feat: finish ZONE-WP-0003 Engine/PIP freeze and claim mapping

Declare the layer in layer.yaml, check it against INTENT.md, and fail
make check on a new Tooling client or HTTP decision surface. Record the
six statute §10 artifacts for the 2026-08-23 cut, name access-engine on
the README, and offer a non-schema PIP field mapping to Taxonomy.

Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
This commit is contained in:
tegwick 2026-08-29 12:49:24 +02:00
parent e9d0fecede
commit acfd93fc86
11 changed files with 682 additions and 35 deletions

View file

@ -28,10 +28,11 @@ Declared in `INTENT.md` frontmatter, in this repository's own voice:
| Tooling contacts | none |
| Conformance | conforming for Tooling contact; the live Engine API is not a missing capability this repository currently owes |
The machine-readable `layer.yaml` form and a conformance check that fails a
new Tooling client or a new decision surface are not yet evidenced here.
Until they are, the declaration is the `INTENT.md` frontmatter and the prose
in that file.
The machine-readable declaration is `layer.yaml`. `tools/check_layer_conformance.py`
fails if that file disagrees with `INTENT.md` frontmatter, if a Tooling-layer
client appears under `tools/`, or if an HTTP authorization decision surface
appears. The six statute §10 artifacts for the already-completed layer cut
are `history/2026-08-29-layer-change-artifacts.md`.
`access-engine` (currently `flex-auth`) is the only PDP. Zone stance and
failure mode remain owner policy and PEP configuration. This repository
@ -82,8 +83,8 @@ This repository provides:
- an offline exception checker with an explicit evaluation instant, covering
grant authority, maximum duration, exclusive expiry, overlap, renewal,
wildcard rejection, and durable-authority bounds; and
- reusable manifests, profiles, exception fixtures, evidence, and 29 unit
tests.
- reusable manifests, profiles, exception fixtures, evidence, and unit
tests covering resolver, exceptions, lineage, and layer conformance.
The resolver consumes already-located declarations and already-resolved
workload-reference projections. It does not discover a fleet, repair an
@ -91,9 +92,10 @@ ambiguous join, read a live clock, or publish a consumer registry. Its profile
fixture records owner-approved v0.1 behavior; only the referenced owner policy
and PEP configuration can change a live effect.
The resolver output is a reference membership/admission record. It is not yet
a statute §17 request-claim. Taxonomy owns that schema and has not published
it. This repository must not ship a competing dialect.
The resolver output is a reference membership/admission record. It is not a
statute §17 request-claim. Taxonomy owns that schema and has not published
it. The field mapping offered to Taxonomy is `docs/pip-claim-boundary.md`.
This repository must not ship a competing dialect.
## Authority boundary
@ -140,6 +142,8 @@ decision point.
- Reproducing or extending v0.1 conformance fixtures.
- Checking direct declarations or explicit Repo Manager projections offline.
- Mapping those membership facts onto a future request-claim
(`docs/pip-claim-boundary.md`) without shipping a schema.
- Verifying a versioned owner profile is total and fully attributed.
- Testing an owner exception implementation against the lifecycle boundaries.
- Reviewing a net-kingdom canon lifecycle/content change, including the