CABIER Global Assurance · Reference architecture

    AI Factory Assurance

    Intelligence is manufactured somewhere. Accelerators, clusters, model estates, routing, inference, agents, credentials and tools sit inside an environment that somebody else often operates. This is CABIER assurance applied to that environment.

    It is not an AI factory product and it does not replace the infrastructure. It states what each object is permitted to do, under whose authority, in which jurisdiction, with what evidence, and what breaks when a component fails.

    Reference architecture. Synthetic demonstrator below. No provider integration, partnership or endorsement is stated or implied.

    What the assurance position covers

    An asset register lists what exists. This states what it may do and what depends on it.

    Compute and accelerators

    Capability, isolation and tenancy of the hardware an inference actually runs on.

    Cluster

    The scheduling and isolation boundary between tenants, workloads and jurisdictions.

    Model estate

    Which models exist, at which versions, under whose ownership and with what evaluation evidence.

    Model routing

    Which request reaches which model, and whether that routing respects residency and consequence class.

    Inference

    Where inference occurs, what leaves the boundary and what is retained.

    Agents

    Autonomous or semi-autonomous processes operating on the estate, with objectives and delegation.

    Data

    Classification, residency, retention and permitted purpose of everything the estate can reach.

    Identity and credentials

    Which identities hold which credentials, and how long a credential remains valid.

    Tools and tool servers

    The reach an agent acquires the moment a tool is attached.

    Network and storage

    The paths and stores that determine whether a residency statement is true.

    Tenants

    Isolation between institutions sharing infrastructure, and what a failure crosses.

    Jurisdictions

    Every place engaged by entity, operator, data, inference and user, cumulatively.

    Dependencies

    Third parties, clouds, providers and single points whose withdrawal changes the position.

    Resilience

    What degrades, what continues and what stops when a component becomes unavailable.

    Evidence

    Whether the position can be re-examined later by someone who was not there.

    The chain the relationship graph has to carry

    An asset register lists what exists. This states what each object is permitted to do, under whose authority, in which jurisdiction, with what evidence, and what breaks if it fails.

    AI factoryClusterModelRuntimeAgentCredentialToolDataActionInstitutionRegulationEvidence

    Where the factory sits in the hierarchy

    One deployment hierarchy, from where intelligence is manufactured to where it acts, with the same primitives carried across every layer.

    1. 01AI factory

      Where intelligence is manufactured: accelerators, clusters, training and the model estate itself.

    2. 02Data centre, cloud or sovereign infrastructure

      Where intelligence is operated, by a named operator, under a legal relationship.

    3. 03Model

      The capability, at a stated version, with evaluation evidence that belongs to that version.

    4. 04Runtime

      Where inference and agent execution actually occur, rather than where they are described.

    5. 05Agent

      The acting party, with an objective, a delegation path and an authority envelope.

    6. 06Tools, tool servers and credentials

      The reach an agent acquires the moment a tool or a credential is attached.

    7. 07Data

      Classification, residency, permitted purpose and onward flow of everything reachable.

    8. 08Application

      Where intelligence is distributed to people and to other systems.

    9. 09Enterprise and device

      Where intelligence is consumed, inside an institution or at the edge.

    10. 10Action

      The consequential thing that happens, which is the only place assurance finally matters.

    CABIER spans every layer

    • TrustGraph

      The relationships between every object in the hierarchy, so an effect can be traced rather than guessed.

    • AssureAdapt

      Detects change anywhere in the hierarchy and decides when the position must be re-derived.

    • AssureCore

      The single decision boundary: eight Trust Gates, five dispositions, no consequential autonomous execution.

    • AssureMark

      The machine-readable assurance and provenance record for whatever was decided.

    • Evidence

      One evidence architecture, dated, attributable and re-examinable by someone who was not there.

    • Human and institutional authority

      The named authority that adjudicates consequential findings, at every layer.

    Cabier does not replace the underlying infrastructure. Cabier assures what operates across it.

    Inspect the environment

    Set the environment, model, version, agent, consequence class, authority, dependency, control state and evidence state, and read the position the system derives.

    Synthetic demonstrator · illustrative

    Inspect the environment, then read the derived position

    Change any input and the position is re-derived deterministically. Control weights, grading rubrics and Trust Gate internals are not published, so what is shown is the derivation rather than a score.

    Environment
    Model
    Model version
    Agent
    Consequence class
    Authority
    Dependency
    Control state
    Evidence state

    Derived position

    Disposition: Allow with conditions

    Assured with stated conditions. The conditions are part of the position, not advice attached to it.

    Stated facts

    Environment: Dedicated cluster inside a shared site, isolation asserted at the scheduler.

    Model: High-capability general model reached over a provider boundary.

    Model version: Evaluation evidence exists for this exact version, within its freshness window.

    Agent: Tools and credentials attached, so reach extends beyond the model boundary.

    Consequence class: Obligation mapping and dated control evidence attach to the decision.

    Authority: A named person holds the consequence and can be asked to answer for it.

    Dependency: A tested fallback exists that does not share the primary dependency.

    Control state: Design and operating effectiveness both evidenced within the freshness window.

    Evidence state: Independent artefacts support the position and can be re-examined later.

    Trust Gates engaged

    IdentityAuthorisationPolicyDataSecurityRegulatoryEvidence

    Conditions

    No additional condition. The position is proportionate to the stated consequence class.

    Evidence position

    Substantiated. Independent artefacts support the conclusion, dated and re-examinable.

    Accountable authority

    Named accountable owner, with the infrastructure operator as respondent.

    Invalidated by

    A new model version, a routing or permission change, a change of operator or jurisdiction, a new dependency, or expiry of the supporting evidence.

    Derivation, stage by stage

    Deterministic and synthetic. The same sequence always produces the same derived position.

    Synthetic demonstrator · illustrative

    AI factory assurance

    Shared accelerator estate hosting models for three regulated tenants

    Consequence class: Critical
    1. 1. Baseline
    2. 2. Model deployed
    3. 3. Agent deployed
    4. 4. Authority envelope
    5. 5. Infrastructure dependency
    6. 6. Change
    7. Assurance state

    Beneath the factory is a site, an operator and a legal relationship, and that is where a residency statement is either true or not.

    Go down a layer