diff --git a/docs/estate-partition-2026-08-19.md b/docs/estate-partition-2026-08-19.md index d46646f..38b15e2 100644 --- a/docs/estate-partition-2026-08-19.md +++ b/docs/estate-partition-2026-08-19.md @@ -216,7 +216,7 @@ The missing join found in §4 is therefore not a tidy-up. **It is the model.** > **Corrected 2026-08-20.** "No registry carries a join key" was too strong — it > was concluded from ops-warden's catalog alone, the one place a *workload* > declaration would not live. `rapp-*/declarations/rapp.yaml` declares -> `workload_identity` with `data_classification` and `criticality` for nine +> `workload_identity` with `data_classification` and `criticality` for eight > workloads, and ops-warden's `dataclass_floor` already maps classification to > `M0`–`M3`. The chain exists and spans two repos. What is genuinely missing is > an explicit `workload:` field on catalog entries — the key is currently only diff --git a/workplans/ZONE-WP-0001-security-zone-model.md b/workplans/ZONE-WP-0001-security-zone-model.md index 0d79012..dc84296 100644 --- a/workplans/ZONE-WP-0001-security-zone-model.md +++ b/workplans/ZONE-WP-0001-security-zone-model.md @@ -337,7 +337,7 @@ it.** T02 concluded no registry carries a join key. That was too strong; it was derived from ops-warden's catalog alone, which is the one place a workload declaration would *not* live. -`rapp-*/declarations/rapp.yaml` is the workload declaration surface. **Nine** +`rapp-*/declarations/rapp.yaml` is the workload declaration surface. **Eight** rapps declare `workload_identity` (`name`, `principal`, `service_account`, `tenant`) together with `data_classification`, `criticality` (`low`/`medium`/`high`/`critical`), `readiness_state`, and `bound_reefs`. @@ -366,7 +366,7 @@ blocking unknown: 2. **Vocabulary mismatch.** rapps declare `public`, which `dataclass_floor` does not map. `rapp-policy-nexus` is `public` today, so the floor cannot grade it. One of the two vocabularies must move; canon owns `DataClassification`. -3. **Coverage is partial.** Nine workloads are declared; ops-warden's catalog +3. **Coverage is partial.** Eight workloads are declared; ops-warden's catalog yields ~17 distinct path identities. The unmatched remainder is the interesting set — it is where a lane exists for something that is not a declared workload at all.