user-engine/.claude/rules/repo-boundary.md
tegwick 275bfd530b
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Update SCOPE to the finished USER-WP-0001–0023 surface
Replace the WP-0015 planning note with the shipped in/out boundary,
published NetKingdom contracts, operator residuals, and an INTENT
assessment. Fill the repo-boundary neighbor list to match.
2026-08-19 14:42:28 +02:00

710 B

Repo boundary

This repo owns user-engine only: user-domain facts, identity-context mappings, projections, the optional portal, and the adapters that call neighbors.

It does not own:

  • OIDC login, tokens, passwords, MFA — key-cape / Keycloak
  • authorization decisions and protected-system registry — flex-auth
  • tenant identifier, grouping, and capability-role authority — tenant-engine
  • application-owned first-login profiles and action step-up — consuming apps
  • runtime secrets — OpenBao / railiance-platform
  • platform audit store — audit-core
  • transactional mail — email-connect
  • State Hub — state-hub
  • published policy site — policy-nexus
  • SSH certificates — ops-warden