Identity · Authority · Current State · Execution

SAQ™ Admissibility Gate

A deterministic, fail-closed checkpoint before consequential execution.
SAQ™ prevents identity, credentials, model output, workflow requests, or confidence from silently becoming authority to act. It separates private identity from operational activity, validates current authority and state, and admits or refuses each governed action before execution.
Stolen key ≠ verified identity. Verified identity ≠ current authority. Current authority ≠ automatic execution.
The Drift Stack layered architecture: Identity, Frame, Boundary, Drift, and Correction

The Drift Stack™

Identity → Frame → Boundary → Drift → Correction

The original authority failure

The Security Problem SAQ™ Was Built to Solve

Most digital systems collapse authentication, identity, and authority into one trust event.

A person or system presents a password, token, key, certificate, or signed request. If the credential verifies, the system assumes the identity is valid and allows the associated authority to travel with it.

Credential accepted → identity assumed → authority inherited → execution allowed

Credential theft, cryptographic failure, insider compromise, stale permissions, or implementation error can therefore expose everything downstream of the first accepted event.

SAQ™ breaks that inheritance chain.

Identity remains protected

Identity Is Separated Through Shadow ID

SAQ™ separates the private identity record from the identifiers used throughout applications, workflows, models, ledgers, and execution systems.

The private identity remains inside a protected identity boundary. Operational systems receive a Shadow ID rather than direct access to the person or organization behind it.

Private identity → Shadow ID → validated authority → admissibility decision → execution
  • Private identity data remains separated from ordinary system activity.
  • Applications operate on a Shadow ID rather than exposing the underlying person or organization record.
  • A compromised application identifier does not automatically reveal private identity.
  • A valid identity does not automatically inherit unlimited authority.
  • Authority remains scoped to the entity, action, context, boundary, system state, and current permission.

Shadow ID is not merely a privacy alias. It establishes a structural boundary between who an entity is and what a system is currently permitted to do on that entity's behalf.

Limit what compromise can inherit

What Secure Against Quantum™ Means

SAQ™ does not claim that quantum attacks, cryptographic failures, or credential compromise can never occur.

It changes what an attacker gains if one does occur.

  • A stolen credential is not automatically accepted as the complete identity.
  • A recognized identity is not automatically granted authority.
  • Previously valid authority is not assumed to remain current.
  • A permitted action cannot execute outside its defined boundary.
  • Drift, stale state, or failed verification can invalidate permission before execution.

Post-quantum cryptography protects keys, signatures, and encrypted communications. SAQ™ protects the authority architecture behind them so the complete trust model does not depend on a credential alone.

The execution decision

The SAQ™ Admissibility Gate

The gate is a deterministic, fail-closed checkpoint placed directly in the execution path.

At runtime, it answers one question:

Is this specific entity allowed to take this specific action, inside this boundary, under this authority, in the current system state, right now?

The model may suggest. The workflow may request. The agent may appear confident. None of those conditions grants permission to act.

Resolved acting entity
Current, scoped authority
Defined action and execution boundary
Authoritative ledger and system state
Required evidence and validation status
Drift, expiry, revocation, and correction state

Approve

The requested action is admissible under the current identity, authority, boundary, evidence, and state.

Refuse

Execution is blocked because one or more required conditions are absent, invalid, or outside scope.

Invalidate

Previously valid permission is revoked because identity, authority, context, boundary, or state has drifted.

Wired into the governed action path

Where the Gate Sits

  • Downstream of identity resolution
  • Downstream of current authority determination
  • Downstream of boundary and authoritative state
  • Upstream of every governed or irreversible action
  • Inside the wired workflow and non-bypassable by design
Identity → Shadow ID → authority state → boundary and ledger → SAQ™ Gate → action surface

If an action can occur without passing through the gate, it is outside the governed surface. A control that can be bypassed is not the execution boundary.

SAQ™ identity, authority, admissibility, execution, and external correction architecture

Identity and current state establish the governed boundary. The admissibility mechanism determines whether the requested transition may execute. Correction remains external to the execution environment.

From possibility to consequence

SAQ™ Inside the Reality Stack™

SAQ™ is not a safety layer added after a model produces an answer. It is an execution mechanism operating inside the larger Reality Stack™ and Drift Stack™ architecture.

The Reality Stack™ defines possibility, boundary, authoritative state, drift, and correction. The Drift Stack™ operationalizes identity, reference frame, coherence boundary, drift, and external correction.

SAQ™ sits at the transition between possibility and consequence. It determines whether a requested transition is admissible before that transition becomes part of reality.

The mechanism must be demonstrable

SAQ™ Conformance Requirements

A system cannot claim SAQ™ conformance by adopting the language or displaying a diagram. It must demonstrate the architecture in operation.

  • Separate private identity from ordinary system identifiers and activity.
  • Resolve operational activity through a protected Shadow ID or equivalent identity boundary.
  • Bind execution authority to an explicit entity, action, boundary, context, and current state.
  • Route every governed action through a non-bypassable admissibility gate.
  • Produce deterministic approve, refuse, or invalidate outcomes.
  • Detect and invalidate stale authority when identity, context, boundary, or system state drifts.
  • Require correction or revalidation before authority resumes.

Conformance depends on implemented mechanisms and evidence—not company size, marketing language, intent, or payment alone.

SAQ™ mechanisms are addressed by filed and pending U.S. patent applications related to identity separation, authority, admissibility, execution control, drift detection, invalidation, and external correction. Discussion and citation are welcome; implementation and commercial-use rights require an applicable license.

Technical Architecture

The model proposes. The architecture determines whether the system is allowed to act.

Use the licensing page for commercial implementation rights, or the partner pathway to explore a deeper build-and-certify relationship with Samirac.