Composition and Emergence on Shared Surfaces: Ensemble Trifecta Closure
Enterprise security architecture still inherits a Zero Trust ontology whose atomic unit of risk is a subject requesting a resource. That ontology fails on the interaction-surface class: shared services (package caches, GET-mutable public wikis, MCP registries, approval channels) where per-agent Rule of Two and classical subject→resource checks pass while compositions of locally legitimate actions close Willison's lethal trifecta. Harm is compositional and often emergent. The package-cache / war-room story is a teaching metaphor for that class — not product scope. Hugging Face Artifactory and DseWiki are instances; novel surfaces stay in scope via continuous IBI and Invariant 1, not by enumerating today's caches. This thesis argues for an interaction-centric Modern Enterprise Security Architecture (MESA) whose headline contribution is Invariant 1 (Ensemble Trifecta / INV-01), stated as a cut property: for every agent b, Cl(b) is the join of property vectors over vertices with a directed path into b, masked by edge flow type; the PDP-gated edge set must form a cut such that residual closure ≠ (1,1,1). Least Privilege and per-session Rule of Two are not that invariant. Least Agency (OWASP 2026 Agentic Top 10) is adopted, not coined. MESA plugs into OWASP ASI, Five Eyes Careful Adoption, and CISA ZTMM: public surface = IBI + ACM + ACA + INV-01. Three architectural claims: (a) interaction surfaces as first-class trust boundaries, including public third-party blackboards; (b) campaign-graph evaluation as the unit of defense testing; (c) the ensemble trifecta cut as the compositional control that Least Agency and Least Privilege do not supply. Five case families ground the claim. Reference implementation: mesa-ibi-scanner (cut semantics).
Authors
- Uddeshya Kumar
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-15
- DOI
- https://doi.org/10.5281/zenodo.22761743
- Primary Topic
- Access Control and Trust
- Type
- preprint