generated from coulomb/repo-seed
Folds the workload-maturity axis into WP-0015. The model is now two orthogonal axes — environment posture (dev/test/prod, how the secret store is secured) and workload maturity (M0-M3, how trusted a workload is to receive secrets/classified data) — unified by a secret-flow lattice (deliver only if posture==prod AND workload.maturity >= secret.required_maturity). "Critical secrets must not flow to workloads below maturity M" is the no-write-down case. Layering: generic WorkloadMaturityLevel + lattice → info-tech-canon (reusing its DataClassification / DevSecOps gates / Security criticality / CARING); NetKingdom M0-M3 requirements → net-kingdom canon. ops-warden authors + checks conformance, not enforcement. Still proposed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>