Six checkpoints, and the default at each is deny
checkpoint · refusal · the task budget under all of it
Assurance fabric / System overview
Deny-by-default checks at each boundary
Identity, application, data, service, tenant, and device checks each require a declared grant. Passing one check does not bypass the next check.
Inside the system
Each plate preserves the internal layout, paths, boundaries, and highlighted decisions. Use the short label first, then follow the lines through the system.
checkpoint · refusal · the task budget under all of it
reachable set · three gate leaves · the outcome classifier
the tuple · the capability bits · the declared registries · the metering wire
one principal, two tiers · the authorship tiers · the scoped grant, N deep
three worked refusals · the capability registry · the escape-surface diff
Key parts
These are the main boundaries, inputs, outputs, and failure rules. The examples show a specific use of each part.
A request must pass each relevant boundary. Success at one layer does not bypass the next.
A signed-in user may open an application but still be denied a data set or device action outside the mission grant.
Permission combines an allowed action with organization, service level, and policy. This limits broad access.
A partner unit can receive read access to a shared track feed without gaining write access to the source mission store.
Network, sandbox, and tenant choices are stated and checked. Missing policy is treated as refusal.
A workload cannot begin using an undeclared outbound connection simply because the network is reachable.
Uses
Pilot questions
Which boundaries need separate grants
How tenant and mission scope are represented
What refusal evidence may be retained and shared