Enhancement Without Transformation: Structural Limits of Extending Access Control into Deterministic Authorization Infrastructure
Adding finer policies, richer attributes, ontologies, formal policy analysis, or signed decision records to an access-control arrangement raises a specific architectural question: which authorization requirements do those enhancements establish? This technical note examines the structural limits of extending access control into deterministic authorization infrastructure for AI systems. Its central claim is conditional: an evaluator enhancement leaves an authorization deficiency intact when it preserves the deficient input, release, or evidence dependencies. The analysis identifies what must change to remove those deficiencies and what evidence is needed to substantiate the resulting authorization claims. Three conditional propositions organize the analysis. The first concerns decision inputs that omit a policy-material distinction or fail the policy's evidence requirements. The second concerns feasible paths that reach a covered effect without enforcement requiring ALLOW from the designated decision process. The third concerns release that is not bound to the determined action or to still-valid governing dependencies. A stipulated messaging example follows these deficiencies through a progression of architectural changes, ending in an arrangement of conventional components that satisfies the modeled requirements under explicit assumptions. Deterministic authorization infrastructure The note uses this term for an arrangement that enforces and maintains the adopted profile's requirements across governed changes: deterministic action-bound verdicts; non-bypassable and fail-closed enforcement; release-time validity of governing state and bound dependencies; established input provenance; authorization artifacts supporting independent reconstruction. Determinism is one requirement of this arrangement; it does not by itself establish the others. Three levels of claim are kept separate throughout: category membership (performing runtime authorization at all, which request-level access controls can do), adopted-profile conformance, and product equivalence (claimed in neither direction). Changes are classified by the dependencies they alter, not by vendor, component name, or implementation effort. Conventional components can form a conforming arrangement; their names establish neither conformance nor equivalence. Three conditional propositions The propositions are stated over one stipulated messaging example in which a permitted status update and the same update with a prohibited confidential attachment present the same baseline evaluator projection: Input deficits preserved by enrichment. Adding attributes does not by itself supply evidence meeting the policy's source-authority, origin, integrity, binding, and freshness requirements. Recognized-source evidence relayed through the requester may resolve the input deficit; preserving that reliance for reconstruction is a separate obligation. Bypass invariance under evaluation-only enhancement. A feasible path that reaches the covered effect without enforcement requiring ALLOW from the designated decision process remains a bypass when the enhancement preserves that path's reachability, capabilities, and downstream acceptance conditions. Non-transfer of authorization across an unverified material change. Release unbound to the determined action, or to still-valid governing dependencies, is not cured by a better evaluator. What the note provides A six-stage explanatory progression, with mediation separated from binding, freshness, and the required artifact, ending in an arrangement assembled from conventional components whose stated contracts satisfy the modeled requirements under explicit assumptions as a conditional design claim. A claims–arguments–evidence matrix stating the evidence needed to substantiate each claim. Six proposed failure cases stating what must block and what evidence would demonstrate the required behavior. Scope ALLOW, DENY, and ABSTAIN remain the operative verdicts. Deterministic evaluation, operational completion, and independent reconstruction are treated as distinct obligations. Release requires a valid ALLOW and satisfaction of the full release prerequisite; DENY blocks execution, and ABSTAIN blocks execution pending authorized human resolution. The examples are hypothetical. No executed tests, product-equivalence claims, patent-scope claims, or implementation mechanisms are included. Related works in the FERZ corpus Deterministic AI Governance (v1.2) Standing Eligibility versus Runtime Authorization (v1.0) The Authorization Boundary Integrity Model (v1.2) The Authorization Artifact Test (v1.2) The Five Tests Standard (5TS) Execution-Time Authorization for AI Agents (v3.1) The Closed-World Bargain (v1.1) The Hook Is Not the Boundary (v1.0) On the Impossibility of Observability-Based Authorization (v1.4.0) Containment Is Not Authorization (v1.0), whose stipulated example this note develops The full FERZ corpus is collected in the FERZ community on Zenodo.
Authors
- Edward Meyman (ORCID: https://orcid.org/0009-0008-8012-6100)
Institutions
- Ferghana Polytechnical Institute (UZ)
- Ferro (United States) (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-16
- DOI
- https://doi.org/10.5281/zenodo.22799948
- Primary Topic
- Access Control and Trust
- Type
- article
- Field-Weighted Citation Impact
- 0.00