Headless multi-application, multi-tenant security zone mangement engine.
Find a file
custodian-sync a752f87f8f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-23:
  - update .custodian-brief.md for zone-engine

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
2026-08-23 11:31:10 +02:00
docs docs: close operator config migration evidence 2026-08-22 15:51:03 +02:00
history docs: reconcile delivered scope with intent 2026-08-23 10:42:12 +02:00
tests feat: compile security zone declarations 2026-08-22 14:19:07 +02:00
tools feat: compile security zone declarations 2026-08-22 14:19:07 +02:00
workplans docs: plan zone reference contract hardening 2026-08-23 11:29:20 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-23 11:31:10 +02:00
.gitignore feat: compile security zone declarations 2026-08-22 14:19:07 +02:00
.repo-classification.yaml Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
AGENTS.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
GOAL.md docs: finish security zone adoption workplan 2026-08-22 15:40:55 +02:00
INTENT.md Complete security zone model and canon draft 2026-08-22 14:03:46 +02:00
Makefile feat: compile security zone declarations 2026-08-22 14:19:07 +02:00
README.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
SCOPE.md docs: plan zone reference contract hardening 2026-08-23 11:29:20 +02:00
WORK-RECORDS.md docs: plan zone reference contract hardening 2026-08-23 11:29:20 +02:00

zone-engine

Headless authority for security zones — named bands of the estate with different enforcement rigidity, and the lifecycle of time-boxed exceptions to them.

A zone answers a question no existing axis answers: is this control enforced here, and what happens when it fails? NetKingdom can already say how exposed a workload is (environment posture), how ready it is (workload maturity M0M3), and what state the organization is in (organization_posture). All three describe. None decides.

zone-engine is not a policy decision point. flex-auth remains the only PDP; zone membership reaches it by compilation into the registry it already consumes, never by a synchronous lookup in the decision path.

Orient: GOAL.mdSCOPE.mdworkplans/.