repo-config/README.md "Downstream Carry" requires every downstream repo to carry locally adapted AUDIT.md and spec/secrets.json "scoped to self-auditing its own rulesets, settings, and secrets ... the standard shape", but the hub ships no downstream reference for either - the hub's AUDIT.md is fleet-wide (registry lookup, type classification, reports/, convergence via target PRs) and most of it does not apply to a self-audit.
Vantage-Config authored the first operational-model adaptation from scratch (Vantage-Config #9): settings diff, normalized ruleset diff with the operational/develop.json payload swap, and a names-only secrets check, all targeting the current repo via gh repo view. Suggest the hub keep a reference downstream shape (or bless an existing carry as the example) so later adoptees adapt instead of invent, and so the fleet audit can letter-check the carried files.
repo-config/README.md "Downstream Carry" requires every downstream repo to carry locally adapted
AUDIT.mdandspec/secrets.json"scoped to self-auditing its own rulesets, settings, and secrets ... the standard shape", but the hub ships no downstream reference for either - the hub's AUDIT.md is fleet-wide (registry lookup, type classification, reports/, convergence via target PRs) and most of it does not apply to a self-audit.Vantage-Config authored the first operational-model adaptation from scratch (Vantage-Config #9): settings diff, normalized ruleset diff with the
operational/develop.jsonpayload swap, and a names-only secrets check, all targeting the current repo viagh repo view. Suggest the hub keep a reference downstream shape (or bless an existing carry as the example) so later adoptees adapt instead of invent, and so the fleet audit can letter-check the carried files.