Arriving mid-argument Own your surface · the depth model ↗ Layers 04 & 05 · org-bound
The surface · the org-bound reading

The deepest two layers are not a platform problem. They are an org design problem.

Authority is granted by an organization before it is enforced by a system.

If you came here from the depth model, you already have the argument: own your source, own your surface — and the surface has five layers, worked from the inside out.

This page is where the last two of them get built. Not the code that enforces them — the design decisions that have to exist before any platform can enforce anything: who may grant authority, what gets recorded, and who owns the record.

01 · Where you are

Five layers, numbered outside-in and worked inside-out.

The surface is not a perimeter. It is depth — from how the agentic world perceives you, down to the record it must never rewrite. Two of those layers are commodities you should address and not overpay for. Three are urgent.

Start at the deepest layer, where the value and the danger both concentrate, and move outward. That triage order is the whole reason this page exists at the bottom of the stack rather than the top.

The full argument, the figures behind it, and the two commodity layers are at Pegasus Source. This page assumes them.

01 Reputation & GEO Commodity
02 Agentic legibility Commodity
03 Edge security Urgent
04 The membrane You are here
05 The sovereign core You are here
02 · Layer 04, as org design

A membrane is an organizational artifact that happens to be enforced in software.

The membrane is the layer that decides what any other layer is allowed to do: every consequential action authenticated, permissioned, and recorded. Software enforces it. But software cannot invent it — someone has to decide what authority exists, who may grant it, and what the organization is willing to be held to afterward.

Those are org design decisions, and they fail in a specific way: not with a breach, but with a decision no one can account for. Three of them carry most of the weight.

The permission envelope
A positive definition of what may be done.

Not a list of prohibitions — those encode an estimate of capability, and the estimate is always wrong. An envelope states the systems, operations, and authority granted, and closes everything else. Writing one is an act of delegation: it forces an organization to say out loud which decisions it is prepared to hand over, and to whom.

The decision trace
What was decided, on what basis, under whose authority.

An access log records that something happened. A trace records why it was allowed to. When an optimization target becomes evidence — and it does, the moment anyone asks a court or a regulator to look — the defensible answer was specified in advance or it does not exist. Deciding what the organization traces is deciding what it can later prove.

Ownership of the record
Whoever holds the logs holds the account.

If the trace of your own decisions lives in a vendor's tenancy, on their retention schedule, in their export format, then the account of how your organization behaved is theirs to produce. This is the quietest of the three failures and the hardest to reverse — it is settled in procurement, months before anyone reads a log.

You cannot bound capability. You can only grant authority — and granting is something an organization does.

The membrane, stated plainly
03 · Layer 05, as org design

Reached, never rewritten — as a rule about people, not only about data.

The sovereign core is the encoded judgment of the business: the record of truth that everything else defers to. The discipline that protects it is stated technically — every data object carries its own governance metadata, and the record is reached through a scoped, revocable, logged interface rather than copied out to be rewritten elsewhere.

The organizational half of that rule is less discussed and breaks more often. Every copy of the core is an unowned second version of the truth — and copies are almost never made by attackers. They are made by a team under deadline, given a spreadsheet extract because the governed path was slower than the quarter.

Which means the core is protected by the same thing that protects any standard: making the governed path the fastest one available, and giving someone the authority to say no when it isn't.

Four questions the core answers or doesn't
Who may grant an agent access to the record?
Named, and few. If the answer is "whoever owns the project," there is no core.
How is that grant revoked, and how fast?
Revocation that requires a release cycle is not revocation.
Where are the sanctioned copies, and who signed for them?
Every organization has some. Unlisted ones are the exposure.
When the governed path is slower, who is allowed to overrule it?
If nobody is, everybody is.
04 · How the work runs here

The Four Pillars of GOVERN / ASSURE are how this gets built, not a document about it.

Permission envelopes, decision traces, and log ownership are the production form of the pillars. If the question in your room is "how does this map to what we already answer to?" — NIST AI RMF, the OWASP LLM Top 10, the CSA AI Controls Matrix — that mapping is already written down here.

The crosswalk
The Four Pillars, mapped to the standards →
A direct mapping to NIST AI RMF, OWASP, and the CSA matrix. The canonical reference for the CISO conversation.
The technology dimension
Ready the surface · the enterprise CTO seat →
Where this work sits inside the HOT framework, and what it asks of the seat that owns technology decisions.
The order of the work
The Work — how an engagement moves →
The sequence, the governance rail that runs alongside it, and what is produced at each step.
05 · The same boundary, elsewhere

Enforcement happens in two places, and both are somebody's practice: bound to an organization, which is this page — and bound to a platform, where the crossing is written into the systems that hold the record. Neither is a tier of the other. If your record of truth lives on IBM i, the platform-bound reading is not optional and it is not ours.

Bound to the platform
The crossing, enforced on IBM i ↗
Object security, the audit journal, and the authorization model — the same authority, made native. Pegasus4i.
The argument above both
Own your surface · all five layers ↗
The depth model, the figures behind it, and the two commodity layers. Pegasus Source — the thesis, not a sale.
Design the authority first

Someone has to decide what may be granted. That is the engagement.

Envelopes written, traces specified, log ownership settled before procurement closes it for you — designed into the organization, then handed to whoever enforces it. It starts with a conversation about the decision actually in front of you.

Start the conversation →
Or read where you stand first · the HOT scan ↗ The standards crosswalk →
The ExO 3.0 framework — MTP, the Permission Envelope, the Four Pillars of GOVERN / ASSURE, and HIDO — is the work of
Salim Ismail and contributors. OpenExO · The Organizational Singularity ↗