Identity
Who or what is represented.
A Canonical Representation Unit brings identity, state, evidence, integrity, and governance into a computational object whose representation can be independently evaluated across systems.
Conventional systems often distribute responsibility for an object across multiple services. One establishes identity. Another stores state. Another evaluates policy. Another determines permissions. Another records provenance.
CRU brings those concerns into a common governed representation.
The database, network, cloud, application, or execution environment can change without necessarily redefining the object itself.
Portability requires more than copying data. Two systems need a deterministic way to determine whether they are evaluating the same logical object and state.
The particular storage or transport mechanism does not define the CRU.
A signature is evidence. An attestation is evidence. A cryptographic hash is evidence. Provenance is evidence.
But evidence alone does not determine authority. A valid signature may establish who signed something. It does not automatically determine what the receiving system should permit because of that signature.
Cryptography establishes evidence. Governance determines what that evidence means.
Identity asks: What object is this? State asks: What is true about this object now?
Alice can remain the same person while her role changes. A device can remain the same device while its security condition changes. An AI object can retain continuity while its governing state evolves.
Identity alone rarely determines authority. A governance decision may depend upon the object’s current state together with applicable evidence and context.
Who or what is represented.
Relevant governed attributes.
Current purpose or responsibility.
Current technical context.
Conditions surrounding the request.
Rules governing the decision.
Governance gives those inputs meaning. This is broader than authentication. Authentication may establish identity. Governance determines what may occur under the current conditions.
A Governed Result expresses the outcome of a particular governance evaluation.
Not “Authorized Everywhere.”
Authorized Under These Conditions.
A Governed Result exists within an Authority Context that establishes the boundary within which the result has meaning.
Explore Authority Context and Federation →The capability is not arbitrary authority carried by an object. It is an operational expression of applicable governance.
Not every capability should become a permanent entitlement. CRU can support capabilities bounded by purpose, scope, conditions, or time.
Just enough. Just in time.
A proposed change does not have to become accepted state merely because someone attempted to modify the object.
The object persists while governance determines which state transitions become authoritative.
A qualification may expire. A mission condition may change. A device may become compromised. Another governed object may change state.
A trigger can initiate governance. It does not manufacture authority.
Where the required CRU state, evidence, governing rules, and applicable capabilities are available locally, governance need not require continuous connectivity to a centralized service.
Disconnected does not mean uncontrolled operation.
The source of authority does not necessarily have to be the environment performing the action.
This separation allows governance to travel without requiring every participating system to become part of one centralized trust environment.
Cryptography establishes evidence. Governance determines meaning. Governed results determine permitted effect within bounded authority.
CRU makes that relationship a property of the governed computational object rather than leaving it entirely implicit in the infrastructure surrounding it.
What happens when a governed object crosses an authority boundary?
Explore Governance & Federation →