Skip to content

2026 04 27 uelgf synthesis complete framework

github-actions[bot] edited this page Apr 27, 2026 · 1 revision

Universal Entity Lifecycle Governance Framework (UELGF): complete framework synthesis, formal specification suitable for adoption as an organisational standard in a regulated financial institution and presentation to a board risk committee

Research Question

What is the complete specification of the Universal Entity Lifecycle Governance Framework (UELGF), integrating foundational definitions and principles, entity taxonomy and Confidentiality, Integrity, and Availability (CIA) classification, governed golden rails, policy architecture, decommission lifecycle, and runtime feedback loop, that is suitable for formal adoption as an organisational standard by a regulated financial institution, presentation to a board risk committee as the governance response to agentic Artificial Intelligence (AI) and citizen development risks, and use as the engineering specification against which governance tooling, platform engineering capability, and policy-as-code infrastructure are designed and built?

Scope

In scope:

  • Synthesis of all six companion research items into a single coherent framework document
  • Executive summary: the problem the framework solves, the two inseparable concerns (governance and acceleration), and the central claim that the rail IS the compliance
  • Formal scope statement: what constitutes an entity, confirmation that the framework applies to all entity types and all builder personas without exception
  • Entity taxonomy with Confidentiality, Integrity, and Availability (CIA) classification system including governance profile matrix
  • Governed golden rail specification including scaffold generation requirement, builder persona spectrum, citizen development rail requirement, and deviation handling
  • Policy architecture including 8-layer organisational context model, policy independence guarantee, scope boundary mechanism, and kill switch
  • Decommission lifecycle including ghost entity detection, dependency elimination trigger, and archive record specification
  • Runtime feedback loop including signal taxonomy, automated response taxonomy, feedback closure to rail system, and feedback closure to systems capability debt programme
  • Dependency ordering of foundational prerequisites: the framework requires a coherent information architecture, an enforced access control model, and a classified data estate, and deploying the framework over an ungoverned foundation does not substitute for that foundation
  • Implementation sequencing recommendation: minimum viable governance state and honest assessment of what the framework cannot do until foundational prerequisites are satisfied
  • Statement of explicit limitations: the framework governs entities that enter the rail; it does not automatically govern entities built entirely outside organisational visibility; enforcement of rail entry as the mandatory path requires executive mandate the framework itself cannot substitute for
  • Consistency verification: all component specifications are internally consistent, non-contradictory, and cross-referenced correctly

Out of scope:

  • Original research on any individual component, this is a synthesis item that draws exclusively on the findings of the six companion items
  • Implementation design or architecture for specific tooling platforms
  • Jurisdiction-specific legal analysis beyond what appears in the companion items

Constraints:

  • This item must not be started until all six companion items are completed:
    • 2026-04-27-uelgf-foundational-definitions-principles
    • 2026-04-27-uelgf-entity-taxonomy-cia-classification
    • 2026-04-27-uelgf-governed-golden-rails
    • 2026-04-27-uelgf-policy-architecture-8-layer-context
    • 2026-04-27-uelgf-decommission-lifecycle
    • 2026-04-27-uelgf-runtime-feedback-loop
  • The document must be written at two registers simultaneously: precise enough to serve as an engineering specification, and accessible enough for a board risk committee to evaluate it as a governance response. Where these conflict, precision takes precedence and a plain-language summary is provided alongside the precise definition.
  • The document must not claim to solve problems it does not solve, the statement of explicit limitations must be honest about what requires executive mandate, what requires foundational prerequisites, and what the framework detects but cannot prevent.

Context

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] This synthesis item produces the formal framework document that the six companion UELGF items were specifying by parts, and it is intended to be adoptable as an organisational standard and explainable to a board risk committee.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-citizen-development-empirical-evidence.html] Prior completed research shows that organisations accumulate systems capability debt and that unmet delivery need can create demand for ungoverned workaround systems and citizen-developed local capability.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-26-access-control-amplification-agentic-operations.html] Prior completed research also shows that agentic AI removes implicit human-speed rate limits and amplifies the blast radius of over-broad permissions and workaround estates once automation can act repeatedly and continuously.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html] The foundational companion item concludes that no single surveyed framework governs all entity types under one consistent policy architecture across a complete lifecycle that includes creation, operation, suspension, and decommission.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] The synthesis therefore has to show both how UELGF fills that gap and where it cannot substitute for foundational prerequisites, so that sequencing guidance remains honest for organisations at different stages of governance maturity.

