Deterministic AI Governance: A Unified Derivation of the Runtime Authorization Boundary, Authorization Artifact, Integrity Model, and Five Tests Standard

This monograph reconstructs the FERZ governance doctrine as a unified analytical argument. Beginning with the distinction between observation and pre-execution authorization, it states the additional definitions and integrity requirements from which the runtime authorization boundary, the authorization artifact, the Authorization Boundary Integrity Model, and the Five Tests Standard follow. Deterministic here qualifies the authorization control, not the governed system or the correctness of its outputs; the doctrine does not claim that the governed AI system, the formation of policy, the source inputs, or the authorized human resolution process are deterministic. The derivation. The argument proceeds from the governance problem through the separation of authority, delegation, policy, authorization, and enforcement; derives the runtime authorization boundary, the three-member verdict space (ALLOW, DENY, ABSTAIN, with ABSTAIN blocking execution and initiating the governed escalation path: an authorized human resolution supplies authority-bound input, the boundary materially consumes it and emits a separate action-bound verdict, and the ABSTAIN remains unresolved until that verdict exists); derives the authorization artifact and the independent-reconstruction requirement under a declared replay mode; decomposes boundary integrity into three orthogonal properties (output integrity, input integrity as decision-time admissibility, replay integrity) over the input-binding substrate; states the normative control requirements at the standard level; and culminates in the Authorization Non-Substitution Principle, for which the corpus's substitution analyses provide representative applications. Position relative to established traditions. The monograph positions the resulting structure relative to the reference-monitor, access-control, and runtime-verification traditions, to proof-carrying authorization and related evidence models, and to the provenance tradition. The contribution claimed is not ownership of the inherited principles but the derivation of a unified authorization structure from their application to a specific governance problem. Nothing in the comparison implies that conventional authorization technology is categorically incapable of satisfying the derived requirements; classification attaches to the deployed arrangement, not to the name or tradition of its components. Claim discipline. The argument is conceptual and classificatory. It does not report empirical validation or claim that these constructs follow from a single premise alone. Here, derivation denotes a structured analytical reconstruction: each later requirement follows conditionally from the stated authorization objective, definitions, scope assumptions, and cited prior results; it is not a theorem that all governance architectures must adopt this model. An appended source map identifies the controlling publication for each doctrinal position, and a claim-status appendix states, for each principal construct, what kind of claim it is, how it can be independently examined, and what it does not establish. Version 1.3. This edition extends the doctrine with one limitation and one interpretive bridge, and executes accumulated citation maintenance. Section 13 adds the evaluative-adequacy limitation per What Deterministic Authorization Requires: the three integrity properties and a positive Authorization Artifact Test result do not, by themselves, establish that the representation and evaluation addressed the conditions material to permission within the declared scope; evaluative adequacy is not a fourth integrity property, and Input Integrity and evaluative adequacy are different questions, neither establishing the other. Section 10 states this monograph's reading of Deterministic Governance Is Multi-Dimensional: its reference to corresponding 5TS integrity tests is evidence contribution to the ABIM properties, not equivalence or restatement, and its five assurance functions remain a separate decomposition. Section 12's substitution set gains the four-substitution application of Dangerous Trends. Appendix B gains role statements for all three, mapping the execution binding of What Deterministic Authorization Requires to canonical equivalence together with state freshness and release binding. Appendix D grows to 76 headwords, adding Evaluative adequacy and Useful coverage at their sources' operative formulations. References: Deterministic Governance Is Multi-Dimensional enters as 42, Dangerous Trends as 43, and What Deterministic Authorization Requires as 44; the Taxonomy pin moves to v1.7.1. No settled result is changed. It supersedes Version 1.2 (September 2026), recorded below. Version 1.2. This edition extends the doctrine with three additions and executes accumulated citation maintenance. Section 5 adds the risk-acceptance subsection: risk acceptance and