Correct the subject: policy is about the workload, and a zone is an admission floor
Operator direction. The T02 analysis concluded "a zone is a property of the lane", which mistook the corpus for the subject — ops-warden's catalog is a credential surface with no workloads in it, so lane properties were the only thing available to partition. Partitioning what is available is not the same as finding what policy applies to. Three roles: the repo providing the software SUGGESTS a posture for running it; the workload and its responsible party DECLARE the scrutiny applied, and are the policy subject; the zone REQUIRES a standard for admission. A workload is not labelled with a zone, it qualifies to run in one. This is canon's existing mechanism, not a new one. Decision 8.2 already splits authority this way and joins tier minima by machine, precisely so a checkable constraint does not depend on someone remembering a signature; Decision 5.6 already ruled stance behaves as a tier minimum under it. It also dissolves the grade-versus-acceptance question raised for T03 — they are the two sides of that join. Consequence: the four bands survive as membership inputs, demoted from conclusions, and the missing lane-to-workload join is not a tidy-up. It is the model. M0-M3 already grades workloads, which is the side of the join that exists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
158efab24a
commit
ce716c4ae3
3 changed files with 108 additions and 10 deletions
9
SCOPE.md
9
SCOPE.md
|
|
@ -31,9 +31,12 @@ and this repo is what that ADR defers to.
|
|||
|
||||
## In scope
|
||||
|
||||
- **Zone identity and membership.** What zones exist, and what puts a lane,
|
||||
actor or workload in one — derived from posture already declared rather than
|
||||
a fourth hand-maintained list.
|
||||
- **Zone identity and admission standards.** What zones exist, and the standard
|
||||
a **workload** must meet to be admitted to one. Security policy is about the
|
||||
running workload and whoever answers for it — the repo providing the software
|
||||
only *suggests*. A zone is a floor a workload qualifies against, not a label
|
||||
applied to it, and it is the `tenancy-posture` Decision 8.2 tier-minimum
|
||||
mechanism rather than a new one.
|
||||
- **Time-boxed exception lifecycle.** A relaxation with an expiry enforced by
|
||||
something rather than intended, plus the record of who widened what, when,
|
||||
and until when. **This is the task that decides whether this repo needs a
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue