +01:00
adr-005-cross-repo-workplans-project-repos.md docs(canon): define prj- project repository flavor 2026-08-09 17:24:07 +02:00
adr-006-canon-federation-concept-ownership.md docs(canon): ADR-006 accepted — R7 places evidence pair in dedicated itc-evid 2026-08-17 10:03:15 +02:00
adr-007-workplan-identity-and-repo-worker-topology.md docs(canon): renumber ADR-008/009 -> ADR-010/011 after ID collision 2026-08-17 13:04:04 +02:00
adr-008-multi-tenancy-model.md ADR-008: relocate the multi-tenancy framework to NetKingdom canon 2026-08-17 15:40:59 +02:00
adr-010-hub-authority-and-local-cache-model.md docs(canon): renumber ADR-008/009 -> ADR-010/011 after ID collision 2026-08-17 13:04:04 +02:00
adr-011-federated-namespaces-and-reconciliation-limits.md docs(canon): renumber ADR-008/009 -> ADR-010/011 after ID collision 2026-08-17 13:04:04 +02:00