Prior completed research providing foundational context:

Approach

  1. Consistency verification: Before synthesis, verify that the six companion items are internally consistent: that definitions used in one item are compatible with definitions used in others, that the entity taxonomy used by the rail specifications matches the taxonomy produced by the classification item, that the policy architecture referenced by the rail specifications is consistent with the policy architecture item, and so on. Document any inconsistencies found and resolve them with explicit reasoning.
  2. Executive summary drafting: Produce a 500-word executive summary covering: the problem (capability debt, agentic AI, absence of a unified framework), the two inseparable concerns (governance and acceleration), the central claim (rail IS compliance, getting started is generative), and the framework's response to the board risk committee's governance question.
  3. Framework document assembly: Assemble the full framework document from the six companion items in the specified structure. Where companion items contain redundancy or repetition, synthesise into coherent non-redundant text. Where companion items reveal gaps when read together, identify the gap explicitly and assess whether it requires additional research.
  4. Dependency ordering and implementation sequencing: Synthesise the dependency ordering findings from the companion items and the completed dependency ordering research item into a concrete implementation sequencing recommendation. The recommendation must be honest about what the UELGF cannot provide until foundational prerequisites (coherent information architecture, enforced access control, classified data estate) are satisfied.
  5. Statement of limitations: Produce the explicit limitations statement. This must be technically accurate: the framework governs entities that enter the rail; it cannot govern entities built entirely outside organisational visibility; enforcement of rail entry requires executive mandate; the kill switch requires that credentials were issued through the managed credential system to be revocable; ghost entity detection has a detection lag. Each limitation must state what the limitation implies for residual risk.
  6. Board presentation layer: For each major section of the framework, produce a plain-language companion paragraph suitable for a board risk committee member without technical background. This is the secondary register of the document, it does not replace the precise specification, it sits alongside it.

Sources

(This synthesis item is grounded in completed companion items and adjacent completed prerequisite work. Every listed source includes a public URL.)


Research Skill Output

(This section records the research-skill investigation. Section 6 seeds the Findings below.)

§0 Initialise

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] The question is whether the six companion UELGF items compose into one formal lifecycle standard that a regulated financial institution can adopt as an engineering specification and defend to a board risk committee.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] The synthesis must also state the dependency order and explicit limitations honestly, because the adjacent prerequisite and regulatory items conclude that agent deployment over weak foundations is a current or foreseeable control failure rather than a neutral maturity gap.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-deployment-pipeline-citizen-development-governed-gate.html] Prior-work cross-reference was completed against adjacent completed items on systems capability debt, identity and access, permission-safe RAG, policy coherence, and deployment gating before the synthesis began.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] The required output is one knowledge item whose Research Skill Output records the investigation verbatim and whose Findings restate the same synthesis in board-readable and engineering-usable form.

§1 Question Decomposition

  • A. Framework validity
    • A1. Do the six companion items define one internally consistent control model rather than six loosely related ideas?
    • A2. Does the resulting model apply to all consequential entity types and all builder personas?
  • B. Problem statement and intent
    • B1. What problem does the framework solve that prior governance approaches leave unresolved?
    • B2. Why are governance and acceleration inseparable in this design?
  • C. Core lifecycle specification
    • C1. What is the formal definition of a governed entity?
    • C2. What taxonomy and CIA assignment rules define governance intensity?
    • C3. What exactly must the governed golden rail emit and enforce at creation, promotion, operation, and retirement?
  • D. Policy and enforcement architecture
    • D1. How do Policy Administration Point (PAP), Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP) interact?
    • D2. How does the 8-layer context model constrain entity scope without letting local scope weaken enterprise policy?
    • D3. What typed boundary, freshness, and kill-switch rules are required?
  • E. End-of-life and runtime adaptation
    • E1. What makes decommission a first-class governed state?
    • E2. What signals, response classes, and feedback loops must runtime monitoring produce?
  • F. Preconditions, sequencing, and limitations
    • F1. Which foundational conditions must exist before the framework can work as claimed?
    • F2. What minimum viable governance state can use the framework partially but honestly?
    • F3. What residual risks remain even after adoption?

