Headless multi-application, multi-tenant security zone mangement engine.
Find a file
tegwick e5af1ba270 ZONE-WP-0001-T02: partition the estate
Four bands, derived rather than invented, each of the 27 catalog lanes in
exactly one: Decided (1), Fronted (10), Covered (12), Signposted (4).

The finding is that delegation.mode — introduced by ops-warden WP-0030 to answer
a governance question — predicts operational danger better than the field named
risk. Ten of eleven high-risk lanes are interim, eight of those exec_capable.

Two results that constrain T03 and T04. The three existing controls each cut the
estate differently (1, 13 and 11 lanes) with only 8 in the overlap, so stance is
per control per zone and never per zone alone. And the posture registry shares no
join key with the catalog, so environment posture and M0-M3 compose in principle
but cannot be joined today without inventing a mapping — fabrication under §6.

The residue is the most valuable output: 14 of 27 lanes carry no risk value, and
is_high_risk is risk == "high", so the agent read-boundary never fires for them.
Five are exec_capable. Routed to risk-nexus as RISK-F-0003.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:08:53 +02:00
docs ZONE-WP-0001-T02: partition the estate 2026-08-19 23:08:53 +02:00
workplans ZONE-WP-0001-T01: net-kingdom answered — separate standard, tenancy.yaml carrier, reefs struck 2026-08-19 22:06:32 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-19 21:19:35 +02:00
.gitignore chore: track scaffold gitignore and custodian brief 2026-08-19 21:20:12 +02:00
.repo-classification.yaml Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
AGENTS.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
GOAL.md Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected 2026-08-19 22:20:13 +02:00
INTENT.md Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected 2026-08-19 22:20:13 +02:00
README.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
SCOPE.md Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected 2026-08-19 22:20:13 +02:00
WORK-RECORDS.md chore: track scaffold gitignore and custodian brief 2026-08-19 21:20:12 +02:00

zone-engine

Headless authority for security zones — named bands of the estate with different enforcement rigidity, and the lifecycle of time-boxed exceptions to them.

A zone answers a question no existing axis answers: is this control enforced here, and what happens when it fails? NetKingdom can already say how exposed a workload is (environment posture), how ready it is (workload maturity M0M3), and what state the organization is in (organization_posture). All three describe. None decides.

zone-engine is not a policy decision point. flex-auth remains the only PDP; zone membership reaches it by compilation into the registry it already consumes, never by a synchronous lookup in the decision path.

Orient: GOAL.mdSCOPE.mdworkplans/.