-
Notifications
You must be signed in to change notification settings - Fork 0
2026 04 27 uelgf foundational definitions principles
Universal Entity Lifecycle Governance Framework (UELGF): foundational definitions, formal principles, and the inseparability of governance and acceleration in the governed golden rail
What are the foundational definitions, formal principles, and architectural properties required to specify the Universal Entity Lifecycle Governance Framework (UELGF) such that it applies consistently to all entity types, all builder personas, and establishes governance and acceleration as inseparable concerns embedded in the governed golden rail, rather than governance as a procedural overlay applied after the fact?
In scope:
- Formal definition of the core constructs: entity (type-agnostic), governed golden rail, licence to operate, and the Policy Decision Point (PDP)
- The principle that the rail is the compliance, following the rail automatically satisfies all governance requirements
- The principle that the getting-started stage is generative: it produces a complete governed scaffold, not a form submission
- The builder persona spectrum (citizen developer through principal engineer through procurement manager) and the requirement that the rail adapts its interface to persona without adapting the governance beneath it
- Declared purpose and scope as a machine-checkable specification rather than a statement of intent
- The principle that off-rail existence is detectable, reportable, and subject to remediation
- The principle that rail adoption is incentivised rather than mandated where possible, with mandation as the backstop
- The principle that the framework is an organisational capability (not a project) requiring a product mindset, ownership, and ongoing investment
- Policy independence: the lifecycle of organisational policy is managed entirely outside the lifecycle of any entity
- Decommission as a first-class concern equivalent in governance rigour to any other lifecycle stage
- The causal problem the framework solves: systems capability debt driving ungoverned workarounds, agentic Artificial Intelligence (AI) removing the implicit rate-limiting controls that made those workarounds tolerable
Out of scope:
- Detailed entity taxonomy or Confidentiality, Integrity, and Availability (CIA) classification (covered by companion item
2026-04-27-uelgf-entity-taxonomy-cia-classification) - Rail specifications for individual entity types or CIA tiers (covered by
2026-04-27-uelgf-governed-golden-rails) - Policy architecture component design (covered by
2026-04-27-uelgf-policy-architecture-8-layer-context) - Decommission procedural specification (covered by
2026-04-27-uelgf-decommission-lifecycle) - Runtime feedback loop specification (covered by
2026-04-27-uelgf-runtime-feedback-loop) - Implementation sequencing and transitional architecture
Constraints:
- All definitions must be precise enough to serve as engineering specifications, not just policy language
- The relationship between entity, rail, licence to operate, and policy engine must be formally specified with dependency directions explicit
- The foundational principles must be consistent with the prior completed research on systems capability debt, agentic AI regulatory preconditions, and business-led low-code governance
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Prior completed research in this repository established that systems capability debt creates workaround demand, that low-code agent creation becomes durable only when platform guardrails already exist, and that write-capable agentic Artificial Intelligence (AI) turns unresolved access, data, and control weaknesses into current or foreseeable control failures.
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html] The unresolved design problem is therefore not whether governance is needed, but how to define one lifecycle control plane in which creation, change, operation, and retirement are already governed at the moment capability is emitted.
- Entity definition: Survey existing definitions of "entity" across security frameworks (National Institute of Standards and Technology (NIST) Zero Trust), enterprise architecture (The Open Group Architecture Framework (TOGAF), ArchiMate), and AI governance (NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0) to determine whether any existing definition is type-agnostic enough to cover AI agents, microservices, Software as a Service (SaaS) products, data pipelines, and procurement decisions under a single construct. Produce the formal definition or justify why a novel one is required.
- Rail vs governance overlay: Investigate the pattern of governance-as-rail versus governance-as-overlay in comparable high-assurance domains (air traffic control certification, pharmaceutical good manufacturing practice, financial product approval) to ground the principle that the rail is the compliance in evidence from other regulated industries.
- Incentive structure for rail adoption: Identify what mechanisms in comparable frameworks (National Health Service (NHS) Digital, Payment Card Industry Data Security Standard (PCI DSS), Federal Risk and Authorization Management Program (FedRAMP)) are used to make the governed path the path of least resistance, and assess their applicability to a multi-persona software delivery context.
- Generating vs administrative getting-started: Contrast the generative scaffold model (output: complete governed scaffold at first moment) with existing registration-based approaches (e.g., ServiceNow Configuration Management Database (CMDB) intake, Amazon Web Services (AWS) Landing Zone account vending) to produce a precise specification of what "generative" means and requires architecturally.
- Policy independence formal property: Identify whether policy independence (policy lifecycle entirely separate from entity lifecycle) is explicitly stated as a design property in any existing framework (Extensible Access Control Markup Language (XACML), Open Policy Agent (OPA) / Rego, Cedar policy language) and what architectural mechanisms enforce it.
- Synthesis: Produce the formal definitions and principles as a set of numbered, testable invariants suitable for use as acceptance criteria when evaluating whether a proposed implementation correctly embodies the UELGF.