§2 Investigation

A. Companion-item consistency check

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html] The foundational item defines UELGF as a lifecycle control plane in which every consequential entity must enter through a generative, policy-bound, continuously authorized rail and must remain off-rail detectable and retirement-capable.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html] The taxonomy item defines one canonical entity type, one CIA tier, highest-triggered-axis scoring, non-discretionary floors for high-consequence surfaces, and scaffold-time invariants that materially alter risk and enforcement topology.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] The rail item defines the rail as universal scaffold + CIA tier baseline + entity modifier + persona surface + platform adapter, with citizen-development rails treated as platform archetypes rather than bespoke exceptions.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html] The policy item defines one canonical PAP, stateless PDPs, typed scope objects, ordered 8-layer precedence, fail-closed freshness, and deny-first kill-switch suspension.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] The decommission item defines retirement as a converged state across registry, runtime, credentials, dependency cleanup, and archive evidence, and it defines ghost-entity control as registry-to-runtime divergence detection.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] The runtime-feedback item defines typed governance signals, five routable response classes, recurrence-driven re-evaluation, same-rail learning, and cross-rail debt-programme escalation.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] No material contradiction appears across the six items: the taxonomy feeds the rail, the rail depends on the policy architecture, the policy architecture governs runtime and suspension, and decommission and feedback close the lifecycle rather than competing with it.

B. Problem statement, governance, and acceleration

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-citizen-development-empirical-evidence.html] Adjacent completed research concludes that systems capability debt creates demand for workaround systems and that low-code or citizen-development adoption is often multi-causal but strongly shaped by unmet delivery need and central-estate friction.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html; https://davidamitchell.github.io/Research/research/2026-04-26-access-control-amplification-agentic-operations.html] Adjacent completed research also concludes that write-capable agentic deployment into weak access control, incomplete asset classification, or unresolved resilience gaps is already a current or foreseeable control failure in regulated settings.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] UELGF therefore cannot be only a governance overlay, because a slow sanctioned path leaves workaround demand intact; the framework has to make the governed path faster and clearer than bypass if it is meant to reduce off-rail creation rather than merely document it.

C. Formal scope statement and universal entity definition

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html] The framework should govern every consequential socio-technical object or workflow that can create, store, transform, expose, move, delegate, or retire business capability, data, permissions, obligations, or operational risk, regardless of whether it was built in code, low-code tooling, Software as a Service (SaaS), workflow tooling, or model-led agent tooling.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] The framework should apply to all builder personas, including platform engineers, software engineers, business operators, and citizen developers, because persona-specific user experience can vary without changing the underlying identity, evidence, policy, and promotion obligations.

D. Entity taxonomy and CIA synthesis

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html] The canonical taxonomy distinguishes policy or content artefacts, data products, frontend applications, integration components, software services, SaaS products, decision workflows, and four Artificial Intelligence (AI) agent autonomy classes, with the highest-action surface winning when a nominally passive object also executes consequential actions.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://handbook.apra.gov.au/standard/cps-234; https://www.pcisecuritystandards.org/standards/pci-dss/] The CIA model keeps confidentiality, integrity, and availability separate, sets overall tier to the highest triggered axis, and attaches automatic floors to consequence-bearing surfaces such as privileged policy mutation, payment execution, critical system-of-record availability, and higher-autonomy agents.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-pap-dynamic-policy-profiling-proportionality.html] Governance intensity should therefore be computed compositionally as tier baselines plus entity modifiers rather than as one flat bespoke matrix, because one shared grammar is required if policy-as-code and rail templates are to remain machine-checkable and maintainable.

E. Governed golden rail synthesis

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] The rail specification requires a universal scaffold that emits an entity identifier, registry record, machine-checkable manifest, governed execution identity, source container, promotion path, policy profile, observability pack, ownership record, decommission metadata, and exception route before builder-authored logic goes live.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://learn.microsoft.com/en-us/power-platform/admin/default-environment-routing; https://docs.appian.com/suite/help/26.3/Deploy_to_Target_Environments.html] The citizen-development portion of the rail is not optional or separate from the main framework, because the completed rail item identifies at least two governed archetypes, managed-maker environment rail and package-promotion rail, that keep non-engineers inside the same promotion and evidence substrate.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] The rail is compliance in UELGF because following the rail attaches the mandatory identity, policy, evidence, promotion, monitoring, and retirement surfaces that define the approved operating envelope, while bypassing the rail means those surfaces are absent or unverifiable.

