docs: finish security zone adoption workplan

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
tegwick 2026-08-22 15:40:55 +02:00
parent 221a856132
commit a211d61e70
6 changed files with 68 additions and 22 deletions

View file

@ -130,17 +130,19 @@ Their answers are binding on this repo and are recorded in the workplan.
## Current state (2026-08-22)
`ZONE-WP-0001` is active. T01T05 are complete: ownership is confirmed, the
estate is partitioned, stance and failure mode are modelled, the exception
lifecycle requires **no zone-engine runtime**, and the declaration/compiler
contract is drafted. The integrated owner draft is
`ZONE-WP-0001` is finished. T01T05 established the model: ownership is
confirmed, the estate is partitioned, stance and failure mode are modelled, the
exception lifecycle requires **no zone-engine runtime**, and the
declaration/compiler contract is drafted. The integrated owner draft is
`docs/security-zones_v0.1.md`.
Net-kingdom Decisions 5.6.1 and 5.6.2 settle the workload boundary. Operational
execution units declare authoritative workload identity directly in
`tenancy.yaml`; absence resolves to `unknown`, never inference. T06 is offering
the draft for canon publication and T07 remains adoption. No API, storage, or
wire schema has been shipped.
`tenancy.yaml`; absence resolves to `unknown`, never inference. The standard is
published in net-kingdom canon, and T07 proves adoption in ops-warden and
flex-auth with zone-engine compiling both declarations. No API, storage, or
synchronous lookup has been shipped because the exception lifecycle showed
that none is needed.
---