- National Institute of Standards and Technology (NIST) Special Publication (SP) 800-207 - Zero Trust Architecture — - zero trust focus on resources, subject and device authorization, and Policy Decision Point (PDP) / Policy Enforcement Point (PEP) decomposition.
- NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0 publication page — - framework purpose and use-case-agnostic positioning.
- NIST AI RMF Core — - Govern, Map, decommission, purpose, scope, oversight, and targeted application subcategories.
- Extensible Access Control Markup Language (XACML) 3.0 core specification — - Policy Administration Point (PAP), Policy Decision Point (PDP), Policy Enforcement Point (PEP), Policy Information Point (PIP), subject, resource, action, and environment definitions.
- Open Policy Agent (OPA) documentation — - policy engine overview and policy-as-code operating model.
- OPA philosophy — - explicit policy decoupling argument and independent policy lifecycle.
- Cedar policy language guide — - entities, schema validation, principal-action-resource-context model, and separation of authorization logic from application code.
- Federal Risk and Authorization Management Program (FedRAMP) authorization process, Office of Management and Budget (OMB) M-24-15 Section IV — - continuously maintained authorization and presumption of adequacy.
- FedRAMP agency authorization path — - readiness assessment, iterative authorization workflow, and continuous monitoring context.
- International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 27001:2022 — - Information Security Management System (ISMS) and continual improvement framing.
- AWS landing zone overview — - foundational governed environment and baseline structure.
- AWS Control Tower overview — - landing zone, controls, drift handling, dashboard, and centralized governance.
- AWS Control Tower Account Factory — - standardized account templates and governed account provisioning.
- ServiceNow Configuration Management Database (CMDB) welcome guide — - registration, onboarding, and data acquisition model rather than governed scaffold generation.
- NHS England digital clinical safety assurance — - mandated national standards, clinical safety documentation, and lifecycle assurance.
- Food and Drug Administration (FDA) Quality Systems Approach to Pharmaceutical current Good Manufacturing Practice (CGMP) Regulations — - quality built into product and testing alone not sufficient.
- Federal Aviation Administration (FAA) Advisory Circular 120-92D, Safety Management Systems — - safety integrated into processes and operations.
- The TOGAF Standard overview — - enterprise architecture methodology and framework context.
- TOGAF introduction to building blocks — - architecture building blocks, interfaces, dependencies, and mapping to organizational entities and policies.
- ArchiMate overview — - enterprise architecture language spanning business processes, organizational structures, information flows, information technology systems, and technical infrastructure.
- Systems capability debt and agentic AI operational risk — - causal context for workaround demand and machine-speed amplification.
- Business-led low-code agent governance — - persona spectrum, platform guardrails, and bounded maker autonomy.
- Agentic AI regulatory preconditions — - regulated-environment control baseline.
- Enterprise AI platform operating models
- AI governance assurance: change control, verification, and review loops
- AI agent identity and access management in the enterprise
(Full output from running the research skill, retained verbatim in the completed item. Sections 0-5 are the investigation, and section 6 seeds the Findings section below.)
- [fact; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/] Research question restated: what formal definitions, principles, and architectural properties are required so the Universal Entity Lifecycle Governance Framework (UELGF) governs every consequential entity through one lifecycle rail in which governance is built into creation and operation rather than added later.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Scope confirmed: this item covers universal definitions, rail principles, persona handling, policy independence, incentive design, and lifecycle parity, while leaving detailed taxonomies, per-entity rails, and implementation sequencing to companion items.
- [fact; source: https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/architecture/togaf7-doc/arch/p4/bbs/bbs_intro.htm; https://www.iso.org/standard/27001] Constraints confirmed: the definitions must be engineering-grade, comparisons must stay grounded in accessible public standards, and places where detailed standard text was not directly accessible are recorded as lower-confidence comparison points.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-platform-operating-models.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-use-case-routing-frameworks.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Prior completed repository work already established that durable enterprise AI governance requires a shared control plane, explicit release gates, risk-based routing, and distinct machine identities, so this item defines the foundational vocabulary those mechanisms depend on.
- Output format: knowledge.
- Root question: What definitions and invariants make UELGF a universal lifecycle governance specification rather than a loose policy metaphor?
-
A. Universal entity abstraction
- A1. How do Zero Trust Architecture (ZTA), Extensible Access Control Markup Language (XACML), Cedar, The Open Group Architecture Framework (TOGAF), and ArchiMate describe the governed object?
- A2. Is any existing term already broad enough to cover assets, services, workflows, automations, data, and external capabilities under one lifecycle abstraction?
- A3. If not, what minimum properties must a novel UELGF entity definition include?
-
B. Rail versus overlay
- B1. Do high-assurance domains treat assurance as embedded in the operating path or as end-stage inspection?
- B2. What does that imply for the proposition that the rail is the compliance?
-
C. Incentive structure
- C1. Which frameworks make the approved path faster, clearer, or more reusable than ad hoc alternatives?
