Headless multi-application, multi-tenant security zone mangement engine.
Find a file
tegwick e8a569f2e6 Measure the join: 1 of 27 lanes, and correct my own over-correction
T02 said no join key exists — too strong. The correction said the workload side
exists "and most of the join with it" — too optimistic, and it was an inference
from structure rather than a measurement. Computed, the join matches exactly one
lane: issue-core-ingestion-api-key.

rapp-qonto-keycape-client demonstrates the predicted naming failure: the path
offers keycape-client and rapp-qonto while the rapp declares name qonto, so
neither candidate matches.

The gap is therefore not a missing key but missing declarations. Thirteen lanes
name something plausible that no rapp declares as a workload; thirteen more are
not KV addresses at all.

This blocks stance modelling rather than unblocking it, and the tempting escape —
binding zones to something other than a workload for lanes that have none —
would quietly undo the subject decision. Recorded as a decision for repo-manager
and net-kingdom rather than resolved here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 07:22:33 +02:00
docs Correct the rapp count: eight declarations, not nine 2026-08-20 07:21:02 +02:00
workplans Measure the join: 1 of 27 lanes, and correct my own over-correction 2026-08-20 07:22:33 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-19 21:19:35 +02:00
.gitignore chore: track scaffold gitignore and custodian brief 2026-08-19 21:20:12 +02:00
.repo-classification.yaml Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
AGENTS.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
GOAL.md Refine SCOPE, add INTENT, fix the GOAL invariant flex-auth rejected 2026-08-19 22:20:13 +02:00
INTENT.md Correct the subject: policy is about the workload, and a zone is an admission floor 2026-08-19 23:36:31 +02:00
README.md Seed zone-engine — authority for security zones and exception lifecycle 2026-08-19 21:18:44 +02:00
SCOPE.md Correct the subject: policy is about the workload, and a zone is an admission floor 2026-08-19 23:36:31 +02:00
WORK-RECORDS.md ZONE-WP-0001-T03: maturity-derived risk defaults, and what they can attach to 2026-08-19 23:23:49 +02:00

zone-engine

Headless authority for security zones — named bands of the estate with different enforcement rigidity, and the lifecycle of time-boxed exceptions to them.

A zone answers a question no existing axis answers: is this control enforced here, and what happens when it fails? NetKingdom can already say how exposed a workload is (environment posture), how ready it is (workload maturity M0M3), and what state the organization is in (organization_posture). All three describe. None decides.

zone-engine is not a policy decision point. flex-auth remains the only PDP; zone membership reaches it by compilation into the registry it already consumes, never by a synchronous lookup in the decision path.

Orient: GOAL.mdSCOPE.mdworkplans/.