docs: finish security zone adoption workplan

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
tegwick 2026-08-22 15:40:55 +02:00
parent 221a856132
commit a211d61e70
6 changed files with 68 additions and 22 deletions

View file

@ -326,7 +326,7 @@ evaluated where their effects occur. This requires no zone-engine runtime.
## 10. Adoption
The draft is offered to net-kingdom for publication. Adoption requires:
Net-kingdom published this standard at revision `337484a`. Adoption requires:
1. flex-auth and ops-warden accept the initial control profile or publish a
versioned replacement with total zone and `unknown` coverage;
@ -334,3 +334,8 @@ The draft is offered to net-kingdom for publication. Adoption requires:
3. a third consumer compiles or reads the resolved view; and
4. ops-warden retires `policy.enabled` and the dormant `trust_zone` constant in
the same migration.
All four gates were met on 2026-08-22. The exact consumer revisions, tests,
resolved membership digests, and live caller decision are recorded in
`docs/evidence/security-zone-adoption-2026-08-22.md` in the owning zone-engine
repository.