- C2. When is mandation still required as a backstop?
-
D. Generative onboarding
- D1. What distinguishes a generated governed scaffold from a registration or inventory step?
- D2. Which emitted control surfaces are required at the first moment of existence?
-
E. Policy independence
- E1. Which standards explicitly separate policy lifecycle from governed-object lifecycle?
- E2. Which components enforce that separation?
-
F. Continuous authorization and retirement
- F1. What makes a licence to operate continuous rather than one-time?
- F2. Which standards require decommission to be governed with equal rigor?
-
G. Organisational capability
- G1. What evidence shows this must be owned as a product capability rather than a project?
- G2. What acceptance-criteria invariants follow from the evidence?
- [fact; source: https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/togaf] Access note: direct Open Group online specification chapter pages for ArchiMate and newer TOGAF sections returned session-timeout pages in this runtime, so the comparison used the accessible Open Group overview pages plus the public legacy TOGAF building-block page.
- [fact; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/agency-authorization-path/] Access note: the seeded FedRAMP authorization URL returned 404, so the investigation replaced it with the current official OMB Section IV page and the current FedRAMP agency-authorization-path page.
- [fact; source: https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fda.gov/media/71023/download] Access note: the FAA and FDA sources were accessible only as Portable Document Format (PDF) documents in this runtime, so the evidence below is based on extracted text from those official files.
- [fact; source: https://csrc.nist.gov/pubs/sp/800/207/final] NIST Special Publication (SP) 800-207 says Zero Trust Architecture focuses on protecting resources, defined at the abstract level as assets, services, workflows, and network accounts, and it requires authentication and authorization before a session to a resource is established.
- [fact; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html] XACML defines a resource as data, a service, or a system component; a subject as an actor; an action as an operation on a resource; and a Policy Decision Point (PDP) as the system entity that evaluates applicable policy and renders an authorization decision.
- [fact; source: https://docs.cedarpolicy.com/] Cedar defines entities as application data used in authorization decisions, with principals, actions, resources, and context declared in schema and evaluated by an authorization engine that is separate from application code.
- [fact; source: https://www.opengroup.org/architecture/togaf7-doc/arch/p4/bbs/bbs_intro.htm] TOGAF says an Architecture Building Block is a package of functionality defined to meet business needs, with published interfaces, dependencies, and a map to business or organizational entities and policies.
- [fact; source: https://www.opengroup.org/archimate-forum/archimate-overview] ArchiMate describes a language for the construction and operation of business processes, organizational structures, information flows, Information Technology (IT) systems, and technical infrastructure.
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://docs.cedarpolicy.com/; https://www.opengroup.org/architecture/togaf7-doc/arch/p4/bbs/bbs_intro.htm; https://www.opengroup.org/archimate-forum/archimate-overview] No surveyed standard provides one superordinate term that simultaneously covers long-lived assets, short-lived workflows, bounded automations, data-bearing components, and externally acquired capabilities under one lifecycle grammar, so UELGF requires a novel universal entity definition rather than reuse of any single borrowed term.
- [fact; source: https://www.fda.gov/media/71023/download] FDA quality-systems guidance states that quality should be built into the product and that testing alone cannot be relied on to ensure product quality.
- [fact; source: https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf] FAA Advisory Circular 120-92D says a Safety Management System (SMS) is intended to be designed and developed so employees manage risks as part of operations and business decision-making processes.
- [fact; source: https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf] The same FAA circular says system safety attributes are integrated into all processes and procedures.
- [fact; source: https://www.fedramp.gov/docs/authority/m-24-15/process/] The FedRAMP authorization process defines authorization as an assessed and actively maintained security posture whose adequacy is reusable by agencies while continuous monitoring is sustained.
- [inference; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] Comparable high-assurance systems converge on the same design principle: assurance is strongest when embedded into the production path itself, while ex-post inspection or approval without built-in operating controls is treated as insufficient.
- [assumption; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] Cross-domain transfer assumption: the FDA, FAA, and FedRAMP sources are treated as valid structural analogues for UELGF because the shared design problem is how to embed assurance into a lifecycle path, even though the legal domains differ. Justification: the claimed transfer is about control-shape, not sector-specific legal obligations.
- [fact; source: https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/agency-authorization-path/] FedRAMP makes a Readiness Assessment Report optional but highly recommended, exposes FedRAMP Ready offerings in the Marketplace, and positions readiness work as a way to identify security gaps before full authorization effort begins.
- [fact; source: https://www.fedramp.gov/docs/authority/m-24-15/process/] FedRAMP also creates reuse incentives through the presumption of adequacy, which reduces duplicative security-assessment work once an authorization is actively maintained.
- [fact; source: https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://docs.aws.amazon.com/controltower/latest/userguide/account-factory.html] AWS Control Tower lets distributed teams provision new accounts quickly through configurable Account Factory templates while central administrators monitor compliance, controls, and nonconformant resources from one dashboard.
