Headless multi-application, multi-tenant security zone mangement engine.
Amended by net-kingdom as canon owner of tenancy-posture_v0.1. T01: enforcement stance is a sibling canon standard, not a seventh axis (the six ladders are monotone and stance is not; and a descriptive framework cannot carry a prescriptive axis without handing out its own exemptions). Ownership confirmed; the repo is not archived. Declaration surface is tenancy.yaml's reserved zones: key, not a new root file. T02: the reef question is struck — the unreconciled pair is reef vs P/V and it is canon's defect (NK-WP-0027), not this model's scope. organization_posture: do not fold in, consume as an input. T05: carrier file settled; only the shape inside zones: remains open. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| AGENTS.md | ||
| GOAL.md | ||
| README.md | ||
| SCOPE.md | ||
| WORK-RECORDS.md | ||
zone-engine
Headless authority for security zones — named bands of the estate with different enforcement rigidity, and the lifecycle of time-boxed exceptions to them.
A zone answers a question no existing axis answers: is this control enforced
here, and what happens when it fails? NetKingdom can already say how exposed a
workload is (environment posture), how ready it is (workload maturity M0–M3),
and what state the organization is in (organization_posture). All three
describe. None decides.
zone-engine is not a policy decision point. flex-auth remains the only
PDP; zone membership reaches it by compilation into the registry it already
consumes, never by a synchronous lookup in the decision path.
Orient: GOAL.md → SCOPE.md → workplans/.