risk transfer decide where an action-specific permission requirement applies and never convert an existing requirement into no requirement; evidence of accepted risk is a governed input to a verdict, not the verdict; and where an action executes without an action-bound verdict, no risk posture supplies the authorization artifact after the fact, the gap the technical advisory TA-2026-01 identifies. Section 11 adds the layered-supervision application per Layering Is Not Authorization: release on aggregated non-objection is not a policy-grounded verdict over the specific proposed action, and increasing the number of PASS signals does not change PASS into ALLOW, a categorical result that holds against a stack of deterministic validators. Section 13 adds the deliberative-adequacy limitation per The Override Asymmetry v2.2 (the boundary can bind what was presented to a resolver and under what authority; neither satisfaction of presentation conditions nor a valid authority-bound resolution establishes the adequacy of the resolver's deliberation; reconstruction cannot recover a distinction the boundary did not bind) and disclaims cross-organizational compatibility evidence, locating that problem in Cross-Agent Governance Alignment, whose result becomes part of authorization only through each domain's local runtime authorization boundary under the Composition Test. Appendix C adds boundary completeness as a necessary-condition filter. Appendix D grows to 74 headwords, and the glossary expressly distinguishes the governed state, the factual and operational conditions evaluated, from the governing state under which evaluation occurs. Appendix A records the corrected Override Asymmetry superseding note and the Version 1.2 Additions row. Citation pins move to the current editions: the Authorization Boundary Integrity Model v1.2, The Override Asymmetry v2.2 with its companion, Execution-Time Authorization for AI Agents v3.1, and The Authorization Boundary v3.1; Layering Is Not Authorization enters as reference 40 and Cross-Agent Governance Alignment as reference 41. Section 6 states the escalation custody handoff explicitly and distinguishes custody transfer from decision authority (custody of the held action transfers; the authority to emit the operative verdict remains with the boundary), and every abbreviation is spelled out at first use. No settled result is changed. Version 1.1. This edition aligns the monograph with subsequently deposited controlling sources: the Authorization Artifact Test v1.2 (declared replay modes and bound-materials reconstruction), the Authorization Boundary Integrity Model v1.1 with the ABIM Evidence Requirements v3.5 (input integrity as decision-time admissibility; property-level evidence conclusions), Override Asymmetry v2.0 (boundary-exclusive human resolution of escalated actions), The Closed-World Bargain v1.1 (declared scope; bounded authorization versus authorization infrastructure), and current editions of the foundational corpus. The Version 1.0 capsule source map is retained as a historical record with superseding notes. What this record is. A technical monograph stating a general doctrine. FERZ, Inc. builds deterministic governance infrastructure for AI systems; this monograph does not describe a FERZ product and certifies no implementation. Citation. Cite the concept DOI for the work and the version DOI for this specific edition. Related work. Meyman, E. (2026). The Authorization Non-Substitution Principle. FERZ, Inc. https://doi.org/10.5281/zenodo.22017004 Meyman, E. (2026). On the Impossibility of Observability-Based Authorization. FERZ, Inc. https://doi.org/10.5281/zenodo.19647542 Meyman, E. (2026). The Authorization Artifact Test. FERZ, Inc. https://doi.org/10.5281/zenodo.20013582 FERZ, Inc. (2026). Five Tests Standard (5TS), Version 1.2.0. https://doi.org/10.5281/zenodo.21040295 Meyman, E. (2026). The Authorization Boundary Integrity Model. FERZ, Inc. https://doi.org/10.5281/zenodo.20929115 FERZ, Inc. (2026). ABIM Evidence Requirements. https://doi.org/10.5281/zenodo.22117938 Meyman, E. (2026). The Override Asymmetry. FERZ, Inc. https://doi.org/10.5281/zenodo.19772248 Meyman, E. (2026). The Closed-World Bargain. FERZ, Inc. https://doi.org/10.5281/zenodo.21643658 Meyman, E. (2026). Layering Is Not Authorization. FERZ, Inc. https://doi.org/10.5281/zenodo.22267761 Meyman, E. (2026). Cross-Agent Governance Alignment (CAGA). FERZ, Inc. https://doi.org/10.5281/zenodo.18761409 Meyman, E. (2026). What Deterministic Authorization Requires: Runtime Boundaries, Formal Evaluation, and Authorization Evidence. FERZ, Inc. https://doi.org/10.5281/zenodo.22749462 Meyman, E. (2026). Deterministic Governance Is Multi-Dimensional: Beyond Bounded Execution Gating in AI Systems. FERZ, Inc. https://doi.org/10.5281/zenodo.18902166 Meyman, E. (2026). Dangerous Trends: Monitoring Is Not Authorization. FERZ, Inc. https://doi.org/10.5281/zenodo.22760847 Meyman, E. (2026). A Taxonomy of AI Governance Approaches. FERZ, Inc. https://doi.org/10.5281/zenodo.18275969

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-17
DOI
https://doi.org/10.5281/zenodo.22803857
Primary Topic
Scientific Computing and Data Management
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Deterministic AI Governance: A Unified Derivation of the Runtime Authorization Boundary, Authorization Artifact, Integrity Model, and Five Tests Standard

Edward Meyman
Zenodo (CERN European Organization for Nuclear Research)
Scientific Computing and Data Management
article

Deterministic AI Governance: A Unified Derivation of the Runtime Authorization Boundary, Authorization Artifact, Integrity Model, and Five Tests Standard

Edward Meyman
article en

Abstract

This monograph reconstructs the FERZ governance doctrine as a unified analytical argument. Beginning with the distinction between observation and pre-execution authorization, it states the additional definitions and integrity requirements from which the runtime authorization boundary, the authorization artifact, the Authorization Boundary Integrity Model, and the Five Tests Standard follow. Deterministic here qualifies the authorization control, not the governed system or the correctness of its outputs; the doctrine does not claim that the governed AI system, the formation of policy, the source inputs, or the authorized human resolution process are deterministic. The derivation. The argument proceeds from the governance problem through the separation of authority, delegation, policy, authorization, and enforcement; derives the runtime authorization boundary, the three-member verdict space (ALLOW, DENY, ABSTAIN, with ABSTAIN blocking execution and initiating the governed escalation path: an authorized human resolution supplies authority-bound input, the boundary materially consumes it and emits a separate action-bound verdict, and the ABSTAIN remains unresolved until that verdict exists); derives the authorization artifact and the independent-reconstruction requirement under a declared replay mode; decomposes boundary integrity into three orthogonal properties (output integrity, input integrity as decision-time admissibility, replay integrity) over the input-binding substrate; states the normative control requirements at the standard level; and culminates in the Authorization Non-Substitution Principle, for which the corpus's substitution analyses provide representative applications. Position relative to established traditions. The monograph positions the resulting structure relative to the reference-monitor, access-control, and runtime-verification traditions, to proof-carrying authorization and related evidence models, and to the provenance tradition. The contribution claimed is not ownership of the inherited principles but the derivation of a unified authorization structure from their application to a specific governance problem. Nothing in the comparison implies that conventional authorization technology is categorically incapable of satisfying the derived requirements; classification attaches to the deployed arrangement, not to the name or tradition of its components. Claim discipline. The argument is conceptual and classificatory. It does not report empirical validation or claim that these constructs follow from a single premise alone. Here, derivation denotes a structured analytical reconstruction: each later requirement follows conditionally from the stated authorization objective, definitions, scope assumptions, and cited prior results; it is not a theorem that all governance architectures must adopt this model. An appended source map identifies the controlling publication for each doctrinal position, and a claim-status appendix states, for each principal construct, what kind of claim it is, how it can be independently examined, and what it does not establish. Version 1.3. This edition extends the doctrine with one limitation and one interpretive bridge, and executes accumulated citation maintenance. Section 13 adds the evaluative-adequacy limitation per What Deterministic Authorization Requires: the three integrity properties and a positive Authorization Artifact Test result do not, by themselves, establish that the representation and evaluation addressed the conditions material to permission within the declared scope; evaluative adequacy is not a fourth integrity property, and Input Integrity and evaluative adequacy are different questions, neither establishing the other. Section 10 states this monograph's reading of Deterministic Governance Is Multi-Dimensional: its reference to corresponding 5TS integrity tests is evidence contribution to the ABIM properties, not equivalence or restatement, and its five assurance functions remain a separate decomposition. Section 12's substitution set gains the four-substitution application of Dangerous Trends. Appendix B gains role statements for all three, mapping the execution binding of What Deterministic Authorization Requires to canonical equivalence together with state freshness and release binding. Appendix D grows to 76 headwords, adding Evaluative adequacy and Useful coverage at their sources' operative formulations. References: Deterministic Governance Is Multi-Dimensional enters as 42, Dangerous Trends as 43, and What Deterministic Authorization Requires as 44; the Taxonomy pin moves to v1.7.1. No settled result is changed. It supersedes Version 1.2 (September 2026), recorded below. Version 1.2. This edition extends the doctrine with three