The Authorization Boundary Integrity Model

A complete authorization boundary satisfies three independent properties. Most architectures satisfy one or two and present as complete. This work names the construct and the properties, and gives a way to see which one a given architecture is quietly missing. The model is stated generally and applies to any system that authorizes actions before they execute, including AI governance architectures. An authorization boundary is the point at which a proposed action is judged against policy before execution and then permitted, refused, or held. These outcomes correspond to the verdicts ALLOW, DENY, and ABSTAIN. Output integrity: an unauthorized action cannot execute, because no path reaches the world without passing the boundary. Input integrity: a verdict does not rest on evidence whose admissible origin has not been established. Replay integrity: a verdict can be independently reconstructed from the bound inputs, the policy and version state that applied, the authority chain, and the proposed action. Beneath the three sits a substrate, input binding, which records which inputs a decision used. Input binding supports reconstruction, but it does not establish admissibility. That distinction is load-bearing: a faithfully bound, fully reproducible verdict over fabricated inputs has replay integrity and no input integrity. Because the three properties are orthogonal, the Authorization Boundary Integrity Model (ABIM) also functions as a classification. Any authorization architecture can be located by the properties it satisfies and the one a given class structurally cannot, separating observability and advisory guardrails, policy engines that authorize caller-asserted facts, and signed logging from a complete boundary. The model states what has to be true for an authorization boundary to deserve the name. It does not claim that any one system already holds all three properties, and it notes that input integrity is the newest and least developed of the three. This is the synthesis of a three-part series and the citable framework reference for the model. The companion articles establish the arguments individually: Watching Is Not Stopping on output integrity, The Trust Boundary Has Two Sides on input integrity, and A Signature Is Not a Reconstruction on replay integrity.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-08-26
DOI
https://doi.org/10.5281/zenodo.20929115
Citations
2
Primary Topic
Access Control and Trust
Type
article
Field-Weighted Citation Impact
35.37
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

The Authorization Boundary Integrity Model

Edward Meyman
2 citations
Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
35.37
article

The Authorization Boundary Integrity Model

Edward Meyman
article en
2 citations

Abstract

A complete authorization boundary satisfies three independent properties. Most architectures satisfy one or two and present as complete. This work names the construct and the properties, and gives a way to see which one a given architecture is quietly missing. The model is stated generally and applies to any system that authorizes actions before they execute, including AI governance architectures. An authorization boundary is the point at which a proposed action is judged against policy before execution and then permitted, refused, or held. These outcomes correspond to the verdicts ALLOW, DENY, and ABSTAIN. Output integrity: an unauthorized action cannot execute, because no path reaches the world without passing the boundary. Input integrity: a verdict does not rest on evidence whose admissible origin has not been established. Replay integrity: a verdict can be independently reconstructed from the bound inputs, the policy and version state that applied, the authority chain, and the proposed action. Beneath the three sits a substrate, input binding, which records which inputs a decision used. Input binding supports reconstruction, but it does not establish admissibility. That distinction is load-bearing: a faithfully bound, fully reproducible verdict over fabricated inputs has replay integrity and no input integrity. Because the three properties are orthogonal, the Authorization Boundary Integrity Model (ABIM) also functions as a classification. Any authorization architecture can be located by the properties it satisfies and the one a given class structurally cannot, separating observability and advisory guardrails, policy engines that authorize caller-asserted facts, and signed logging from a complete boundary. The model states what has to be true for an authorization boundary to deserve the name. It does not claim that any one system already holds all three properties, and it notes that input integrity is the newest and least developed of the three. This is the synthesis of a three-part series and the citable framework reference for the model. The companion articles establish the arguments individually: Watching Is Not Stopping on output integrity, The Trust Boundary Has Two Sides on input integrity, and A Signature Is Not a Reconstruction on replay integrity.

Zenodo (CERN European Organization for Nuclear Research)
Ferghana Polytechnical Institute (UZ), Ferro (United States) (US)
Peace, Justice and strong institutions
Openalex Percentile: Top 0%
Access Control and Trust
35.37
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.