zone-engine/workplans/ZONE-WP-0003-security-layer-model-alignment.md
tegwick acfd93fc86 feat: finish ZONE-WP-0003 Engine/PIP freeze and claim mapping
Declare the layer in layer.yaml, check it against INTENT.md, and fail
make check on a new Tooling client or HTTP decision surface. Record the
six statute §10 artifacts for the 2026-08-23 cut, name access-engine on
the README, and offer a non-schema PIP field mapping to Taxonomy.

Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
2026-08-29 12:49:24 +02:00

11 KiB
Raw Permalink Blame History

id type title domain repo status owner assignee lane topic_slug planning_priority created updated quality_dod quality_dod_at quality_dod_by quality_dod_note origin context_paths quality_dor quality_dor_at quality_dor_by quality_dor_note state_hub_workstream_id
ZONE-WP-0003 workplan Declare Engine/PIP and freeze the offline zone-membership surface infotech zone-engine finished zone-engine grok yellow netkingdom P1 2026-08-29 2026-08-29 DoD-Ok 2026-08-29 grok layer.yaml agrees with INTENT.md; make check covers the freeze (no Tooling client, no decision surface); §10 artifacts and PIP claim mapping are cited; README uses the ruled PDP name; no live API was added. history/2026-08-29-security-layer-model-scope-against-intent.md
GOAL.md
INTENT.md
SCOPE.md
README.md
intakes/intakes.md
history/2026-08-23-retain-reference-decision.md
history/2026-08-29-security-layer-model-scope-against-intent.md
DoR-Ok 2026-08-29 grok Gaps are evidenced against security-layer-model v0.7, companion v0.2, and the shipped offline resolver; owners, stop conditions, and the no-runtime freeze are explicit. 95573eaf-0b3f-5d48-af55-231f46d7295e

ZONE-WP-0003 — Declare Engine/PIP and freeze the offline zone-membership surface

Goal

Make this repository a conforming Engine-layer PIP under NetKingdom Security Layer Model v0.7 without reversing the 2026-08-23 no-runtime decision. Declare the layer in a machine-readable form, close the declaration intake, record the already-completed layer cut, and map current membership output onto the facts a future request-claim must carry.

Source review: history/2026-08-29-security-layer-model-scope-against-intent.md. Statute: net-kingdom/canon/standards/security-layer-model_v0.7.md. Companion: net-kingdom/SECURITY-COMPANION.md v0.2.

INTENT.md already declares layer: Engine and role: PIP in this repository's own voice. This workplan makes that declaration checkable and closes the remaining documentary gaps. It does not add a live API.

Why these gaps are the relevant ones

Priority Gap Why address it here
P0 No layer.yaml or conformance check Statute §11 is mechanical; a new Tooling client or decision surface would land as the small convenience §6 warns about
P0 ZONE-IN-0001 still open after the declaration gate-house asked for our voice; §14 still counts us among the silent nine
P1 Statute §10 artifacts for the 2026-08-23 cut are incomplete The procedure was written from this case; the freeze is the checkable piece
P1 README.md still names only flex-auth Consumer-facing docs must use the ruled PDP name
P1 Resolver output is membership, not a claim Statute §18 wants claims; §17 forbids inventing the schema here

A live Engine API, a PEP stance map, compiled stance, reef/zone composition, and the flex-auth repository rename are intentionally excluded.

Authority and dependencies

  • gate-house / net-kingdom own the statute and the §4 catalog. This plan declares into that catalog; it does not edit it.
  • access-engine (currently flex-auth) owns the PDP, policy packages, and the governed rename. This plan uses the ruled name in prose and leaves fixture owner identities as flex-auth until that rename lands.
  • Taxonomy owns the request-claim schema (statute §17, unassigned). This plan offers a field mapping, not a schema.
  • zone-engine owns the declaration, the conformance check, the freeze record, and the PIP mapping note.
  • Operator action is not required. No archive, rename, or service deployment is in this plan.

Boundaries

  • Do not add an API, daemon, database, controller, scheduler, or reload path.
  • Do not expose an authorization decision surface or cache a verdict.
  • Do not compile stance into membership or change a live effect from a local profile edit.
  • Do not publish a PEP stance map; this repository is not PEP-shaped.
  • Do not invent the estate request-claim schema.
  • Do not map reef-* onto security zones.
  • Do not treat observation-in-production or automatic containment as available.
  • Do not fold ZONE-WP-0001 or ZONE-WP-0002 back open.
  • Leave fixture policy_owner / source identities as the actual repository names they pin.

T01 - Machine-readable layer declaration and conformance check

id: ZONE-WP-0003-T01
status: done
priority: high
state_hub_task_id: "ca687f30-2ad5-5243-8e48-efc34c78465c"

Add layer.yaml in the kings-guard no-contact shape, pointing at security layer model v0.7:

  • layer: engine
  • role: pip
  • tooling_contacts: []
  • non_tooling_clients lists any State Hub / work-record client, recorded as not-catalogued
  • no pep_stance path
  • catalog note: §4 Engine / PIP; offline reference conformance per the 2026-08-23 disposition

Add tools/check_layer_conformance.py and a unit test. The check must fail if:

  • layer.yaml is missing, unparseable, or disagrees with INTENT.md frontmatter;
  • a Tooling-layer client import appears under tools/ (OpenBao/Vault, cluster, direct datastore);
  • a new HTTP authorization decision surface appears.