F. Policy architecture synthesis

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html] The policy architecture requires one canonical PAP that authors, signs, versions, and publishes policy, stateless PDPs that evaluate current policy plus request context, PEPs that intercept and enforce, and a PIP that supplies entity registration, lifecycle, identity, and anomaly attributes.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html] The 8-layer organisational context model is an ordered constraint stack in which regulation, risk appetite, values, strategy, standards, patterns, procedures, and per-entity scope are typed separately and lower layers may specialize but never weaken higher layers.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html] The machine-checkable boundary is a typed scope object rather than a coarse string scope, and scope violations must remain distinct from ordinary policy denials because they indicate a broken registration envelope or misuse condition rather than a valid in-scope refusal.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html] The kill switch is deny-first and multi-channel: suspend licence state, revoke or stop renewing credentials, invalidate live sessions where possible, drain or terminate queued work, and notify dependencies, with tighter latency for narrower blast radius and slower fanout for broader class or type suspension.
  • [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Kill-switch effectiveness assumes consequential entities were issued through managed identity and credential paths that the control plane can revoke or refuse to renew. Justification: the companion items prove the control shape, but estate-specific revocability still depends on implementation discipline.

G. Decommission and runtime feedback synthesis

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] Decommission is a gated lifecycle state reached only when no new work can be admitted, in-flight work is drained or cancelled safely, credentials no longer authorize action, dependencies have been updated or warned, and an archive record has been sealed.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] Ghost-entity detection depends on registry-to-runtime reconciliation across scaffold events, promotion events, runtime inventory, drift state, credential activity, and dependency state, because each surface reveals a different class of unregistered, orphaned, lapsed, or tier-drifted entity.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] The runtime feedback loop normalizes observations into typed governance signals and routes them through five outcomes, observe-only, notify and case, soft suspension, hard suspension, and decommission-candidate, using different acute, anomaly, and recurrence windows rather than one threshold.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] Same-rail recurrence should create rail backlog or new-rail work, while cross-rail recurrence should create a machine-readable demand signal for the systems-capability-debt programme, because the framework needs a learning loop for sanctioned paths and a separate investment signal for unmet estate capability.

H. Dependency ordering, implementation sequencing, and explicit limitations

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html] The best-supported dependency chain is: coherent delegated-domain policy, representable information architecture and access boundaries, scoped machine identity and delegation, permission-safe RAG or tool access where relevant, and then deployment-gate enforcement over those artefacts.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html] The synthesis therefore cannot claim that UELGF substitutes for coherent information architecture, enforced access control, or classified data, because the adjacent prerequisite work concludes those are technical and regulatory preconditions for safe agentic deployment rather than optional enhancements.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] A minimum viable governance state can still use UELGF partially if it has one coherent delegated-domain policy source, one entity inventory, separate machine identities for consequential automation, one governed promotion gate, baseline telemetry, kill-switch authority over managed credentials, and a decommission workflow, but such an organisation should present the framework as bounded containment and evidence generation rather than as full-spectrum governance.
  • [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Mandatory rail entry for consequential entities requires board or executive mandate outside the framework itself. Justification: incentive-first design can lower bypass demand, but the companion items do not prove that incentives alone eliminate all off-rail behavior for high-consequence work.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] The framework does not automatically govern entities built wholly outside organisational visibility, and ghost detection therefore leaves residual risk equal to discovery lag until runtime, credential, or inventory evidence surfaces the entity.

§3 Reasoning

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] The central synthesis move is to treat the rail, not a checklist around the rail, as the unit of compliance, because the foundational and rail items agree that generative control surfaces are stronger than post-creation governance overlays.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html] The taxonomy and policy items fit naturally because one answers what the entity is and how consequential it is, while the other answers which layers of policy bind it and how decisions are evaluated.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] Decommission and runtime feedback are not appendices to creation-time governance, because the lifecycle remains governable only if state can be constrained, suspended, re-evaluated, retired, and learned from after the entity first goes live.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Dependency ordering changes the honesty condition of the synthesis: the framework can define a complete target architecture now, but it cannot honestly claim safe full deployment where lower-layer prerequisites remain absent.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] Governance and acceleration remain inseparable because the framework is meant to reduce workaround demand caused by systems capability debt, not simply to document the consequences after off-rail demand has already moved elsewhere.

