--- repo: zone-engine repo_flavor: project project_status: draft started: "2026-08-19" --- # Goal — zone-engine ## Outcome Enforcement rigidity is a declared, reviewable property of a named zone rather than a boolean per repo. A control can be turned on for the band of the estate that wants its failure mode, and left advisory where that failure mode would stop the work. Deep refactors get relaxed rigidity through an exception that expires on its own. ## Invariants - **`flex-auth` remains the only policy decision point.** zone-engine is authority over zone **identity and membership**; the **effect** of a zone on any decision flex-auth renders is expressed in a flex-auth policy package. The first draft of this invariant said "nothing this repo builds sits synchronously in a decision path". flex-auth rejected that on review: it is a *latency* guarantee, not an authority one. Compiled data that determines an outcome is still deciding — it just decided earlier. Under the old wording zone-engine could compile `enforced: false` for a lane, flip `warden sign` from deny to allow with no flex-auth policy change, and be literally compliant. Membership is ours; stance is theirs. - **Compiled, not queried.** Membership reaches flex-auth by compilation into the registry it already loads. This is a *consequence* of the invariant above, not the invariant itself — flex-auth is `service_class: latency-critical` and loads its registry once at process start. - **A zone that can be quietly widened is not a boundary.** Every change of stance is observable, and every exception has an enforced expiry. - **Accuracy, not altitude** (`tenancy-posture_v0.1` §6). A repo declaring a stricter zone than it can evidence is the failure to design against, because it looks like progress. - **Placement is not posture.** Reefs are a separate axis and stay separate. - **The model precedes the schema.** No API, no storage, no wire format until `ZONE-WP-0001` has partitioned the real estate. ## Success gates 1. The model partitions today's estate — the 27 ops-warden catalog lanes, the actor inventory, the posture-carrying workloads — without a residue of unexplained exceptions. 2. A canon standard is drafted and offered to `net-kingdom`, in the family of `tenancy-posture_v0.1`. 3. At least two repos declare zones and are read by a third — a model only its author honours is not adopted. 4. `ops-warden`'s `policy.enabled` is retired in favour of a zone-aware control, closing `WARDEN-WP-0031-T05`. 5. Whether a runtime is needed is answered on evidence from the exception lifecycle, not assumed. ## Project retirement Archive when the standard is canon, the declarations are live, and either a runtime exists with an owner or the decision that none is needed is recorded.