Cabier Global Assurance · Architecture
AssureCore
Every consequential action passes through the same assurance logic. Not a policy document, not a quarterly review, and not a probability. Eight gates, one disposition, and a record that can be re-examined years later by someone who was not there.
Cabier governs the decision boundary. The institution retains the action. No autonomous consequential execution is implied anywhere in this architecture.
Published as reference architecture. Gate internals, thresholds and control weights are set per engagement and are not published.
The eight Trust Gates
Each gate is a question with a dated answer. A gate that cannot be answered is not passed by default.
Identity
Is the requesting system, agent and human identity established and current?
Authorisation
Is this action inside the envelope granted to that identity, by someone entitled to grant it?
Policy
Does institutional policy permit the action in this context, at this value, at this hour?
Data
Is the data reached, retained and transferred within the classification and residency permitted?
Security
Is the path, credential and tool chain in a state the security position accepts?
Regulatory
Which obligations apply to this action across every jurisdiction engaged, and are they satisfied?
Resilience
What is the consequence of this action failing, and is the fallback available?
Evidence
Will the decision, its basis and its outcome be recorded so it can be re-examined later?
Five dispositions
Nothing resolves to a silent yes.
Allow
Every gate satisfied on current evidence. Recorded, not silent.
Allow with conditions
Permitted inside a stated boundary, with the condition, owner and expiry recorded.
Human review
The decision requires institutional authority. The system prepares the decision; it does not take it.
Block
A gate is failed and no compensating condition is available.
Escalate
The condition exceeds the authority of the reviewer it would ordinarily reach.
What every disposition must state
A verdict without its basis is not defensible. Each disposition identifies the following, or it is not a disposition.
Governing facts
What was requested, by which identity, over what data, at what value, in which environment.
Applicable authority
The law, regulation, standard, supervisory expectation or internal policy relied on.
Relevant controls
Which controls were tested, their state and the date of the test.
Evidence state
What evidence exists, how complete it is, where it is held and when it expires.
Escalation condition
The specific condition that would move this disposition to human review or block.
Architectural principles
- No autonomous consequential execution is implied. Cabier governs the decision boundary; the institution retains the action.
- A disposition is never a bare verdict. If it cannot state its governing facts, authority, controls, evidence and escalation condition, it is not a disposition.
- Consequential authorisation decisions do not rest solely on probabilistic model output. Deterministic controls and relationship reasoning carry the load; intelligence assists judgement.
- Where policy requires it, no autonomous execution is a hard control rather than a guideline, configurable and evidenced.
A disposition is only useful if the next system in the chain can read the assurance position rather than infer it.
See how the position travels