Headless multi-application, multi-tenant security zone mangement engine.
Find a file
tegwick 158efab24a ZONE-WP-0001-T03: maturity-derived risk defaults, and what they can attach to
Operator direction: an ungraded lane inherits the default its maturity context
implies — accepted in experimental context, high or critical in production.

M0-M3 is the right ladder and already carries rank, phase, max_dataclass and
promotion gates; what it lacks is a join to lanes, which is T02's gap.
.repo-classification.yaml category cannot carry it: railiance-platform, which
runs production OpenBao and owns three of RISK-F-0003's five exposed lanes, is
category tooling, while net-kingdom, a canon docs repo, is product. It orders
work mode, not blast radius.

Also records that maturity must come from the lane's owner, not the repo holding
the catalog, and that 'accepted' is an acceptance rather than a grade — it needs
an owner and an expiry, so it is a second field, not a rung.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:23:49 +02:00
docs ZONE-WP-0001-T02: partition the estate 2026-08-19 23:08:53 +02:00
workplans ZONE-WP-0001-T03: maturity-derived risk defaults, and what they can attach to 2026-08-19 23:23:49 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-19 21:19:35 +02:00
.gitignore chore: track scaffold gitignore and custodian brief 2026-08-19 21:20:12 +02:00
.repo-classification.yaml Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
AGENTS.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
GOAL.md Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected 2026-08-19 22:20:13 +02:00
INTENT.md Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected 2026-08-19 22:20:13 +02:00
README.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
SCOPE.md Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected 2026-08-19 22:20:13 +02:00
WORK-RECORDS.md ZONE-WP-0001-T03: maturity-derived risk defaults, and what they can attach to 2026-08-19 23:23:49 +02:00

zone-engine

Headless authority for security zones — named bands of the estate with different enforcement rigidity, and the lifecycle of time-boxed exceptions to them.

A zone answers a question no existing axis answers: is this control enforced here, and what happens when it fails? NetKingdom can already say how exposed a workload is (environment posture), how ready it is (workload maturity M0M3), and what state the organization is in (organization_posture). All three describe. None decides.

zone-engine is not a policy decision point. flex-auth remains the only PDP; zone membership reaches it by compilation into the registry it already consumes, never by a synchronous lookup in the decision path.

Orient: GOAL.mdSCOPE.mdworkplans/.