Operating model
How the Assurance Loop Runs
Nine steps in the loop, ten phases in an engagement, five authorization levels governing what may be touched. Nothing executes because the analysis found it interesting.
The loop
Nine steps, run continuously
Observe
Take in what existing tooling already reports: vulnerability management, endpoint detection, identity, cloud posture, log platforms, governance systems, threat intelligence, red-team findings.
Normalize
Translate every source into one common security ontology: principals, assets, services, resources, credentials, controls, data, trust, actions, threats.
Model
Assemble the adversarial digital twin: a living graph of assets, relationships, access, controls, trust and business consequence.
Infer
Reason over sequences rather than isolated findings, and mark what is known, inferred, simulated, hypothesised or unknown.
Simulate
Run scenarios against the twin: credential compromise, vendor compromise, cloud control failure, CI/CD abuse, agent misuse, insider action.
Validate
Test hypotheses using the safest method that can answer them, inside the authorization level that has actually been granted.
Prioritize
Rank by consequence and structural position, not by severity score alone. Choke points and high-centrality dependencies come first.
Remediate
Propose the smallest set of interventions that disconnects untrusted sources from crown jewels, with the expected risk reduction stated.
Verify
Recompute the attack surface after the change, confirm the pathway is actually broken, and record residual risk.
The ninth step returns to the first. After remediation the surface is recomputed under environmental change, new exposures and revised threat behaviour, which is what makes the state continuous rather than a report with a date on it.
Engagement
The ten-phase assurance lifecycle
Authority
Five authorization levels
Each level is agreed in writing before work starts, with named systems, named windows and a named accountable authority. A level is a ceiling, not a default.
Level 0
Passive analysis of supplied artifacts and authorized evidence. No target interaction.
Level 1
Digital-twin, graph, or synthetic simulation. No production interaction.
Level 2
Safe non-invasive validation using approved queries, read-only checks, dry runs, stubs, synthetic users, or equivalent controls.
Level 3
Controlled authorized security testing in explicitly named environments using an approved test plan, monitoring, rate limits, stop conditions, and rollback.
Level 4
Preauthorized reversible containment by policy. No irreversible action and no authority inferred from general testing permission.
What stays human
Decisions the model never makes
The full list of things this work does not claim is on the limits and non-claims page.

