zone-engine/GOAL.md
tegwick 38a186d308 Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected
GOAL.md still carried the first-draft invariant — "nothing this repo builds sits
synchronously in a decision path" — after flex-auth's review had rejected it as
a latency guarantee wearing an authority guarantee's clothes. Under that wording
zone-engine could compile enforced: false for a lane, flip warden sign from deny
to allow with no flex-auth policy change, and be literally compliant. Replaced:
identity and membership here, effect in a flex-auth policy package. Compiled-not-
queried is demoted to a consequence of that, which is what it always was.

SCOPE now records what the two reviews settled rather than what was proposed:
separate standard (canon Decision 5.6), membership declared in tenancy.yaml's
reserved zones: key, stance out of scope for controls flex-auth decides, the
fail-open axis modelled PEP-side because a PDP structurally cannot express it,
organization_posture an input rather than a declaration field, and reefs not
ours. Plus the two inherited constraints: the dead trust_zone field already
sitting where membership would go, and flex-auth's lack of a reload path.

INTENT.md states the argument, including what would falsify the repo — the
exception lifecycle not needing a runtime is called out as a legitimate outcome
that should archive this repo rather than keep it for its own sake.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 22:20:13 +02:00

61 lines
2.8 KiB
Markdown

---
repo: zone-engine
repo_flavor: project
project_status: draft
started: "2026-08-19"
---
# Goal — zone-engine
## Outcome
Enforcement rigidity is a declared, reviewable property of a named zone rather
than a boolean per repo. A control can be turned on for the band of the estate
that wants its failure mode, and left advisory where that failure mode would
stop the work. Deep refactors get relaxed rigidity through an exception that
expires on its own.
## Invariants
- **`flex-auth` remains the only policy decision point.** zone-engine is
authority over zone **identity and membership**; the **effect** of a zone on
any decision flex-auth renders is expressed in a flex-auth policy package.
The first draft of this invariant said "nothing this repo builds sits
synchronously in a decision path". flex-auth rejected that on review: it is a
*latency* guarantee, not an authority one. Compiled data that determines an
outcome is still deciding — it just decided earlier. Under the old wording
zone-engine could compile `enforced: false` for a lane, flip `warden sign`
from deny to allow with no flex-auth policy change, and be literally
compliant. Membership is ours; stance is theirs.
- **Compiled, not queried.** Membership reaches flex-auth by compilation into
the registry it already loads. This is a *consequence* of the invariant
above, not the invariant itself — flex-auth is `service_class:
latency-critical` and loads its registry once at process start.
- **A zone that can be quietly widened is not a boundary.** Every change of
stance is observable, and every exception has an enforced expiry.
- **Accuracy, not altitude** (`tenancy-posture_v0.1` §6). A repo declaring a
stricter zone than it can evidence is the failure to design against, because
it looks like progress.
- **Placement is not posture.** Reefs are a separate axis and stay separate.
- **The model precedes the schema.** No API, no storage, no wire format until
`ZONE-WP-0001` has partitioned the real estate.
## Success gates
1. The model partitions today's estate — the 27 ops-warden catalog lanes, the
actor inventory, the posture-carrying workloads — without a residue of
unexplained exceptions.
2. A canon standard is drafted and offered to `net-kingdom`, in the family of
`tenancy-posture_v0.1`.
3. At least two repos declare zones and are read by a third — a model only its
author honours is not adopted.
4. `ops-warden`'s `policy.enabled` is retired in favour of a zone-aware control,
closing `WARDEN-WP-0031-T05`.
5. Whether a runtime is needed is answered on evidence from the exception
lifecycle, not assumed.
## Project retirement
Archive when the standard is canon, the declarations are live, and either a
runtime exists with an owner or the decision that none is needed is recorded.