Hygiene: SCOPE stance sentence, stack/architecture stubs, first-session archive
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Record the published fail-closed PEP stance in SCOPE, fill the agent
stack and architecture stubs from the shipped layout, and retire the
first-session protocol now that USER-WP-0001–0024 exist.

Assistant: grok
Assistant-Session: 01a04cea-f0d6-7ab3-9ffd-881eb6bea6cb
This commit is contained in:
tegwick 2026-08-29 14:37:38 +02:00
parent df976512df
commit c431915d56
6 changed files with 52 additions and 16 deletions

View file

@ -103,9 +103,10 @@ not become hidden sources of profile or identity-domain truth.
user-engine must not become a hidden source of authorization truth.
Memberships, hats, and access-control facts are claims. `access-engine`
renders the decision. When `access-engine` is unreachable, shipped
behaviour is fail-closed for protected mutations; that stance still has
to be published, tested equal to the code, and recorded as stance
application rather than as a minted local decision id.
behaviour is fail-closed for protected mutations. That stance is published
in `pep-stance.yaml`, tested equal to `FlexAuthHTTPAdapter`, and recorded
as stance application (`decision_id` absent) rather than as a minted
local decision id.
Governing published contracts: