Enhancement Without Transformation: Structural Limits of Extending Access Control into Deterministic Authorization Infrastructure

Adding finer policies, richer attributes, ontologies, formal policy analysis, or signed decision records to an access-control arrangement raises a specific architectural question: which authorization requirements do those enhancements establish? This technical note examines the structural limits of extending access control into deterministic authorization infrastructure for AI systems. Its central claim is conditional: an evaluator enhancement leaves an authorization deficiency intact when it preserves the deficient input, release, or evidence dependencies. The analysis identifies what must change to remove those deficiencies and what evidence is needed to substantiate the resulting authorization claims. Three conditional propositions organize the analysis. The first concerns decision inputs that omit a policy-material distinction or fail the policy's evidence requirements. The second concerns feasible paths that reach a covered effect without enforcement requiring ALLOW from the designated decision process. The third concerns release that is not bound to the determined action or to still-valid governing dependencies. A stipulated messaging example follows these deficiencies through a progression of architectural changes, ending in an arrangement of conventional components that satisfies the modeled requirements under explicit assumptions. Deterministic authorization infrastructure The note uses this term for an arrangement that enforces and maintains the adopted profile's requirements across governed changes: deterministic action-bound verdicts; non-bypassable and fail-closed enforcement; release-time validity of governing state and bound dependencies; established input provenance; authorization artifacts supporting independent reconstruction. Determinism is one requirement of this arrangement; it does not by itself establish the others. Three levels of claim are kept separate throughout: category membership (performing runtime authorization at all, which request-level access controls can do), adopted-profile conformance, and product equivalence (claimed in neither direction). Changes are classified by the dependencies they alter, not by vendor, component name, or implementation effort. Conventional components can form a conforming arrangement; their names establish neither conformance nor equivalence. Three conditional propositions The propositions are stated over one stipulated messaging example in which a permitted status update and the same update with a prohibited confidential attachment present the same baseline evaluator projection: Input deficits preserved by enrichment. Adding attributes does not by itself supply evidence meeting the policy's source-authority, origin, integrity, binding, and freshness requirements. Recognized-source evidence relayed through the requester may resolve the input deficit; preserving that reliance for reconstruction is a separate obligation. Bypass invariance under evaluation-only enhancement. A feasible path that reaches the covered effect without enforcement requiring ALLOW from the designated decision process remains a bypass when the enhancement preserves that path's reachability, capabilities, and downstream acceptance conditions. Non-transfer of authorization across an unverified material change. Release unbound to the determined action, or to still-valid governing dependencies, is not cured by a better evaluator. What the note provides A six-stage explanatory progression, with mediation separated from binding, freshness, and the required artifact, ending in an arrangement assembled from conventional components whose stated contracts satisfy the modeled requirements under explicit assumptions as a conditional design claim. A claims–arguments–evidence matrix stating the evidence needed to substantiate each claim. Six proposed failure cases stating what must block and what evidence would demonstrate the required behavior. Scope ALLOW, DENY, and ABSTAIN remain the operative verdicts. Deterministic evaluation, operational completion, and independent reconstruction are treated as distinct obligations. Release requires a valid ALLOW and satisfaction of the full release prerequisite; DENY blocks execution, and ABSTAIN blocks execution pending authorized human resolution. The examples are hypothetical. No executed tests, product-equivalence claims, patent-scope claims, or implementation mechanisms are included. Related works in the FERZ corpus Deterministic AI Governance (v1.2) Standing Eligibility versus Runtime Authorization (v1.0) The Authorization Boundary Integrity Model (v1.2) The Authorization Artifact Test (v1.2) The Five Tests Standard (5TS) Execution-Time Authorization for AI Agents (v3.1) The Closed-World Bargain (v1.1) The Hook Is Not the Boundary (v1.0) On the Impossibility of Observability-Based Authorization (v1.4.0) Containment Is Not Authorization (v1.0), whose stipulated example this note develops The full FERZ corpus is collected in the FERZ community on Zenodo.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-16
DOI
https://doi.org/10.5281/zenodo.22799949
Primary Topic
Access Control and Trust
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Enhancement Without Transformation: Structural Limits of Extending Access Control into Deterministic Authorization Infrastructure

Edward Meyman
Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
article

Enhancement Without Transformation: Structural Limits of Extending Access Control into Deterministic Authorization Infrastructure

Edward Meyman
article en

Abstract

Adding finer policies, richer attributes, ontologies, formal policy analysis, or signed decision records to an access-control arrangement raises a specific architectural question: which authorization requirements do those enhancements establish? This technical note examines the structural limits of extending access control into deterministic authorization infrastructure for AI systems. Its central claim is conditional: an evaluator enhancement leaves an authorization deficiency intact when it preserves the deficient input, release, or evidence dependencies. The analysis identifies what must change to remove those deficiencies and what evidence is needed to substantiate the resulting authorization claims. Three conditional propositions organize the analysis. The first concerns decision inputs that omit a policy-material distinction or fail the policy's evidence requirements. The second concerns feasible paths that reach a covered effect without enforcement requiring ALLOW from the designated decision process. The third concerns release that is not bound to the determined action or to still-valid governing dependencies. A stipulated messaging example follows these deficiencies through a progression of architectural changes, ending in an arrangement of conventional components that satisfies the modeled requirements under explicit assumptions. Deterministic authorization infrastructure The note uses this term for an arrangement that enforces and maintains the adopted profile's requirements across governed changes: deterministic action-bound verdicts; non-bypassable and fail-closed enforcement; release-time validity of governing state and bound dependencies; established input provenance; authorization artifacts supporting independent reconstruction. Determinism is one requirement of this arrangement; it does not by itself establish the others. Three levels of claim are kept separate throughout: category membership (performing runtime authorization at all, which request-level access controls can do), adopted-profile conformance, and product equivalence (claimed in neither direction). Changes are classified by the dependencies they alter, not by vendor, component name, or implementation effort. Conventional components can form a conforming arrangement; their names establish neither conformance nor equivalence. Three conditional propositions The propositions are stated over one stipulated messaging example in which a permitted status update and the same update with a prohibited confidential attachment present the same baseline evaluator projection: Input deficits preserved by enrichment. Adding attributes does not by itself supply evidence meeting the policy's source-authority, origin, integrity, binding, and freshness requirements. Recognized-source evidence relayed through the requester may resolve the input deficit; preserving that reliance for reconstruction is a separate obligation. Bypass invariance under evaluation-only enhancement. A feasible path that reaches the covered effect without enforcement requiring ALLOW from the designated decision process remains a bypass when the enhancement preserves that path's reachability, capabilities, and downstream acceptance conditions. Non-transfer of authorization across an unverified material change. Release unbound to the determined action, or to still-valid governing dependencies, is not cured by a better evaluator. What the note provides A six-stage explanatory progression, with mediation separated from binding, freshness, and the required artifact, ending in an arrangement assembled from conventional components whose stated contracts satisfy the modeled requirements under explicit assumptions as a conditional design claim. A claims–arguments–evidence matrix stating the evidence needed to substantiate each claim. Six proposed failure cases stating what must block and what evidence would demonstrate the required behavior. Scope ALLOW, DENY, and ABSTAIN remain the operative verdicts. Deterministic evaluation, operational completion, and independent reconstruction are treated as distinct obligations. Release requires a valid ALLOW and satisfaction of the full release prerequisite; DENY blocks execution, and ABSTAIN blocks execution pending authorized human resolution. The examples are hypothetical. No executed tests, product-equivalence claims, patent-scope claims, or implementation mechanisms are included. Related works in the FERZ corpus Deterministic AI Governance (v1.2) Standing Eligibility versus Runtime Authorization (v1.0) The Authorization Boundary Integrity Model (v1.2) The Authorization Artifact Test (v1.2) The Five Tests Standard (5TS) Execution-Time Authorization for AI Agents (v3.1) The Closed-World Bargain (v1.1) The Hook Is Not the Boundary (v1.0) On the Impossibility of Observability-Based Authorization (v1.4.0) Containment Is Not Authorization (v1.0), whose stipulated example this note develops The full FERZ corpus is collected in the FERZ community on Zenodo.

Zenodo (CERN European Organization for Nuclear Research)
Ferghana Polytechnical Institute (UZ), Ferro (United States) (US)
Industry, innovation and infrastructure
Openalex Percentile: Top 4%
Access Control and Trust
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.