[SLICE 03][CORE-A] Complete namespace/project identity, principal/capability policy, trust classes, and append-only audit #28

Open
opened 2026-09-08 01:57:01 +00:00 by nsaspy · 0 comments
Owner

Parent epic: #12
Depends on: #20
Refines: #1

Goal

Finish the foundational identity/authority model so later semantic/query/federation work inherits one correct boundary.

Implement:

  • stable opaque namespace/project IDs;
  • explicit project-id > canonical remote > path-hint resolution order;
  • explicit ambiguous/unresolved outcomes and no project→global fallback;
  • principal identity + read/session/project/global write capabilities;
  • authority checks separated from namespace resolution;
  • source/trust/provenance classes independent of text content;
  • append-only authorization/write/read-sensitive audit records;
  • namespace aliases/versioning without destructive project-ID changes.

Acceptance

Fixtures prove project isolation, explicit global-write separation, known-ID read denial, ambiguous project failure, path rename without identity loss, provenance cannot self-upgrade trust, and failed authorization leaves no partial durable write.

Parent epic: #12 Depends on: #20 Refines: #1 ## Goal Finish the foundational identity/authority model so later semantic/query/federation work inherits one correct boundary. Implement: - stable opaque namespace/project IDs; - explicit project-id > canonical remote > path-hint resolution order; - explicit ambiguous/unresolved outcomes and no project→global fallback; - principal identity + read/session/project/global write capabilities; - authority checks separated from namespace resolution; - source/trust/provenance classes independent of text content; - append-only authorization/write/read-sensitive audit records; - namespace aliases/versioning without destructive project-ID changes. ## Acceptance Fixtures prove project isolation, explicit global-write separation, known-ID read denial, ambiguous project failure, path rename without identity loss, provenance cannot self-upgrade trust, and failed authorization leaves no partial durable write.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
nsaspy/symbolic-memory#28
No description provided.