HOW CRU WORKS

How CRU Works

A Canonical Representation Unit brings identity, state, evidence, integrity, and governance into a computational object whose representation can be independently evaluated across systems.

01

Start with the object.

Conventional systems often distribute responsibility for an object across multiple services. One establishes identity. Another stores state. Another evaluates policy. Another determines permissions. Another records provenance.

CRU brings those concerns into a common governed representation.

Identity
State
Evidence
Governance

The database, network, cloud, application, or execution environment can change without necessarily redefining the object itself.

02

Canonical Representation

Portability requires more than copying data. Two systems need a deterministic way to determine whether they are evaluating the same logical object and state.

Logical Object
Canonical Representation
Cryptographic Verification

The particular storage or transport mechanism does not define the CRU.

03

Cryptographic Integrity and Provenance

A signature is evidence. An attestation is evidence. A cryptographic hash is evidence. Provenance is evidence.

But evidence alone does not determine authority. A valid signature may establish who signed something. It does not automatically determine what the receiving system should permit because of that signature.

Cryptography establishes evidence. Governance determines what that evidence means.
04

Identity and State

Identity asks: What object is this? State asks: What is true about this object now?

Alice can remain the same person while her role changes. A device can remain the same device while its security condition changes. An AI object can retain continuity while its governing state evolves.

05

Evidence and Context

Identity alone rarely determines authority. A governance decision may depend upon the object’s current state together with applicable evidence and context.

INPUT

Identity

Who or what is represented.

INPUT

Role / Qualification

Relevant governed attributes.

INPUT

Assignment

Current purpose or responsibility.

INPUT

Device Condition

Current technical context.

INPUT

Operational Context

Conditions surrounding the request.

INPUT

Applicable Policy

Rules governing the decision.

06

Governance Evaluation

Governance gives those inputs meaning. This is broader than authentication. Authentication may establish identity. Governance determines what may occur under the current conditions.

State + Evidence + Context + Policy
Governance Evaluation
07

Governed Result

A Governed Result expresses the outcome of a particular governance evaluation.

Evidence + Context + Policy
Governance Evaluation
Governed Result
Not “Authorized Everywhere.”

Authorized Under These Conditions.

A Governed Result exists within an Authority Context that establishes the boundary within which the result has meaning.

Explore Authority Context and Federation →
08

From Governed Result to Capability

The capability is not arbitrary authority carried by an object. It is an operational expression of applicable governance.

Governed Result
Capability
Local Enforcement
09

Capability Leases

Not every capability should become a permanent entitlement. CRU can support capabilities bounded by purpose, scope, conditions, or time.

Governance Evaluation
Capability Lease
Bounded Action
Expiration / Revocation
Just enough. Just in time.
10

Governed State Transitions

A proposed change does not have to become accepted state merely because someone attempted to modify the object.

Current State
Candidate Change
Governance Evaluation
Accepted / Rejected
New Governed State

The object persists while governance determines which state transitions become authoritative.

11

Event-Driven Governance

A qualification may expire. A mission condition may change. A device may become compromised. Another governed object may change state.

Event
CRU-TR
Governance Evaluation
Governed Result
State / Capability Effect
A trigger can initiate governance. It does not manufacture authority.
12

Disconnected Operation

Where the required CRU state, evidence, governing rules, and applicable capabilities are available locally, governance need not require continuous connectivity to a centralized service.

Verify Locally
Evaluate Locally
Enforce Locally
Reconcile When Connected
Disconnected does not mean uncontrolled operation.
13

Separation of Trust and Execution

The source of authority does not necessarily have to be the environment performing the action.

Authority
↓
Verifiable Governed Result
EXECUTION BOUNDARY
Independent Execution Environment

This separation allows governance to travel without requiring every participating system to become part of one centralized trust environment.

THE MODEL

The CRU model.

Canonical Representation
Cryptographic Verification
Identity + Governed State
Evidence + Context
Governance Evaluation
Governed Result
Capability / Effect
State Evolution
Cryptography establishes evidence. Governance determines meaning. Governed results determine permitted effect within bounded authority.

CRU makes that relationship a property of the governed computational object rather than leaving it entirely implicit in the infrastructure surrounding it.

NEXT

Governance & Federation

What happens when a governed object crosses an authority boundary?

Explore Governance & Federation →