Governance

This document defines operating rules for the public developer repository.

Rules Of Engagement

Current Public Adapter Scope

What the current public repo does well:

Phase 1 readiness is defined in PHASE1_READY.md. Any launch claim should use that document as the source of truth for production-ready, experimental, and planned capabilities.

Boundaries:

Core Maintenance Team

RoleCurrent Owner
Project leadNamed project maintainer
Engineering reviewDelegated maintainers
Security reviewSecurity reporter plus invited reviewer when needed
Community triageMaintainers during alpha
Release ownerNamed release maintainer

This is intentionally lightweight for alpha. Add named maintainers only after they accept responsibility for review, security triage, or release ownership.

Stakeholder Communication Plan

Public communication should link to the quickstart, architecture, threat model, and Phase 1 ready criteria. Avoid publishing internal launch plans, unreleased timelines, private stakeholder lists, or unapproved commercial claims in this repository.

Release Checklist

Nono Status

Nono is included as an optional public Execution Broker integration.

The Nono integration is not the identity system or policy model. It is a sandbox execution target that runs only after the Zero Trust Control Plane returns allow. New contributors should keep Nono work scoped to broker behavior, capability mapping, demo evidence, and tests unless an issue explicitly expands that scope.