additions and executes accumulated citation maintenance. Section 5 adds the risk-acceptance subsection: risk acceptance and risk transfer decide where an action-specific permission requirement applies and never convert an existing requirement into no requirement; evidence of accepted risk is a governed input to a verdict, not the verdict; and where an action executes without an action-bound verdict, no risk posture supplies the authorization artifact after the fact, the gap the technical advisory TA-2026-01 identifies. Section 11 adds the layered-supervision application per Layering Is Not Authorization: release on aggregated non-objection is not a policy-grounded verdict over the specific proposed action, and increasing the number of PASS signals does not change PASS into ALLOW, a categorical result that holds against a stack of deterministic validators. Section 13 adds the deliberative-adequacy limitation per The Override Asymmetry v2.2 (the boundary can bind what was presented to a resolver and under what authority; neither satisfaction of presentation conditions nor a valid authority-bound resolution establishes the adequacy of the resolver's deliberation; reconstruction cannot recover a distinction the boundary did not bind) and disclaims cross-organizational compatibility evidence, locating that problem in Cross-Agent Governance Alignment, whose result becomes part of authorization only through each domain's local runtime authorization boundary under the Composition Test. Appendix C adds boundary completeness as a necessary-condition filter. Appendix D grows to 74 headwords, and the glossary expressly distinguishes the governed state, the factual and operational conditions evaluated, from the governing state under which evaluation occurs. Appendix A records the corrected Override Asymmetry superseding note and the Version 1.2 Additions row. Citation pins move to the current editions: the Authorization Boundary Integrity Model v1.2, The Override Asymmetry v2.2 with its companion, Execution-Time Authorization for AI Agents v3.1, and The Authorization Boundary v3.1; Layering Is Not Authorization enters as reference 40 and Cross-Agent Governance Alignment as reference 41. Section 6 states the escalation custody handoff explicitly and distinguishes custody transfer from decision authority (custody of the held action transfers; the authority to emit the operative verdict remains with the boundary), and every abbreviation is spelled out at first use. No settled result is changed. Version 1.1. This edition aligns the monograph with subsequently deposited controlling sources: the Authorization Artifact Test v1.2 (declared replay modes and bound-materials reconstruction), the Authorization Boundary Integrity Model v1.1 with the ABIM Evidence Requirements v3.5 (input integrity as decision-time admissibility; property-level evidence conclusions), Override Asymmetry v2.0 (boundary-exclusive human resolution of escalated actions), The Closed-World Bargain v1.1 (declared scope; bounded authorization versus authorization infrastructure), and current editions of the foundational corpus. The Version 1.0 capsule source map is retained as a historical record with superseding notes. What this record is. A technical monograph stating a general doctrine. FERZ, Inc. builds deterministic governance infrastructure for AI systems; this monograph does not describe a FERZ product and certifies no implementation. Citation. Cite the concept DOI for the work and the version DOI for this specific edition. Related work. Meyman, E. (2026). The Authorization Non-Substitution Principle. FERZ, Inc. https://doi.org/10.5281/zenodo.22017004 Meyman, E. (2026). On the Impossibility of Observability-Based Authorization. FERZ, Inc. https://doi.org/10.5281/zenodo.19647542 Meyman, E. (2026). The Authorization Artifact Test. FERZ, Inc. https://doi.org/10.5281/zenodo.20013582 FERZ, Inc. (2026). Five Tests Standard (5TS), Version 1.2.0. https://doi.org/10.5281/zenodo.21040295 Meyman, E. (2026). The Authorization Boundary Integrity Model. FERZ, Inc. https://doi.org/10.5281/zenodo.20929115 FERZ, Inc. (2026). ABIM Evidence Requirements. https://doi.org/10.5281/zenodo.22117938 Meyman, E. (2026). The Override Asymmetry. FERZ, Inc. https://doi.org/10.5281/zenodo.19772248 Meyman, E. (2026). The Closed-World Bargain. FERZ, Inc. https://doi.org/10.5281/zenodo.21643658 Meyman, E. (2026). Layering Is Not Authorization. FERZ, Inc. https://doi.org/10.5281/zenodo.22267761 Meyman, E. (2026). Cross-Agent Governance Alignment (CAGA). FERZ, Inc. https://doi.org/10.5281/zenodo.18761409 Meyman, E. (2026). What Deterministic Authorization Requires: Runtime Boundaries, Formal Evaluation, and Authorization Evidence. FERZ, Inc. https://doi.org/10.5281/zenodo.22749462 Meyman, E. (2026). Deterministic Governance Is Multi-Dimensional: Beyond Bounded Execution Gating in AI Systems. FERZ, Inc. https://doi.org/10.5281/zenodo.18902166 Meyman, E. (2026). Dangerous Trends: Monitoring Is Not Authorization. FERZ, Inc. https://doi.org/10.5281/zenodo.22760847 Meyman, E. (2026). A Taxonomy of AI Governance Approaches. FERZ, Inc. https://doi.org/10.5281/zenodo.18275969

Zenodo (CERN European Organization for Nuclear Research)
Ferghana Polytechnical Institute (UZ), Ferro (United States) (US)
Peace, Justice and strong institutions
Openalex Percentile: Top 3%
Scientific Computing and Data Management
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.