Start with evidence
Signals remain tied to their source, subject, scope, and observation time.
Evidence-derived trust projection
TrustAI converts validated, current evidence into a purpose-bound projection with confidence and reason codes. Resource policy decides access. Missing evidence, hard gates, and imported context remain visible.
Interpretation
A TrustAI projection answers a bounded question: given the named subject, session, resource, action, audience, policy, evidence, and time, how strongly does the evidence support this access context?
It is a purpose-bound evidence projection. Resource policy, entitlements, assurance, and local authority determine access. Two valid projections for the same subject can differ because the resource, mission, evidence freshness, and policy differ.
Tenant and organization
Subject and session
Purpose and resource
Requested action and audience
Trust profile and policy version
Evidence and applicability digests
Observation and expiry time
Score construction
Each dimension carries an observed value, a conservative lower bound, confidence, weight, source, and freshness. Atlas reduces the influence of uncertain evidence, balances the dimensions, and then applies policy gates.
Signals remain tied to their source, subject, scope, and observation time.
The supported value stays between the conservative floor and the observation. Lower confidence moves it closer to the floor.
Thirteen dimensions
Dimensions separate unlike signals so investigators can see whether the change came from authentication, device, behavior, threat, privilege, federation, resource alignment, or data exposure.
From projection to policy
A projection is evaluated with required dimensions, lower-bound floors, adverse conditions, freshness, and policy-specific thresholds. The same score may produce different outcomes for different resources.
All required evidence and policy conditions pass.
Additional assurance or evidence can meet the current floor.
An explicit adverse veto or hard policy gate is present.
Required evidence or an authority is unavailable, stale, or invalid.
Enterprise continuity
Atlas Trust Fingerprint v2 (ATF2) is a keyed, non-reversible, tenant-scoped lookup handle used to correlate the same governed subject across Atlas contexts.
ATF2 supports enterprise correlation under tenant, purpose, audience, epoch, and read-budget controls. Authentication and authorization remain with their dedicated controls.

Across boundaries
A foreign projection is validated for signature, issuer, profile, audience, purpose, subject binding, freshness, replay, and semantic comparability. The receiving tenant applies its own admission policy.
Model governance
Atlas supports live telemetry and reviewed feedback, but promotion is governed. Training data, labels, validation, calibration, signing, rollback, drift, and operational authority are separate concerns.
Ingest observations with source, subject binding, time, scope, retention, and validation state. Feedback enters governed review before promotion.
Keep training, evaluation, and serving isolated. Record dataset and feature lineage; prevent operational labels from silently feeding the active model.
Evaluate discrimination, calibration, drift, robustness, protected operational scenarios, and the exact model bundle and profile intended for use.
An authorized workflow activates a signed bundle with a defined scope, canary plan, revocation budget, status authority, and rollback target.
Monitor evidence availability, score distribution, explanation integrity, validator status, and outcome quality. Fail closed or advisory when authority is lost.