Logical architecture

A decision system with explicit authority at every boundary.

Atlas separates evidence collection, identity authority, policy evaluation, enforcement, and audit so each signal, assertion, and model result retains its defined authority in the access path.

System layers

Composable services. Deliberate seams.

The browser and API surface present one operational experience. Underneath, services maintain narrow responsibilities and communicate through authenticated interfaces, durable event paths, and policy-bound records.

Runtime path

Every request is evaluated in context.

Authentication establishes control of an authenticator at a stated assurance. Resource policy evaluates the requested action against current evidence and returns an outcome and obligations to the enforcement point.

1 · Request and authenticate

Bind subject, client, session, requested resource, action, and authenticators.

2 · Assemble and decide

Resolve authoritative identity, entitlement, device, threat, relationship, and trust evidence under a named policy version.

3 · Enforce and record

Allow, step up, deny, or return indeterminate; enforce obligations and emit a digest-bound receipt.

Zero-trust invariant: network location, prior access, organizational membership, or a high trust projection may contribute evidence, but none is an implicit authorization grant.

Data and authority

Truth has an owner.

Atlas records which source asserted a fact, when it was observed, how long it is valid, and which transformation produced the normalized value.

  • Authoritative stateTransactional identity, policy, governance, session, and configuration state belongs in durable databases.
  • Derived viewsGraph relationships, caches, search indexes, and model features serve as derived acceleration layers under the authoritative store.
  • Cryptographic custodyProduction signing keys and root secrets are externalized to an approved key authority, with rotation and revocation lifecycles.
  • Evidence retentionReceipts preserve digests, policy versions, source lineage, and verdict reasons without requiring unrestricted replication of source data.

A fast answer is useful. An answer that can be traced to the right authority, policy, and point in time is operationally defensible.

AT

Authority types

Identity authority owns the canonical subject and lifecycle state.

Policy authority owns approved decision logic and activation.

Evidence authorities attest observations within defined scope.

Enforcement points apply the returned result to a named resource and action.

Federated operation

Exchange verifiable context. Preserve local control.

Cross-boundary messages are signed, issuer-bound, audience-bound, purpose-limited, time-bounded, and replay-controlled. A receiving authority checks applicability before mapping claims or adverse signals into its own policy namespace.

  • Local authorizationThe receiving policy maps foreign roles, scores, and assertions under local rules.
  • Restriction can travel safelyAdverse information may narrow access when policy permits; favorable foreign evidence must satisfy stronger comparability gates.
  • Compartments remain compartmentsPartners exchange pseudonymous subject references and decision-relevant claims while containing disclosure to the approved purpose.
Federation operations view with edge and enterprise nodes
Federation operationsIndependent authorities · scoped exchange

Edge and DDIL

Local continuity with explicit connectivity state.

At the edge, Atlas evaluates signed policy and locally available evidence inside an explicit freshness window. It queues attributable changes for reconciliation and surfaces missing central confirmation and applies the defined resource policy.

01

Before separation

Distribute signed policy, issuer trust, key material, revocation posture, subject scope, and time constraints.

02

During disconnection

Use local authority for bounded decisions; surface stale evidence and unavailable dependencies in the result.

03

After reconnect

Verify origin and ordering, replay queued evidence, resolve conflicts, and record reconciliation outcomes.

Failure behavior

Degradation is an explicit policy state.

Each dependency is classified by authority and criticality. Atlas can deny, request step-up, return indeterminate, or operate within a bounded cached window. Administrative surfaces show which dependency changed the posture.

ALLOW

Required evidence is fresh and all policy conditions pass.

STEP_UP

Additional assurance can satisfy the current policy floor.

DENY

A hard gate, veto, or explicit policy condition rejects access.

INDETERMINATE

A required authority or dimension cannot support a valid decision.