The workplan is finished; the retirement section no longer describes it
as the revision still underway.
Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
Updated by fix-consistency on 2026-08-29:
- update .custodian-brief.md for zone-engine
Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
Declare the layer in layer.yaml, check it against INTENT.md, and fail
make check on a new Tooling client or HTTP decision surface. Record the
six statute §10 artifacts for the 2026-08-23 cut, name access-engine on
the README, and offer a non-schema PIP field mapping to Taxonomy.
Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
Intake absorbed into ZONE-WP-0003; gate-house notified that this
repository has declared Engine/PIP under v0.7.
Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
Updated by fix-consistency on 2026-08-29:
- update .custodian-brief.md for zone-engine
Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
Sibling repos already ignore this directory. It blocked registrar
reconciliation of ZONE-WP-0003 because the worktree was dirty.
Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
Assent to ZONE-IN-0001 in this repository's own voice: layer Engine, role
PIP, offline reference remaining the catalogued surface. Align INTENT,
SCOPE, and GOAL with accepted statute v0.7 and companion v0.2. Record the
scope-against-intent review and open ZONE-WP-0003 for the mechanical
remainder. Do not reopen the no-runtime decision.
Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
Regenerated by fix-consistency; adds the inbound layer-declaration intake.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
The layer model is now published as
net-kingdom/canon/standards/security-layer-model_v0.1.md (proposed) and
ratified by gate-house GH-DEC-2026-001. The note previously said the
standard was not yet written.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Records this repository's layer in the NetKingdom IT-security layer model
(Taxonomy / Tooling / Engines / Staff) and what should change in this INTENT
as a result. Links to the review that established the model:
gate-house/history/2026-08-28-security-layer-model-and-gate-house-recut.md
The note flags pending adaptation only; the body is unchanged.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
Records absent from central carried random pre-ADR-007 identifiers minted by
the retired local hub, which C-06 refused as stale references. Deriving from
the canonical record id takes no identity from anything.
Refs CUST-WP-0068-T06
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
T02 said no join key exists — too strong. The correction said the workload side
exists "and most of the join with it" — too optimistic, and it was an inference
from structure rather than a measurement. Computed, the join matches exactly one
lane: issue-core-ingestion-api-key.
rapp-qonto-keycape-client demonstrates the predicted naming failure: the path
offers keycape-client and rapp-qonto while the rapp declares name qonto, so
neither candidate matches.
The gap is therefore not a missing key but missing declarations. Thirteen lanes
name something plausible that no rapp declares as a workload; thirteen more are
not KV addresses at all.
This blocks stance modelling rather than unblocking it, and the tempting escape —
binding zones to something other than a workload for lanes that have none —
would quietly undo the subject decision. Recorded as a decision for repo-manager
and net-kingdom rather than resolved here.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
T02 concluded no registry carries a lane-to-workload join key. Too strong — it
was derived from ops-warden's catalog alone, which is the one place a workload
declaration would not live.
rapp-*/declarations/rapp.yaml declares workload_identity with
data_classification, criticality, readiness_state and bound_reefs for nine
workloads. ops-warden's dataclass_floor already maps synthetic/internal/
confidential/restricted to M0-M3. So workload -> classification -> minimum
maturity is a shared vocabulary spanning two repos already, and it is the
operator's maturity-derived default half-implemented by accident. criticality
is the other half and no control reads it yet.
Three real defects replace the blocking unknown: the lane-to-workload key is
only derivable by parsing path_template, whose convention is inconsistent
(rapp-qonto/keycape-client parses a bundle as a workload) and whose names
disagree with workload_identity.name; rapps declare "public" which
dataclass_floor does not map; and nine declared workloads do not cover ~17
catalog path identities.
Consequence for ownership: zone-engine does not need to build a workload
registry. It consumes rapp declarations plus dataclass_floor, and asks
ops-warden for one explicit field.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The lane-to-workload join moves from a noted gap to the critical path: with no
workloads in the corpus there is nothing to attach an admission standard to, and
the honest answer may be that the join belongs to whatever declares workloads
rather than to zone-engine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Operator direction. The T02 analysis concluded "a zone is a property of the
lane", which mistook the corpus for the subject — ops-warden's catalog is a
credential surface with no workloads in it, so lane properties were the only
thing available to partition. Partitioning what is available is not the same as
finding what policy applies to.
Three roles: the repo providing the software SUGGESTS a posture for running it;
the workload and its responsible party DECLARE the scrutiny applied, and are the
policy subject; the zone REQUIRES a standard for admission. A workload is not
labelled with a zone, it qualifies to run in one.
This is canon's existing mechanism, not a new one. Decision 8.2 already splits
authority this way and joins tier minima by machine, precisely so a checkable
constraint does not depend on someone remembering a signature; Decision 5.6
already ruled stance behaves as a tier minimum under it. It also dissolves the
grade-versus-acceptance question raised for T03 — they are the two sides of that
join.
Consequence: the four bands survive as membership inputs, demoted from
conclusions, and the missing lane-to-workload join is not a tidy-up. It is the
model. M0-M3 already grades workloads, which is the side of the join that exists.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Operator direction: an ungraded lane inherits the default its maturity context
implies — accepted in experimental context, high or critical in production.
