Skip to content
Black Atlas — Powered by KRYOS V6

Release control

Human Decision Gates


Sensitive, contested or high-impact outputs require explicit human review before use. Black Atlas supports decision quality; it does not automate accountability.

Why review exists

Review is an operating control, not a disclaimer

Triggers

What requires human review

  • conclusions that would change the security posture of a production environment
  • outputs where registered sources contradict each other
  • answers resting on inference rather than observed evidence
  • material intended for executive, board, regulator or customer circulation
  • anything touching attribution, legal exposure or personnel
  • any request beyond the authorization level agreed in advance

States

Review states and release conditions

Unreviewed

Generated and bounded, but not yet examined by a person. Not for circulation.

In review

A named reviewer holds the output, with the evidence and contradictions attached.

Approved for internal use

Cleared for the team that owns the environment, within the stated qualifications.

Approved for external release

Cleared for circulation beyond the owning team, with sign-off recorded.

Returned

Sent back for narrowing, more evidence, or abstention.

How work is allowed to leave

Released

Evidence, scope, review, and acceptance criteria are satisfied.

Released with qualifications

Material limitations or uncertainty remain but are explicitly bounded and accepted by the accountable authority.

Insufficient evidence

Evidence is incomplete, stale, non-reproducible, or too weak for the requested conclusion.

Out-of-distribution

The system, data, or use case materially differs from validated conditions.

Blocked

Authorization, safety, competency, evidence, or release criteria are not satisfied.

Accountability

Who owns the decision

Named sign-off

Release is attributed to a person, not to the system. The record shows who approved what, on which evidence, and when.

Reconstructable reasoning

Inputs, retrievals, contradictions, conclusions and releases are logged so a decision can be replayed rather than remembered.

Authorization stays upstream

Analytical capability never creates operational authority. Permission to analyse is not permission to act.

Fail-closed default

If permission, scope or evidence is missing, the gate holds. The default is to stop, not to proceed carefully.

Authorization

High-risk and contested outputs

Authorization levels are agreed in advance and fix what may be executed. Analytical capability never widens them, and no gate is bypassed because an answer looks convincing.

Level 0

Passive analysis of supplied artifacts and authorized evidence. No target interaction.

Level 1

Digital-twin, graph, or synthetic simulation. No production interaction.

Level 2

Safe non-invasive validation using approved queries, read-only checks, dry runs, stubs, synthetic users, or equivalent controls.

Level 3

Controlled authorized security testing in explicitly named environments using an approved test plan, monitoring, rate limits, stop conditions, and rollback.

Level 4

Preauthorized reversible containment by policy. No irreversible action and no authority inferred from general testing permission.