diff --git a/INTENT.md b/INTENT.md index b6b281a..9c125fd 100644 --- a/INTENT.md +++ b/INTENT.md @@ -1,5 +1,20 @@ # INTENT — whitehat-security +> **NetKingdom layering review — 2026-08-28.** This repository's role was reviewed +> against the NetKingdom IT-security layer model: **Taxonomy → Tooling → Engines → +> Staff**, layered by determinism and by the kind of artifact each layer produces. +> Findings and the argument behind them: +> `gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md`. +> The model as currently stated is `gate-house/INTENT.md` § "Where Gate House Sits"; +> it is ruled to become a `net-kingdom/canon/standards/` standard, not yet written. +> +> The layer rule that binds every repository: **Staff never touches tooling +> directly. It acts only through engine APIs.** +> +> **This repository is Staff — interactive, non-deterministic; offensive validation.** Add the layer label and the Staff invariant. whitehat-security executes gate-house's assurance specifications (T-01…T-10 of the Active Secrets Management Canon) as one of its targets, and findings return through the conformance loop: gate-house asserts an invariant, the engines implement it, whitehat tries to break it, kings-guard observes it in operation, findings return to gate-house as doctrine change. The specifications are gate-house's; the attack, and the verdict on whether the control actually held, are whitehat's. +> +> *This note records what should change. The body below is not yet adapted.* + ## Why this repo exists `whitehat-security` is **NetKingdom's offensive security facility**. It attacks