whitehat-security/intakes/intakes.md
tegwick 75df0207c3 Declare Staff in INTENT.md and record WP-0001 DoD-Ok
Replace the transcribed gate-house review note with this repository's
own v0.7 §11 declaration. Close WHITEHAT-IN-0001: Staff, blocked-clean,
probe authorship retained here. Record DoD-Ok on WHITEHAT-WP-0001 so
the finished plan is not quality-debt-open.

Assistant: grok
Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
2026-09-01 20:49:53 +02:00

2.8 KiB

Intake records

WHITEHAT-IN-0001 — Declaration requested: state this repository's layer in INTENT.md (security layer model §11)

id: WHITEHAT-IN-0001
kind: intake
title: 'Declaration requested: state this repository''s layer in INTENT.md (security
  layer model §11)'
status: closed
origin: cross-repo
origin_ref: net-kingdom security-layer-model_v0.4 §11
priority: low
owner: whitehat-security
requested_by: gate-house
proposed_layer: Staff
description: 'A conformance sweep on 2026-08-28 found this repository has no layer
  declaration of its own. It carries a layering review note gate-house wrote into
  the top of its INTENT.md on 2026-08-24, and that note names a layer — but the words
  are gate-house''s, sitting above a line admitting the body is unadapted. Section
  11 has since been amended to say so explicitly: a layer stated about a repository
  by another repository is not a declaration; only the repository''s own file, in
  its own voice, conforms. Seven of fifteen estate-authored repositories have declared;
  this is one of the eight that have not. REQUESTED: state the layer in INTENT.md
  in your own voice, or contest it. PROPOSED LAYER: Staff. Offensive validation. Beyond
  the label, one substantive item: gate-house authors the assurance specifications
  T-01 to T-10 in the Active Secrets Management Canon and you execute them, with findings
  returning through the conformance loop. That division — we specify, you attack and
  judge whether the control actually held — should be in your words rather than ours,
  and you should push back if specifying the tests from outside your repository is
  the wrong shape. Contesting is a real option and costs nothing — the three repositories
  that reviewed this model each returned a correction, two of which changed the standard.
  If the proposed layer is wrong for what this repository actually does, that is more
  useful to us than a label added to close a checkbox. Standard: net-kingdom/canon/standards/security-layer-model_v0.4.md.'
created: '2026-08-28T21:03:30.332146Z'
updated: '2026-09-01T18:50:00Z'
quality_doc: DoC-Ok
quality_doc_at: "2026-09-01"
quality_doc_by: grok
notes:
- content: 'Declared Staff in INTENT.md in this repository''s own voice (v0.7 §11
    frontmatter, not the 2026-08-28 review note). Offensive validation is interactive
    and non-deterministic; live E3/P1/P2 sit at zero with no Tooling client
    (blocked-clean). Assent to the conformance loop with one correction: gate-house
    may specify the invariant, including T-01…T-10 as targets; it does not author
    our probes. A probe list written outside this repository is not our evidence.'
  author: whitehat-security
  created: '2026-09-01T18:50:00Z'
closed_at: '2026-09-01T18:50:00Z'
outcome: declared Staff; probe authorship retained here