§4 Consistency Check

  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] No contradiction appears between taxonomy and rail design: the rail item explicitly depends on CIA tier baselines and entity modifiers rather than proposing a competing classification grammar.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html] No contradiction appears between rail design and policy architecture: the rail emits the manifest and bindings that the policy architecture later evaluates, and neither item permits local rail logic to override canonical policy.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] No contradiction appears between kill-switch and feedback logic: acute high-severity feedback reuses the deny-first suspension model instead of inventing a second stop pathway.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] No contradiction appears between decommission and runtime feedback: a repeated severe breach can become a decommission-candidate, and decommission remains the governed exit path rather than a parallel lifecycle.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html] The only meaningful tension is that the framework is complete as a target-state specification even when prerequisites are incomplete in the current estate, so the final synthesis must separate target-state completeness from present-state readiness explicitly.

§5 Depth and Breadth Expansion

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html] Technical lens: the framework is strongest when treated as one control plane with one lifecycle grammar, because separate rails, separate policy stacks, or separate retirement paths would recreate the fragmentation the framework is meant to remove.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] Regulatory lens: a board risk committee can evaluate the framework as a control response only if it sees both preventive design, rail entry, scope, approvals, identities, and detective and corrective design, monitoring, suspension, retirement, and investment feedback.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] Economic lens: the framework is economically justified only if using the rail is cheaper in local transaction cost than bypass for low- and medium-consequence work, because otherwise the institution will fund a governance product that still leaves workaround demand untouched.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html] Behavioral lens: builder self-classification and self-exemption remain structurally biased downward, so independent floors, hard gates, and recurrence-driven review are not bureaucracy for its own sake, they are controls against local incentive distortion.

§6 Synthesis

(This section seeds the Findings below.)

Executive summary:

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html] UELGF is defensible as one lifecycle standard only if every consequential entity, regardless of technology or builder persona, enters through a generative governed rail backed by independent policy, typed scope, continuous authorization, decommission control, and runtime feedback, and only if the institution states clearly that these controls do not substitute for coherent information architecture, access control, and classified data foundations.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-citizen-development-empirical-evidence.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] The framework solves two inseparable problems at once: it creates one governable lifecycle grammar for heterogeneous entities, and it makes the sanctioned path faster and clearer than bypass so that one major driver of off-rail workaround demand is reduced, even though citizen-development and workaround adoption remain multi-causal.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] The complete specification therefore combines one universal entity definition, one canonical taxonomy and CIA model, one compositional rail formula, one policy architecture, one retirement standard, and one learning loop that feeds both rail evolution and systems-capability-debt remediation.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] Its explicit limitations are equally important: the framework governs entities that enter the rail, not entities that remain wholly invisible; mandatory rail entry still requires executive authority; kill-switch strength depends on revocable managed credentials; and ghost-entity control always leaves residual risk equal to detection lag.

Key findings:

