quality_dor_note: "Gaps are evidenced against security-layer-model v0.7, companion v0.2, and the shipped offline resolver; owners, stop conditions, and the no-runtime freeze are explicit."
`INTENT.md` already declares `layer: Engine` and `role: PIP` in this
repository's own voice. This workplan makes that declaration checkable and
closes the remaining documentary gaps. It does not add a live API.
## Why these gaps are the relevant ones
| Priority | Gap | Why address it here |
| --- | --- | --- |
| P0 | No `layer.yaml` or conformance check | Statute §11 is mechanical; a new Tooling client or decision surface would land as the small convenience §6 warns about |
| P0 | `ZONE-IN-0001` still open after the declaration | gate-house asked for our voice; §14 still counts us among the silent nine |
| P1 | Statute §10 artifacts for the 2026-08-23 cut are incomplete | The procedure was written from this case; the freeze is the checkable piece |
| P1 | `README.md` still names only `flex-auth` | Consumer-facing docs must use the ruled PDP name |
| P1 | Resolver output is membership, not a claim | Statute §18 wants claims; §17 forbids inventing the schema here |
A live Engine API, a PEP stance map, compiled stance, reef/zone composition,
and the `flex-auth` repository rename are intentionally excluded.
## Authority and dependencies
- **gate-house / net-kingdom** own the statute and the §4 catalog. This plan
declares into that catalog; it does not edit it.
- **`access-engine` (currently `flex-auth`)** owns the PDP, policy packages,
and the governed rename. This plan uses the ruled name in prose and leaves
fixture owner identities as `flex-auth` until that rename lands.
- **Taxonomy** owns the request-claim schema (statute §17, unassigned). This
plan offers a field mapping, not a schema.
- **zone-engine** owns the declaration, the conformance check, the freeze
record, and the PIP mapping note.
- **Operator action** is not required. No archive, rename, or service
deployment is in this plan.
## Boundaries
- Do not add an API, daemon, database, controller, scheduler, or reload path.
- Do not expose an authorization decision surface or cache a verdict.
- Do not compile stance into membership or change a live effect from a local
profile edit.
- Do not publish a PEP stance map; this repository is not PEP-shaped.
- Do not invent the estate request-claim schema.
- Do not map `reef-*` onto security zones.
- Do not treat observation-in-production or automatic containment as available.
- Do not fold `ZONE-WP-0001` or `ZONE-WP-0002` back open.
- Leave fixture `policy_owner` / source identities as the actual repository
names they pin.
## T01 - Machine-readable layer declaration and conformance check