The Authorization Boundary Integrity Model
A complete authorization boundary satisfies three independent properties. Most architectures satisfy one or two and present as complete. This work names the construct and the properties, and gives a way to see which one a given architecture is quietly missing. The model is stated generally and applies to any system that authorizes actions before they execute, including AI governance architectures. An authorization boundary is the point at which a proposed action is judged against policy before execution and then permitted, refused, or held. These outcomes correspond to the verdicts ALLOW, DENY, and ABSTAIN. Output integrity: an unauthorized action cannot execute, because no path reaches the world without passing the boundary. Input integrity: a verdict does not rest on evidence whose admissible origin has not been established. Replay integrity: a verdict can be independently reconstructed from the bound inputs, the policy and version state that applied, the authority chain, and the proposed action. Beneath the three sits a substrate, input binding, which records which inputs a decision used. Input binding supports reconstruction, but it does not establish admissibility. That distinction is load-bearing: a faithfully bound, fully reproducible verdict over fabricated inputs has replay integrity and no input integrity. Because the three properties are orthogonal, the Authorization Boundary Integrity Model (ABIM) also functions as a classification. Any authorization architecture can be located by the properties it satisfies and the one a given class structurally cannot, separating observability and advisory guardrails, policy engines that authorize caller-asserted facts, and signed logging from a complete boundary. The model states what has to be true for an authorization boundary to deserve the name. It does not claim that any one system already holds all three properties, and it notes that input integrity is the newest and least developed of the three. This is the synthesis of a three-part series and the citable framework reference for the model. The companion articles establish the arguments individually: Watching Is Not Stopping on output integrity, The Trust Boundary Has Two Sides on input integrity, and A Signature Is Not a Reconstruction on replay integrity.
Authors
- Edward Meyman (ORCID: https://orcid.org/0009-0008-8012-6100)
Institutions
- Ferghana Polytechnical Institute (UZ)
- Ferro (United States) (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-08-26
- DOI
- https://doi.org/10.5281/zenodo.20929115
- Citations
- 2
- Primary Topic
- Access Control and Trust
- Type
- article
- Field-Weighted Citation Impact
- 35.37