- [fact; source: https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] NHS England defines digital clinical safety assurance as compliance with required national standards, provides a step-by-step applicability tool, and requires named clinical-safety ownership plus documented hazard and safety-case artifacts.
- [inference; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/agency-authorization-path/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://docs.aws.amazon.com/controltower/latest/userguide/account-factory.html; https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] The governed path becomes the default path when it packages speed, templating, reusable evidence, and administrative clarity together; mandation remains necessary only as the backstop for high-risk cases and repeated off-rail behavior.
- [fact; source: https://docs.aws.amazon.com/prescriptive-guidance/latest/strategy-migration/aws-landing-zone.html] AWS defines a landing zone as an orchestration framework for a foundational environment that provides a baseline for multi-account architecture, identity and access management, governance, data security, network design, and logging.
- [fact; source: https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html] AWS Control Tower says Account Factory helps standardize new-account provisioning with pre-approved configurations and automates the application of controls and policies.
- [fact; source: https://www.servicenow.com/community/cmdb-articles/configuration-management-database-cmdb-welcome-guide/ta-p/2301750] ServiceNow's CMDB guidance describes onboarding as familiarization, business-outcome definition, implementation planning, and data acquisition into a single system of record.
- [inference; source: https://docs.aws.amazon.com/prescriptive-guidance/latest/strategy-migration/aws-landing-zone.html; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://docs.aws.amazon.com/controltower/latest/userguide/account-factory.html; https://www.servicenow.com/community/cmdb-articles/configuration-management-database-cmdb-welcome-guide/ta-p/2301750] A generative start is one that emits a runnable governed object with identity, baseline controls, policy bindings, and observability at creation time, whereas a registration-first start mainly records metadata and still depends on later manual governance work.
- [fact; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html] XACML separates the Policy Administration Point (PAP), which creates policy, from the Policy Decision Point (PDP), which evaluates policy, the Policy Enforcement Point (PEP), which enforces decisions, and the Policy Information Point (PIP), which supplies attributes.
- [fact; source: https://www.openpolicyagent.org/docs/philosophy; https://www.openpolicyagent.org/docs/latest/] OPA explicitly says policy should be decoupled from the software service it governs so policy can be updated without recompiling or redeploying the service.
- [fact; source: https://docs.cedarpolicy.com/] Cedar says policies are completely separate from application code and uses schema validation to check policy design when policies are created or updated.
- [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The AI RMF Map function requires intended purpose, deployment context, risk tolerance, system requirements, knowledge limits, human oversight, and targeted application scope to be documented.
- [inference; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] UELGF should treat declared purpose and scope as a machine-checkable registration manifest consumed by a policy decision function, while organizational policy remains versioned and approved on its own lifecycle outside any one entity.
- [fact; source: https://www.fedramp.gov/docs/authority/m-24-15/process/] FedRAMP says the presumption of adequacy applies only while an authorization is actively maintained through ongoing requirements such as continuous monitoring.
- [fact; source: https://www.iso.org/standard/27001] ISO/IEC 27001 defines an Information Security Management System as a system for establishing, implementing, maintaining, and continually improving information-security risk management.
- [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] AI RMF Govern 1.7 requires processes and procedures for decommissioning and phasing out Artificial Intelligence systems safely and without increasing risk.
- [fact; source: https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html] AWS Control Tower includes continuous oversight, drift handling, preventive controls, detective controls, and noncompliance visibility.
- [inference; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.iso.org/standard/27001; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html] A UELGF licence to operate should therefore be a continuously evaluated authorization state bound to current policy, posture, and evidence, and decommission should be treated as a lifecycle state with equal control rigor rather than as cleanup after the real work is finished.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-platform-operating-models.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html] Prior completed items say durable governance requires a shared central control plane and explicit change-control loops rather than project-by-project governance patches.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Prior completed identity research says durable governance also requires per-actor machine identity, bounded delegation, and attributable downstream action.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] The systems-capability-debt synthesis says persistent capability gaps create workaround demand and that agentic execution removes human-speed friction from that workaround estate.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-platform-operating-models.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] UELGF is best understood as the productized control surface that converts those prior governance requirements into one lifecycle grammar, one identity-bearing rail, and one evidence model that can suppress off-rail workaround demand by making the sanctioned path both safer and faster.
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://docs.cedarpolicy.com/; https://www.opengroup.org/archimate-forum/archimate-overview] Because existing standards define partial classes such as resources, building blocks, and entities inside their own domains, UELGF needs a broader abstraction based on consequence and lifecycle governability rather than on one technical layer.
- [inference; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] Because comparable high-assurance systems embed assurance into the production path and treat end-stage inspection as insufficient, a valid UELGF implementation cannot place compliance after creation as a separate approval overlay.
- [inference; source: https://docs.aws.amazon.com/prescriptive-guidance/latest/strategy-migration/aws-landing-zone.html; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.servicenow.com/community/cmdb-articles/configuration-management-database-cmdb-welcome-guide/ta-p/2301750] Because generative scaffolds emit controls at creation time while registration systems mostly record objects for later governance, "getting started" in UELGF must mean emitting a governed scaffold, not filing an intake form.
