Declare Staff in INTENT.md and record WP-0001 DoD-Ok
Replace the transcribed gate-house review note with this repository's own v0.7 §11 declaration. Close WHITEHAT-IN-0001: Staff, blocked-clean, probe authorship retained here. Record DoD-Ok on WHITEHAT-WP-0001 so the finished plan is not quality-debt-open. Assistant: grok Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
This commit is contained in:
parent
61cff193d3
commit
75df0207c3
5 changed files with 71 additions and 13 deletions
48
INTENT.md
48
INTENT.md
|
|
@ -1,19 +1,42 @@
|
|||
---
|
||||
layer: Staff
|
||||
role: null
|
||||
standard: net-kingdom/canon/standards/security-layer-model_v0.7.md
|
||||
standard_version: "0.7"
|
||||
companion: net-kingdom/SECURITY-COMPANION.md
|
||||
declared_at: "2026-09-01"
|
||||
conformance_state: blocked-clean
|
||||
---
|
||||
|
||||
# INTENT — whitehat-security
|
||||
|
||||
> **NetKingdom layering review — 2026-08-28.** This repository's role was reviewed
|
||||
> against the NetKingdom IT-security layer model: **Taxonomy → Tooling → Engines →
|
||||
> Staff**, layered by determinism and by the kind of artifact each layer produces.
|
||||
> Findings and the argument behind them:
|
||||
> `gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md`.
|
||||
> The model is `net-kingdom/canon/standards/security-layer-model_v0.1.md` (proposed),
|
||||
> ratified by `gate-house/decisions/decisions.md` GH-DEC-2026-001.
|
||||
> **Layer: Staff.** Offensive validation. This is this repository's own
|
||||
> declaration under NetKingdom Security Layer Model v0.7 §11. A catalog row,
|
||||
> a review note, or the 2026-08-28 gate-house insert that used to sit here is
|
||||
> not a declaration. The statute is
|
||||
> `net-kingdom/canon/standards/security-layer-model_v0.7.md` (accepted). The
|
||||
> operative form is `net-kingdom/SECURITY-COMPANION.md`.
|
||||
>
|
||||
> The layer rule that binds every repository: **Staff never touches tooling
|
||||
> directly. It acts only through engine APIs.**
|
||||
> Offensive validation is interactive and non-deterministic. Acting at runtime
|
||||
> does not make this an Engine. We produce dated adversarial evidence, not a
|
||||
> decision surface and not state another layer depends on at runtime. Findings
|
||||
> leave through `risk-nexus`.
|
||||
>
|
||||
> **This repository is Staff — interactive, non-deterministic; offensive validation.** Add the layer label and the Staff invariant. whitehat-security executes gate-house's assurance specifications (T-01…T-10 of the Active Secrets Management Canon) as one of its targets, and findings return through the conformance loop: gate-house asserts an invariant, the engines implement it, whitehat tries to break it, kings-guard observes it in operation, findings return to gate-house as doctrine change. The specifications are gate-house's; the attack, and the verdict on whether the control actually held, are whitehat's.
|
||||
> **Staff never touches Tooling directly. It acts only through Engine APIs.**
|
||||
> This repository holds no OpenBao client, no database driver, and no cluster
|
||||
> mutation API. The default custody broker raises before any custody call.
|
||||
> Manifests in `plane/` are a contract for `ops-mason`, not a client. Live E3
|
||||
> and P1/P2 sit at zero until a runtime-safe engine surface and an approved
|
||||
> window exist; that is blocked-clean, not a quieter Tooling client.
|
||||
>
|
||||
> *This note records what should change. The body below is not yet adapted.*
|
||||
> **The conformance loop, in our words.** gate-house states an invariant.
|
||||
> Engines implement it. This repository designs the attack and records whether
|
||||
> that attack held. kings-guard observes operation. Findings that should change
|
||||
> doctrine return to gate-house; findings that should change a system go to
|
||||
> `risk-nexus` and the owning repo. gate-house may specify *what must hold*,
|
||||
> including T-01…T-10 of the Active Secrets Management Canon as targets. It
|
||||
> does not author our probes. A probe list written outside this repository is
|
||||
> not our evidence.
|
||||
|
||||
## Why this repo exists
|
||||
|
||||
|
|
@ -104,6 +127,9 @@ worth revisiting if conformance findings ever start getting quietly closed.
|
|||
good looks like. This repo says whether we have it.
|
||||
- **Blocking delivery.** In build mode a finding is information. If that
|
||||
changes it will be a recorded decision, not a habit that accretes.
|
||||
- **A decision surface.** Staff does not render or cache an authorization
|
||||
decision. Probe admission is fail-closed against an engagement record; it
|
||||
is not a policy decision point.
|
||||
|
||||
## The targeting rule
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue