Headless multi-application, multi-tenant security zone mangement engine.
Four bands, derived rather than invented, each of the 27 catalog lanes in exactly one: Decided (1), Fronted (10), Covered (12), Signposted (4). The finding is that delegation.mode — introduced by ops-warden WP-0030 to answer a governance question — predicts operational danger better than the field named risk. Ten of eleven high-risk lanes are interim, eight of those exec_capable. Two results that constrain T03 and T04. The three existing controls each cut the estate differently (1, 13 and 11 lanes) with only 8 in the overlap, so stance is per control per zone and never per zone alone. And the posture registry shares no join key with the catalog, so environment posture and M0-M3 compose in principle but cannot be joined today without inventing a mapping — fabrication under §6. The residue is the most valuable output: 14 of 27 lanes carry no risk value, and is_high_risk is risk == "high", so the agent read-boundary never fires for them. Five are exec_capable. Routed to risk-nexus as RISK-F-0003. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| docs | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| AGENTS.md | ||
| GOAL.md | ||
| INTENT.md | ||
| README.md | ||
| SCOPE.md | ||
| WORK-RECORDS.md | ||
zone-engine
Headless authority for security zones — named bands of the estate with different enforcement rigidity, and the lifecycle of time-boxed exceptions to them.
A zone answers a question no existing axis answers: is this control enforced
here, and what happens when it fails? NetKingdom can already say how exposed a
workload is (environment posture), how ready it is (workload maturity M0–M3),
and what state the organization is in (organization_posture). All three
describe. None decides.
zone-engine is not a policy decision point. flex-auth remains the only
PDP; zone membership reaches it by compilation into the registry it already
consumes, never by a synchronous lookup in the decision path.
Orient: GOAL.md → SCOPE.md → workplans/.