- [inference; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/] Because durable policy systems separate authoring, decision, enforcement, and attribute supply, UELGF must keep policy lifecycle external to any one entity and bind entities to approved policy state by reference rather than by embedded copies.
- [inference; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.iso.org/standard/27001] Because authorization, monitoring, and decommission are continuous lifecycle concerns in the surveyed standards, a licence to operate must be continuously maintained and retirement must be a first-class governed state.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Because systems capability debt creates workaround demand and agentic acceleration increases blast radius, governance and acceleration are inseparable in UELGF: the rail is the mechanism that makes fast delivery tolerable.
- [fact; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/] No contradiction appeared on policy independence: XACML, OPA, and Cedar all support explicit separation between policy logic and governed application logic, though they differ in packaging and execution model.
- [fact; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.iso.org/standard/27001; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] No contradiction appeared on continuous authorization and retirement: FedRAMP, ISO/IEC 27001, and AI RMF all frame governance as ongoing rather than one-time.
- [inference; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The "rail is compliance" principle remains an inference rather than a verbatim borrowed sentence, but the cross-domain evidence is directionally consistent and the sources all reject assurance-by-final-inspection as the primary control shape.
- [inference; source: https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/architecture/togaf7-doc/arch/p4/bbs/bbs_intro.htm] The enterprise-architecture comparison is lower confidence than the policy-engine comparison because accessible Open Group material was overview-level rather than full chapter text, but it is still sufficient to show that enterprise architecture languages classify multiple object kinds rather than one universal governed entity.
- [inference; source: https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://docs.aws.amazon.com/controltower/latest/userguide/account-factory.html; https://www.fedramp.gov/docs/authority/m-24-15/process/] Technical lens: the rail must combine provisioning, policy binding, evidence generation, drift detection, and re-authorization so that the entity carries governance state from first emission instead of accumulating detached controls over time.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] Regulatory lens: institutions prefer reusable evidence-bearing authorization paths and explicit documentation of purpose, oversight, and retirement, which means UELGF should be designed as a reusable compliance substrate rather than a case-by-case review ritual.
- [inference; source: https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/agency-authorization-path/; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] Economic lens: incentives matter because sanctioned paths win when they reduce local transaction cost, while off-rail demand rises when sanctioned paths are slower than workaround paths.
- [inference; source: https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Behavioural lens: persona adaptation should change language, defaults, and workflow ergonomics, but not the underlying control obligations, because otherwise each persona becomes a hidden policy variant.
(This section seeds the Findings below.)
Executive summary:
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/; https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The UELGF must be specified as a lifecycle control plane in which every governed entity can exist, change, operate, and retire only through a generative, policy-bound, continuously authorized rail; a framework that treats governance as a later overlay is inconsistent with the strongest comparable evidence.
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.cedarpolicy.com/; https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/architecture/togaf7-doc/arch/p4/bbs/bbs_intro.htm] No surveyed standard offers one ready-made universal entity term broad enough for UELGF, so the framework needs a novel definition based on consequence-bearing lifecycle governability rather than on one existing technical category.
- [inference; source: https://docs.aws.amazon.com/prescriptive-guidance/latest/strategy-migration/aws-landing-zone.html; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.servicenow.com/community/cmdb-articles/configuration-management-database-cmdb-welcome-guide/ta-p/2301750] The getting-started stage must be generative, because a registration-first intake only inventories an object while a generated scaffold emits the control surfaces that make the object governable from its first moment of existence.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.iso.org/standard/27001; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] The resulting UELGF principles are testable as numbered invariants around universal entity coverage, rail exclusivity, machine-checkable purpose, policy independence, continuous licence to operate, off-rail detectability, incentive design, product ownership, and retirement parity.
Key findings:
- [inference; confidence: high; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://docs.cedarpolicy.com/; https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/architecture/togaf7-doc/arch/p4/bbs/bbs_intro.htm] UELGF needs a novel universal entity definition, because the surveyed standards describe resources, actors, building blocks, and application entities inside narrower domain grammars rather than one lifecycle-governable object that spans assets, workflows, automations, data-bearing components, and external capabilities.
- [inference; confidence: high; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The governed golden rail must be defined as the compliance mechanism itself, because the strongest comparable high-assurance systems embed quality, safety, and authorization into the production path instead of relying on post-creation inspection to recover assurance later.
- [inference; confidence: high; source: https://docs.aws.amazon.com/prescriptive-guidance/latest/strategy-migration/aws-landing-zone.html; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://docs.aws.amazon.com/controltower/latest/userguide/account-factory.html; https://www.servicenow.com/community/cmdb-articles/configuration-management-database-cmdb-welcome-guide/ta-p/2301750] A compliant UELGF onboarding step must generate a complete governed scaffold, because baseline identity, control, logging, and policy surfaces must exist at creation time, whereas registry-style intake mainly records objects for later governance work.
