Consume authoritative workload reference contract

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
tegwick 2026-08-22 14:07:01 +02:00
parent 0c3131de48
commit a51039330c
2 changed files with 59 additions and 8 deletions

View file

@ -302,6 +302,15 @@ returns `unknown` without manufacturing a zone. The unresolved `public`
DataClassification floor is handled honestly as `unknown` pending
info-tech-canon's ruling; it no longer blocks the model.
Repo-manager subsequently accepted `RMGR-ADR-004` and the v1 workload-reference
contract. Managed deployables resolve through the explicit
`(rapp_id, workload_identity.name)` pair with optional `deployable`; catalog
owners distinguish workload-applicable subjects from native `not-applicable`
actors, actions, lanes, patterns, and resources. This sharpens rather than
reopens canon's ruling: the executing unit is the workload, while the action or
resource it handles is not. All omitted or unresolved applicable references
remain `unknown`.
**Operator direction 2026-08-19 — defaults derive from maturity, not from
nothing.** An ungraded lane must not inherit the safest-for-the-tool default; it
should inherit the default its *maturity context* implies. Early or experimental
@ -661,6 +670,11 @@ flex-auth was asked to accept or amend the pre-sign stance rows before adding
them to a policy package. Adoption evidence, implementation, and the required
fresh caller-identity check remain open.
Repo-manager adoption/proof is linked as `RMGR-WP-0010-T07` to this task
(`ZONE-WP-0001-T07`, State Hub task
`c7ea24df-8aa9-4ead-ba3a-033aa5201c21`). Its accepted v1 tuple and explicit
`unknown`/`not-applicable` distinction are now consumed by the draft.
## Related
- ops-warden `ADR-0006` — enforcement is zone-scoped, never a global flag