Cabier Global Assurance · Architecture
Consequence Classes
One architecture, five classes of consequence. The assurance object never changes. What changes is intensity: how much evaluation, how narrow the permission envelope, how fresh the evidence has to be, and how much of the decision belongs to a named human rather than to a system.
Treating everyday activity with systemic-grade scrutiny is how assurance programmes become unaffordable and then get bypassed. Treating systemic activity with everyday scrutiny is how institutions find out too late.
Published as reference architecture. Class thresholds and the control intensity attached to each are set per engagement.
Five classes
Everyday
Typical activity
Internal drafting, summarisation, retrieval over non-sensitive material.
Assurance intensity
Deterministic policy and permission checks, evidence retained, no external evaluation.
Regulated
Typical activity
Customer communication, underwriting input, employment or credit relevance, personal data at scale.
Assurance intensity
Obligation mapping, control testing, human oversight of automated outcomes, dated evidence.
Critical
Typical activity
Payment initiation, security operations, clinical support, code shipped to production.
Assurance intensity
Independent evaluation, bounded permission envelope, tested interruption, elevated evidence freshness.
Strategic
Typical activity
Market infrastructure, national services, systemically relied-on platforms.
Assurance intensity
Multi-model evaluation, concentration and dependency analysis, supervisory-grade evidence, named institutional authority.
Systemic and high-consequence
Typical activity
Financial system infrastructure, critical national infrastructure, defence-adjacent and other irreversible-harm settings.
Assurance intensity
Highest intensity throughout, with no autonomous execution as a hard control and human authority at every consequential step.
High-consequence principle
Stated plainly, because the boundary matters more than the capability.
- Cabier is not an operational weapons system and does not participate in targeting, engagement or any operational military decision.
- In defence-adjacent and other irreversible-harm settings the assurance questions are narrow and unchanged: reliability, authorisation, human control, testing, verification, accountability, anomaly detection, evidence, resilience, intervention and dependency.
- Where policy requires no autonomous execution, that is implemented as a hard control, configurable, evidenced and testable, not as a stated intention.
Inside the system or beside it, on customer-controlled compute, with assurance still independently governed.
See where the assurance runs