KERNEL SPACE

Security Kernel

The kernel owns the security primitives beneath autonomous AI execution. Each primitive carries its own maturity label and evidence boundary.

PRIMITIVES

Kernel responsibilities

Specification

Identity

AI entities, artifacts, builds, models, tools, operators, deployments, and evidence bundles.

Specification

Authority

Allow, deny, approval, scope, expiry, delegation, and revocation.

Reference

Integrity

Source, build, dependency, runtime image, policy, manifest, and environment comparisons.

Specification

Policy

Filesystem, network, tool, repository, secret, database, signing, deployment, and failure-mode controls.

Implemented surface

Evidence

Inputs, outputs, tool calls, decisions, builds, tests, findings, incidents, and recovery events.

Reference

Verification

Hashes, signatures, manifests, completeness, runtime conformity, audit scope, and release lineage.

Specification

Containment

Fail-closed behavior for missing, invalid, stale, drifted, revoked, or incomplete state.

Doctrine

Recovery

Revocation, quarantine, key rotation, rollback, evidence continuity, and controlled re-entry.

STATE TRANSITION

Kernel lifecycle

Lifecycle state machine
unregistered -> registered -> policy_bound -> evidence_required
-> verified_with_limitations -> active
-> revoked | quarantined | superseded -> recovered