diff --git a/workplans/ZONE-WP-0001-security-zone-model.md b/workplans/ZONE-WP-0001-security-zone-model.md index fa83561..05f3341 100644 --- a/workplans/ZONE-WP-0001-security-zone-model.md +++ b/workplans/ZONE-WP-0001-security-zone-model.md @@ -222,6 +222,15 @@ Answer explicitly: **Done 2026-08-19.** Full result: `docs/estate-partition-2026-08-19.md`. +> **Corrected the same day by operator direction, recorded in §7 of that +> document.** Policy is about the **workload**, not the lane; the software repo +> only *suggests*; the workload and its responsible party declare the scrutiny; +> and a zone **requires** a standard for admission — a workload qualifies to run +> in a zone rather than being labelled with one. This is `tenancy-posture` +> Decision 8.2's tier-minimum mechanism, which Decision 5.6 had already said +> stance would behave as. The four bands below survive as membership *inputs*, +> not as zones. + Four bands, each of the 27 lanes in exactly one — **Decided** (1, the only lane ops-warden decides), **Fronted** (10, owner has a front door), **Covered** (12, ops-warden proxies what it does not own), **Signposted** (4, routed, nothing @@ -312,6 +321,23 @@ field repeats the error net-kingdom rejected when it refused stance as a tenancy axis. Model them as two fields: grade (derived, defaultable) and acceptance (asserted, owned, expiring). +**Resolved by the T02 correction.** Grade and acceptance are the two sides of a +Decision 8.2 join: the zone asserts a floor, the workload asserts its posture, +and the join is mechanical. Not two fields to invent — one join to implement. + +**And the join is now the critical path.** ops-warden's catalog contains no +workloads, so there is no subject to attach an admission standard to. `M0`-`M3` +already grades workloads, which is the side that exists; what is missing is +anything declaring which workload consumes which lane. T03 cannot produce a +usable stance model until that is answered, and the honest answer may be that it +belongs to whatever declares workloads — not to this repo. + +**Build stage is a positional fact, not a concession.** The organization is in +`build`; the default stance is permissive and zones tighten by *admission*, +rather than by raising a global floor. That is what makes this model compatible +with deep refactoring instead of hostile to it, and it is the same reasoning +that produced `ADR-0006`. + **Amended by flex-auth 2026-08-19 — split membership from stance.** ops-warden's option (c) ("zones as policy-package data") was rejected wholesale because the model must govern two controls flex-auth does not evaluate. flex-auth agrees with