feat: finish ZONE-WP-0003 Engine/PIP freeze and claim mapping
Declare the layer in layer.yaml, check it against INTENT.md, and fail make check on a new Tooling client or HTTP decision surface. Record the six statute §10 artifacts for the 2026-08-23 cut, name access-engine on the README, and offer a non-schema PIP field mapping to Taxonomy. Assistant: grok Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
This commit is contained in:
parent
e9d0fecede
commit
acfd93fc86
11 changed files with 682 additions and 35 deletions
16
README.md
16
README.md
|
|
@ -1,13 +1,15 @@
|
|||
# zone-engine
|
||||
|
||||
Offline reference conformance for NetKingdom **security zones**. This repository
|
||||
validates workload membership and admission, projects only explicit
|
||||
owner-versioned control profiles, checks time-boxed exception fixtures, and
|
||||
verifies the lineage of the canonical standard.
|
||||
Engine-layer **PIP** for NetKingdom **security-zone** identity and membership,
|
||||
retained as offline reference conformance. This repository validates workload
|
||||
membership and admission, projects only explicit owner-versioned control
|
||||
profiles, checks time-boxed exception fixtures, and verifies the lineage of
|
||||
the canonical standard.
|
||||
|
||||
It is not a service or policy decision point. Canon is published by
|
||||
`net-kingdom`; flex-auth and each enforcement-point owner retain live policy
|
||||
authority.
|
||||
It is not a live engine, not a PEP, and not a policy decision point. Canon is
|
||||
published by `net-kingdom`. `access-engine` (currently `flex-auth`) is the
|
||||
only PDP; each enforcement-point owner retains live policy and failure-mode
|
||||
authority. Layer declaration: `INTENT.md` frontmatter and `layer.yaml`.
|
||||
|
||||
## Checks
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue