zone-engine/history/2026-08-29-layer-change-artifacts.md
tegwick acfd93fc86 feat: finish ZONE-WP-0003 Engine/PIP freeze and claim mapping
Declare the layer in layer.yaml, check it against INTENT.md, and fail
make check on a new Tooling client or HTTP decision surface. Record the
six statute §10 artifacts for the 2026-08-23 cut, name access-engine on
the README, and offer a non-schema PIP field mapping to Taxonomy.

Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
2026-08-29 12:49:24 +02:00

4.1 KiB

id type title status recorded standard
ZONE-LAYER-CHANGE-2026-08-23 layer-change-record Statute §10 artifacts for the 2026-08-23 zone-engine layer cut accepted 2026-08-29 net-kingdom/canon/standards/security-layer-model_v0.7.md

Statute §10 artifacts — the 2026-08-23 layer cut

Statute §10 writes the layer-change procedure from this repository's case: the runtime hypothesis was falsified, and the Engine remained as offline reference conformance. The six artifacts are gathered here so a reviewer does not have to reconstruct them from workplan history.

A later live API, decision surface, or compiled stance would be a new cut and would need its own six artifacts plus assent from every repository whose boundary moves. This record does not authorize that.

1. Before / after INTENT.md

Before (through 2026-08-23) After (2026-08-29)
Desired sentence Not yet sayable Sayable; standard adopted
Runtime Hypothesis under test Falsified; cheaper answer taken
Layer Unstated in this repository's voice Engine, role PIP
Surface Assumed an engine might be needed Offline reference conformance
PDP line flex-auth is the only decision point Same ruling; ruled name access-engine (currently flex-auth)

Before-state: history/2026-08-23-retain-reference-decision.md, history/2026-08-23-scope-against-intent.md, and the 2026-08-23 body of INTENT.md retained as design history.

After-state: INTENT.md frontmatter (layer: Engine, role: PIP) and the 2026-08-29 declaration prose. Machine-readable twin: layer.yaml.

2. Client inventory

Contact Before After
Tooling-layer clients (OpenBao, key-cape, datastore) none none
HTTP authorization decision surface none none
Live Engine API none none
Python tools offline resolver, exception checker, lineage checker same
Non-Tooling State Hub work records via CLI / agent sessions same; recorded in layer.yaml

There was no Tooling client to retire and none to add. tools/ imports the standard library and PyYAML only.

3. Gap inventory

Kind Before After
§5.3 declared Tooling contacts none none
Unowned capabilities this repository currently owes none none
Live Engine API not owed; catalog records the offline form still not owed

A missing live API is not a §5.3 gap. Closing it in place would reverse the cut this record describes.

4. Assent list

No new boundary moved on 2026-08-29. The cut of 2026-08-23 was already assented in practice by the two consuming owners:

Repository Evidence Boundary
flex-auth (access-engine) FLEX-WP-0016 adoption; profile owner in profiles/netkingdom-build-v0.1.yaml; review of ZONE-WP-0001 remains the only PDP; stance stays in its policy package
ops-warden retired policy.enabled; PEP failure modes; adoption evidence 2026-08-22/23 consumes membership; owns unreachable-engine stance
net-kingdom published security-zones_v0.1 (still proposed) canon publication
gate-house §4 catalog row names the offline disposition; ZONE-IN-0001 requested the own-voice declaration layer model

A future live surface would require fresh assent from at least access-engine and ops-warden.

5. State-migration decision

history/2026-08-23-retain-reference-decision.md. There was no live state to migrate: no API, no store, no consumer registry. Consumers already read declarations in owning repos and policy in owner packages. Retention is of fixtures, lineage, and offline tools.

6. Permission freeze

Until a later cut carries its own six artifacts:

  • no live API, daemon, database, controller, scheduler, or reload path;
  • no authorization decision surface and no cached verdict;
  • no stance compiled into membership, and no local profile change that alters a live effect;
  • no PEP, and no unreachable-engine stance map published from this repository;
  • no Tooling-layer client.

tools/check_layer_conformance.py is the freeze's check: a new OpenBao import or an /authorize helper fails make check.