M0-M3 is the right ladder and already carries rank, phase, max_dataclass and
promotion gates; what it lacks is a join to lanes, which is T02's gap.
.repo-classification.yaml category cannot carry it: railiance-platform, which
runs production OpenBao and owns three of RISK-F-0003's five exposed lanes, is
category tooling, while net-kingdom, a canon docs repo, is product. It orders
work mode, not blast radius.
Also records that maturity must come from the lane's owner, not the repo holding
the catalog, and that 'accepted' is an acceptance rather than a grade — it needs
an owner and an expiry, so it is a second field, not a rung.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Four bands, derived rather than invented, each of the 27 catalog lanes in
exactly one: Decided (1), Fronted (10), Covered (12), Signposted (4).
The finding is that delegation.mode — introduced by ops-warden WP-0030 to answer
a governance question — predicts operational danger better than the field named
risk. Ten of eleven high-risk lanes are interim, eight of those exec_capable.
Two results that constrain T03 and T04. The three existing controls each cut the
estate differently (1, 13 and 11 lanes) with only 8 in the overlap, so stance is
per control per zone and never per zone alone. And the posture registry shares no
join key with the catalog, so environment posture and M0-M3 compose in principle
but cannot be joined today without inventing a mapping — fabrication under §6.
The residue is the most valuable output: 14 of 27 lanes carry no risk value, and
is_high_risk is risk == "high", so the agent read-boundary never fires for them.
Five are exec_capable. Routed to risk-nexus as RISK-F-0003.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
GOAL.md still carried the first-draft invariant — "nothing this repo builds sits
synchronously in a decision path" — after flex-auth's review had rejected it as
a latency guarantee wearing an authority guarantee's clothes. Under that wording
zone-engine could compile enforced: false for a lane, flip warden sign from deny
to allow with no flex-auth policy change, and be literally compliant. Replaced:
identity and membership here, effect in a flex-auth policy package. Compiled-not-
queried is demoted to a consequence of that, which is what it always was.
SCOPE now records what the two reviews settled rather than what was proposed:
separate standard (canon Decision 5.6), membership declared in tenancy.yaml's
reserved zones: key, stance out of scope for controls flex-auth decides, the
fail-open axis modelled PEP-side because a PDP structurally cannot express it,
organization_posture an input rather than a declaration field, and reefs not
ours. Plus the two inherited constraints: the dead trust_zone field already
sitting where membership would go, and flex-auth's lack of a reload path.
INTENT.md states the argument, including what would falsify the repo — the
exception lifecycle not needing a runtime is called out as a legitimate outcome
that should archive this repo rather than keep it for its own sake.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Amended by net-kingdom as canon owner of tenancy-posture_v0.1.
T01: enforcement stance is a sibling canon standard, not a seventh axis (the six
ladders are monotone and stance is not; and a descriptive framework cannot carry
a prescriptive axis without handing out its own exemptions). Ownership confirmed;
the repo is not archived. Declaration surface is tenancy.yaml's reserved zones:
key, not a new root file.
T02: the reef question is struck — the unreconciled pair is reef vs P/V and it is
canon's defect (NK-WP-0027), not this model's scope. organization_posture: do not
fold in, consume as an input.
T05: carrier file settled; only the shape inside zones: remains open.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Reviewed as the only policy decision point. Four task amendments:
T01 - the 'only PDP' invariant guards latency, not authority. Compiled
data that determines an outcome still decides. Tightened wording:
zone-engine owns membership, flex-auth policy owns stance.
T03 - split membership from stance rather than rejecting option (c)
wholesale. Stance for the pre-sign gate belongs in the policy package
because registry content is absent from decision provenance. Also:
fail-open is a PEP property and no PDP can express it.
T05 - no registry schema change needed; metadata/attributes already
flatten into rego input. But trust_zone is a live name collision -
a hardcoded 'platform' constant no policy reads.
T04 - flex-auth loads registry and policy once at process start with
no reload path, so an inert compiled exception expires only by human
redeploy. Enforced expiry requires a not_after evaluated in rego.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Enforcement controls in this estate have been repo-wide booleans. ops-warden's
flex-auth pre-sign gate was the first to become flippable, and flipping it would
have made flex-auth a hard dependency of every warden sign — including the SSH
certs the ops-bridge tunnels depend on, one of which carries the policy call.
Uniform enforcement across an estate under deep refactor hardens exactly the
access needed to perform the refactor. Deferred under ops-warden ADR-0006; this
repo is what that ADR defers to.
Seeded deliberately without a schema. ZONE-WP-0001 produces a model and a canon
draft, not an API: an engine that ships a wire format before it has partitioned
the real estate defines the model by accident. Whether a runtime is warranted is
an output of the exception-lifecycle task, not an assumption.
Invariants set now, because they are the ones easy to lose later: flex-auth
stays the only PDP and receives membership by compilation, not a synchronous
lookup in a latency-critical decision path; placement (reefs) is not posture;
accuracy not altitude, per tenancy-posture v0.1 §6.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>