- [inference; confidence: high; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://docs.cedarpolicy.com/; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html] Declared purpose and scope should be represented as a machine-checkable manifest that states intended use, deployment context, risk tolerance, human oversight expectations, and targeted application boundary before the entity receives a live licence to operate.
- [inference; confidence: high; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/] Policy lifecycle must remain independent from entity lifecycle, with distinct authoring, decision, enforcement, and attribute-supply components, because embedding policy inside each entity would make governance drift with implementation detail and release timing.
- [inference; confidence: high; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.iso.org/standard/27001; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html] The licence to operate should be a continuously maintained authorization state tied to current policy, posture, evidence, and drift status, not a one-time approval artifact issued at creation or first deployment.
- [inference; confidence: medium; source: https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/agency-authorization-path/; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] UELGF adoption should be incentive-first and mandate-second, because reusable evidence, self-service templates, and standardized support make the sanctioned path locally cheaper, while explicit mandation remains necessary only for high-risk cases and repeated bypass.
- [inference; confidence: high; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-platform-operating-models.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] UELGF must be owned as a long-lived product capability with equal rigor for retirement, because ongoing governance, evidence loops, and workaround suppression are enterprise control-plane functions rather than finite project deliverables.
Evidence map:
Assumptions:
- [assumption; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The control-shape lessons from FDA, FAA, and FedRAMP are transferable to UELGF design because the shared question is how to embed assurance into an operating path, not how to import sector-specific legal text into software governance.
Analysis:
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://docs.cedarpolicy.com/] Formal definition: entity. A UELGF entity is a bounded socio-technical object or workflow that can create, store, transform, expose, move, delegate, or retire business capability, data, permissions, obligations, or operational risk, and is therefore required to carry lifecycle-governable identity, purpose, policy bindings, evidence, and ownership.
- [inference; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html] Formal definition: governed golden rail. The governed golden rail is the only sanctioned lifecycle path that creates, configures, promotes, operates, monitors, and retires entities while attaching mandatory identity, policy, evidence, and enforcement surfaces at each stage such that following the path is sufficient for compliance with the approved policy profile.
- [inference; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.iso.org/standard/27001; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Formal definition: licence to operate. The licence to operate is the current authorization state of an entity, granted only when its declared purpose, control profile, identity posture, evidence completeness, and runtime status satisfy approved policy, and revoked or constrained when those conditions no longer hold.
- [inference; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/] Formal definition: Policy Decision Point. In UELGF, the Policy Decision Point is the authoritative decision function that evaluates a declared request against approved policy, contextual attributes, and current state and returns the binding allow, deny, constrain, or retire decision that enforcement layers must execute.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-platform-operating-models.html] Proposed UELGF invariants: 1. Every consequential capability instance must be represented as one registered UELGF entity before it can enter any live state. 2. No entity may enter operation except through the governed golden rail. 3. Rail entry must emit identity, policy binding, evidence hooks, ownership, and retirement metadata at creation time. 4. Persona-specific interfaces may vary, but the required controls, evidence, and decision points must remain invariant beneath them. 5. Each entity must declare a machine-checkable purpose and scope manifest before creation completes. 6. Organizational policy must version and approve independently from entity release cycles. 7. The licence to operate must be continuously re-evaluated against current policy and state. 8. Off-rail entities or drifted entities must be detectable, reportable, and remediable. 9. The low-friction rail path must remain faster and clearer than the exception path for low- and medium-risk work. 10. High-risk work and repeated bypass must trigger mandatory control escalation. 11. Retirement must require explicit evidence that runtime activity, credentials, dependencies, and records have converged to the approved end state. 12. The rail, policy layer, and evidence layer must have named long-lived product ownership and ongoing investment.
Risks, gaps, uncertainties:
- [fact; source: https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/togaf] Open Group overview material was accessible, but full online specification chapters were not, so the enterprise-architecture comparison is lower confidence than the security-policy comparison.
- [fact; source: https://www.iso.org/standard/27001] ISO/IEC 27001 was accessible only through the public summary page, so the continual-improvement support is strong at principle level but not at clause-detail level.
- [inference; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The "rail is compliance" principle is robust as a control-shape inference, but no single source states the UELGF phrasing verbatim because the synthesis spans multiple domains.
- [inference; source: https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/agency-authorization-path/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] The evidence is stronger on what makes the governed path attractive than on the exact threshold where organizations must switch from incentives to full mandation, so implementation policy will still need local calibration.
Open questions:
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.cedarpolicy.com/; https://www.opengroup.org/archimate-forum/archimate-overview] Should UELGF later split the universal entity definition into durable asset classes and transient workflow classes for operational convenience, while preserving one common lifecycle grammar?
- [inference; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] What is the minimum evidence tuple that should travel with a UELGF licence to operate so re-authorization is automatic rather than manually assembled?