Wire it into make check. Review dates, if any, are reported, never used as a calendar-day build failure.

Done when: layer.yaml is committed, agrees with INTENT.md, make check covers it, and a reviewer can see there are no Tooling contacts, no PEP claim, and no decision surface.

T02 - Close ZONE-IN-0001 and notify gate-house

id: ZONE-WP-0003-T02
status: done
priority: high
state_hub_task_id: "c0f726a6-def6-5318-8270-09c9de3e8678"

Close ZONE-IN-0001 in intakes/intakes.md with outcome absorbed / promoted to this workplan, recording that the proposed Engine layer is assented in this repository's own voice and that the offline PIP form is the catalogued surface, not a contest.

Notify gate-house (State Hub message or equivalent durable notice) that zone-engine has declared Engine / PIP under v0.7 so statute §14 can stop counting this repository among the undeclared nine.

Done when: the intake file is closed with a resolution that points at INTENT.md and this workplan, and the notice to gate-house exists.

T03 - Record the §10 artifacts for the 2026-08-23 layer cut

id: ZONE-WP-0003-T03
status: done
priority: medium
state_hub_task_id: "828a4c67-9644-5b27-ac97-d79563848dfc"

Write a short retrospective under history/ (or a docs/ note cited from INTENT.md) that gathers the six statute §10 artifacts for the already completed cut:

Artifact Source
before/after INTENT.md 2026-08-23 retain text vs 2026-08-29 declaration
client inventory none against Tooling; offline Python tools only
gap inventory none as §5.3 contacts; live Engine API is not a gap this repo currently owes
assent list flex-auth / ops-warden adoption already evidenced; no new boundary moves
state-migration decision history/2026-08-23-retain-reference-decision.md
permission freeze no live API, no decision surface, no compiled stance until a later cut carries its own six artifacts

Done when: a reviewer can find all six artifacts without reconstructing them from workplan history, and INTENT.md or SCOPE.md cites the note.

T04 - Align remaining consumer-facing naming

id: ZONE-WP-0003-T04
status: done
priority: medium
state_hub_task_id: "bd4955b6-dfb8-59e5-be20-f4f8ab93ae8e"

Update README.md so a first-time reader sees Engine / PIP, offline reference, and access-engine as the ruled PDP name (currently flex-auth). Do not rewrite historical evidence, workplan files, or fixture owner identities.

Confirm GOAL.md invariants already match; only patch if T01T03 drift them.

Done when: README.md, INTENT.md, SCOPE.md, and GOAL.md agree on layer, role, and PDP name, and git grep access-engine README.md INTENT.md SCOPE.md GOAL.md is the consumer-facing surface.

T05 - PIP claim-boundary note, without a schema

id: ZONE-WP-0003-T05
status: done
priority: medium
state_hub_task_id: "ee883d61-4d27-5223-826c-c37f66e3bcb4"

Write docs/pip-claim-boundary.md that:

  1. lists the facts this PIP owns today (authoritative identity, declared and effective zone, admission result and reason, membership revision, source and source revision);
  2. maps those fields onto what a future statute §17 request-claim must carry (issuer, freshness, zone membership — not stance, not failure mode);
  3. states that stance and failure mode remain owner policy and PEP configuration, consumed by access-engine as a claim or a versioned rule (statute §18);
  4. marks the mapping as a contribution to Taxonomy, not a published schema;
  5. forbids a competing claim dialect and forbids compiling those facts into registry content that determines an outcome.

Offer the note to gate-house / net-kingdom and to access-engine. Do not wait on their assent to keep the freeze.

Done when: the note is cited from SCOPE.md, tests still pass unchanged, and no new wire format has shipped.

Acceptance criteria

  • layer.yaml declares Engine / PIP, no Tooling contacts, no PEP map.
  • make check fails a new undeclared Tooling client or decision surface.
  • ZONE-IN-0001 is closed on the own-voice declaration.
  • gate-house has been notified.
  • Statute §10 artifacts for the 2026-08-23 cut are gathered in one place.
  • Consumer-facing docs use access-engine as the ruled PDP name.
  • PIP facts are mapped for a future claim schema without shipping one.
  • No live API, daemon, decision surface, or compiled stance was added.

Out of scope

  • A zone-engine API, daemon, database, controller, scheduler, or synchronous lookup.
  • Publishing a PEP unreachable-engine stance map.
  • Compiling stance into registry content or changing owner policy.
  • Inventing or publishing the estate request-claim schema.
  • Mapping Railiance reefs onto security zones.
  • The flex-authaccess-engine repository rename.
  • Promoting security-zones_v0.1 out of proposed.
  • Archiving or renaming this Forgejo repository.
  • Estate-wide reference migration of unresolved catalog entries.

Stop conditions

Stop and return to the relevant owner if implementation would require any of the following:

  • adding zone-engine to a live authorization or enforcement path;
  • making a local profile authoritative over an owner policy package;
  • inventing a claim schema and presenting it as estate canon;
  • cataloguing this repository as PEP-shaped;
  • reversing the 2026-08-23 retain / no-runtime decision without a new §10 layer-change record and assent from the repositories whose boundaries move.