- [inference; source: https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] Which measurable service-level targets would prove that the rail remains genuinely easier than off-rail creation for each builder persona?
- [fact; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-27-uelgf-foundational-definitions-principles.md] Review outcome: all visible claim-bearing lines in the Research Skill Output are labeled as fact, inference, or assumption, and the external claims are bound to explicit web sources.
- [fact; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-27-uelgf-foundational-definitions-principles.md] Review outcome: abbreviation first-use checks were applied for UELGF, Zero Trust Architecture (ZTA), Extensible Access Control Markup Language (XACML), Open Policy Agent (OPA), Federal Risk and Authorization Management Program (FedRAMP), Information Security Management System (ISMS), Configuration Management Database (CMDB), Food and Drug Administration (FDA), Federal Aviation Administration (FAA), and Safety Management System (SMS).
- [fact; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-27-uelgf-foundational-definitions-principles.md] Review outcome: the synthesis and Findings sections use the same eight key findings, the same confidence levels, and the same source structure.
- [fact; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-27-uelgf-foundational-definitions-principles.md] Review outcome: no em dashes remain in the rewritten content.
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/; https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The UELGF must be a lifecycle control plane in which every governed entity can exist only through a generative, policy-bound, continuously authorized rail, because the strongest comparable standards all embed assurance into the operating path rather than adding it after creation.
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.cedarpolicy.com/; https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/architecture/togaf7-doc/arch/p4/bbs/bbs_intro.htm] No surveyed standard already provides a sufficiently broad universal entity term for UELGF, so the framework needs its own definition based on consequence-bearing lifecycle governability instead of borrowing one narrower category unchanged.
- [inference; source: https://docs.aws.amazon.com/prescriptive-guidance/latest/strategy-migration/aws-landing-zone.html; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.servicenow.com/community/cmdb-articles/configuration-management-database-cmdb-welcome-guide/ta-p/2301750] The getting-started stage must be generative rather than administrative, because governance cannot be guaranteed when identity, policy, evidence, and monitoring surfaces appear only after an object has already been created.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.iso.org/standard/27001; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] The resulting specification is best expressed as explicit invariants around universal entity coverage, policy independence, machine-checkable purpose, continuous licence to operate, off-rail detectability, incentive design, product ownership, and retirement parity.
- [inference; confidence: high; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://docs.cedarpolicy.com/; https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/architecture/togaf7-doc/arch/p4/bbs/bbs_intro.htm] UELGF needs a novel universal entity definition, because the surveyed standards describe resources, actors, building blocks, and application entities inside narrower domain grammars rather than one lifecycle-governable object that spans assets, workflows, automations, data-bearing components, and external capabilities.
- [inference; confidence: high; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The governed golden rail must be defined as the compliance mechanism itself, because the strongest comparable high-assurance systems embed quality, safety, and authorization into the production path instead of relying on post-creation inspection to recover assurance later.
- [inference; confidence: high; source: https://docs.aws.amazon.com/prescriptive-guidance/latest/strategy-migration/aws-landing-zone.html; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://docs.aws.amazon.com/controltower/latest/userguide/account-factory.html; https://www.servicenow.com/community/cmdb-articles/configuration-management-database-cmdb-welcome-guide/ta-p/2301750] A compliant UELGF onboarding step must generate a complete governed scaffold, because baseline identity, control, logging, and policy surfaces must exist at creation time, whereas registry-style intake mainly records objects for later governance work.
- [inference; confidence: high; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://docs.cedarpolicy.com/; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html] Declared purpose and scope should be represented as a machine-checkable manifest that states intended use, deployment context, risk tolerance, human oversight expectations, and targeted application boundary before the entity receives a live licence to operate.
- [inference; confidence: high; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/] Policy lifecycle must remain independent from entity lifecycle, with distinct authoring, decision, enforcement, and attribute-supply components, because embedding policy inside each entity would make governance drift with implementation detail and release timing.
- [inference; confidence: high; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.iso.org/standard/27001; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html] The licence to operate should be a continuously maintained authorization state tied to current policy, posture, evidence, and drift status, not a one-time approval artifact issued at creation or first deployment.
- [inference; confidence: medium; source: https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/agency-authorization-path/; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] UELGF adoption should be incentive-first and mandate-second, because reusable evidence, self-service templates, and standardized support make the sanctioned path locally cheaper, while explicit mandation remains necessary only for high-risk cases and repeated bypass.
- [inference; confidence: medium; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-platform-operating-models.html; https://davidamitchell.github.io/Research/research/2026-04-22-ai-governance-assurance-change-control-verification.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] UELGF must be owned as a long-lived product capability with equal rigor for retirement, because ongoing governance, evidence loops, and workaround suppression are enterprise control-plane functions rather than finite project deliverables.
- [assumption; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The control-shape lessons from FDA, FAA, and FedRAMP are transferable to UELGF design because the relevant comparison is whether assurance is embedded in the operating path, not whether the sector-specific legal obligations are identical.
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://docs.cedarpolicy.com/] Entity definition: A UELGF entity is a bounded socio-technical object or workflow that can create, store, transform, expose, move, delegate, or retire business capability, data, permissions, obligations, or operational risk, and therefore must carry governable identity, purpose, policy bindings, evidence, and ownership throughout its lifecycle.
- [inference; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html] Governed golden rail definition: The governed golden rail is the exclusive lifecycle path that creates, configures, promotes, operates, monitors, and retires entities while attaching mandatory identity, policy, evidence, and enforcement surfaces at each stage such that following the path is sufficient for compliance with the approved profile.
- [inference; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.iso.org/standard/27001; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Licence-to-operate definition: The licence to operate is the current authorization state of an entity, granted only while its declared purpose, policy profile, evidence completeness, identity posture, and runtime condition continue to satisfy approved policy.
- [inference; source: https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://www.openpolicyagent.org/docs/philosophy; https://docs.cedarpolicy.com/] Policy Decision Point definition: The UELGF Policy Decision Point is the authoritative decision function that evaluates a request against approved policy, contextual attributes, and current state and returns the binding allow, deny, constrain, or retire decision that enforcement layers must execute.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-platform-operating-models.html] Numbered invariants: 1. Every consequential capability instance must be represented as one registered UELGF entity before any live use. 2. No entity may operate outside the governed golden rail. 3. Rail entry must emit identity, policy binding, evidence hooks, ownership, and retirement metadata at creation time. 4. Persona-specific interfaces may vary, but control obligations and evidence requirements must not. 5. Each entity must declare a machine-checkable purpose and scope manifest before creation completes. 6. Organizational policy must version and approve independently from entity release. 7. The licence to operate must be continuously re-evaluated against current policy and runtime state. 8. Off-rail entities and drifted entities must be detectable, reportable, and remediable. 9. The rail path must remain faster and clearer than the exception path for low- and medium-risk work. 10. High-risk work and repeated bypass must trigger mandatory escalation. 11. Retirement must prove convergence of runtime inactivity, credential withdrawal, dependency cleanup, and retained evidence. 12. The rail, policy layer, and evidence layer must have named product ownership and ongoing investment.
- [fact; source: https://www.opengroup.org/archimate-forum/archimate-overview; https://www.opengroup.org/togaf] Open Group overview material was accessible, but full online specification chapters were not, so the enterprise-architecture comparison is lower confidence than the policy-engine comparison.
- [fact; source: https://www.iso.org/standard/27001] ISO/IEC 27001 support is based on the public summary page rather than full clause text, so its use here is principle-level rather than control-clause-level.
- [inference; source: https://www.fda.gov/media/71023/download; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf; https://www.fedramp.gov/docs/authority/m-24-15/process/] The "rail is compliance" conclusion is well supported as a structural inference, but it remains a synthesis across multiple domains rather than a phrase borrowed directly from one standard.
- [inference; source: https://www.fedramp.gov/docs/rev5/playbook/csp/authorization/agency-authorization-path/; https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] The evidence is better at showing what makes approved paths attractive than at proving the exact boundary where incentives stop working and hard mandation must start.
- [inference; source: https://csrc.nist.gov/pubs/sp/800/207/final; https://docs.cedarpolicy.com/; https://www.opengroup.org/archimate-forum/archimate-overview] Should later UELGF design split the universal entity model into durable asset classes and transient workflow classes while preserving one common lifecycle grammar?
- [inference; source: https://www.fedramp.gov/docs/authority/m-24-15/process/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] What minimum evidence tuple should travel with a licence to operate so re-authorization and suspension are automatic rather than manually assembled?
- [inference; source: https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html; https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/] Which measurable service targets would demonstrate that the governed golden rail remains genuinely easier than off-rail creation for each builder persona?
- Type: knowledge
- Description: Formal UELGF definitions for entity, governed golden rail, licence to operate, and Policy Decision Point, plus twelve testable invariants for evaluating whether an implementation truly embeds governance into the delivery rail.
- Links:
Navigation
By Tag
bureaucracy
change-management
coase
constraint-analysis
control-model
decision-rights
delegation
- Q4: Decision rights that should move closer to execution
- Q5: Control model for the best throughput-risk trade-off
delivery-risk
- Operating model synthesis for split-authority delivery systems
- Q6: Leading indicators of instability in split-authority flow systems
demand-segmentation
enterprise
exception-handling
execution
flow
flow-design
flow-metrics
governance
- Operating model synthesis for split-authority delivery systems
- Q1: Dominant flow constraint in split-authority delivery systems
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q4: Decision rights that should move closer to execution
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
governance-patterns
incentives
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
instability
institutional-economics
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
leading-indicators
operating-model
organisation
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
organisational-design
queue-design
queueing
regulated-enterprise
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
routing
throughput
throughput-risk
transaction-costs
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
triage
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q3: Routing design that isolates exceptions from routine flow
williamson