  1. [inference; confidence: medium; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] A formal UELGF standard should apply to every consequential entity and every builder persona under one lifecycle grammar, because the companion items only remain internally coherent when entity coverage, rail obligations, and control evidence are universal rather than selectively optional.
  2. [inference; confidence: high; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf] The governed golden rail should be specified as the compliance mechanism itself and should generate a complete governed scaffold before builder-authored logic goes live, because both the UELGF companion items and external high-assurance analogues reject assurance-by-overlay as the primary control shape.
  3. [inference; confidence: high; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://handbook.apra.gov.au/standard/cps-234; https://www.pcisecuritystandards.org/standards/pci-dss/; https://www.faa.gov/documentLibrary/media/Order/FAA_Order_8110.49A.pdf] Governance intensity should be assigned through one canonical entity taxonomy plus highest-triggered-axis CIA scoring with mandatory floors for high-consequence surfaces, because regulated and high-assurance analogues do not allow builders to self-downgrade materially consequential action surfaces.
  4. [inference; confidence: high; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://docs.cedarpolicy.com/policies/validation.html; https://csrc.nist.gov/pubs/sp/800/207/final] The policy architecture should keep the Policy Administration Point (PAP), Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP) separate, encode policy as an ordered 8-layer constraint stack, and evaluate a schema-validated scope object that names allowed actions, resources, data domains, connectors, side effects, approval requirements, and limits, because policy independence and deterministic scope checking collapse if local enforcement surfaces can carry their own unsynchronized policy.
  5. [inference; confidence: high; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://docs.aws.amazon.com/IAM/latest/UserGuide/id-credentials-access-keys-update.html; https://docs.aws.amazon.com/config/latest/developerguide/WhatIsConfig.html] Decommission and runtime feedback must be first-class lifecycle phases, because safe retirement depends on converged registry, runtime, credential, dependency, and archive state, while safe operation depends on typed runtime signals that can suspend, re-evaluate, retire, and feed both rail backlog and systems-capability-debt remediation.
  6. [inference; confidence: medium; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] The framework depends on foundational prerequisites in a strict order, coherent delegated-domain policy, representable information architecture and access boundaries, scoped machine identity, and only then permission-safe retrieval or tool access plus deployment-gate enforcement, because upper-layer controls cannot validate or constrain what lower layers cannot represent.
  7. [inference; confidence: medium; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] A realistic minimum viable governance state can still use UELGF as bounded containment and evidence generation if it has coherent delegated-domain policy, entity inventory, separate machine identities for consequential automation, a governed promotion gate, baseline telemetry, and revocable managed credentials, but it should not claim full safety until broader foundational prerequisites are satisfied.
  8. [inference; confidence: medium; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] The standard must carry an explicit limitations clause stating that the framework cannot govern entities that never enter organisational visibility, cannot replace executive mandate for mandatory rail entry, cannot guarantee immediate stop if credentials were never managed through revocable channels, and cannot remove residual risk during ghost-entity detection lag.

Evidence map:

Claim Source Confidence Notes
[inference] UELGF should apply one lifecycle grammar to all consequential entities and all builder personas. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html medium Cross-item internal consistency.
[inference] The rail is the compliance mechanism and must emit a complete governed scaffold before live logic exists. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html ; https://www.fedramp.gov/docs/authority/m-24-15/process/ ; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf high Companion synthesis plus external analogue support.
[inference] Taxonomy plus highest-triggered-axis CIA scoring with mandatory floors is the right governance-intensity model. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html ; https://handbook.apra.gov.au/standard/cps-234 ; https://www.pcisecuritystandards.org/standards/pci-dss/ ; https://www.faa.gov/documentLibrary/media/Order/FAA_Order_8110.49A.pdf high Strong on floors and consequence logic.
[inference] Policy architecture must keep the Policy Administration Point (PAP), Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP) separate and evaluate a schema-validated scope object with fail-closed freshness. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html ; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html ; https://docs.cedarpolicy.com/policies/validation.html ; https://csrc.nist.gov/pubs/sp/800/207/final high Direct standards and companion convergence.
[inference] Decommission and runtime feedback must be first-class lifecycle phases with registry-to-runtime reconciliation and typed response classes. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html ; https://docs.aws.amazon.com/IAM/latest/UserGuide/id-credentials-access-keys-update.html ; https://docs.aws.amazon.com/config/latest/developerguide/WhatIsConfig.html high Strong lifecycle symmetry and observability support.
[inference] UELGF depends on lower-layer prerequisites in the order policy coherence, information architecture, scoped identity, then permission-safe retrieval or tool access and deployment gating. https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html ; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html ; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html medium Adjacent prerequisite chain.
[inference] A minimum viable governance state can use UELGF partially, but only as bounded containment and evidence generation rather than full safety. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html ; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html medium Target-state versus readiness distinction.
[inference] The standard needs explicit limitations for invisible off-rail entities, mandate dependence, managed-credential dependence, and detection lag. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html ; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html medium Honest residual-risk statement.

Assumptions:

  • [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Consequential entities are issued through managed identity and credential channels that the control plane can revoke or refuse to renew. Justification: the source set proves the control model but not universal estate discipline.
  • [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://opentelemetry.io/docs/concepts/signals/] Runtime platforms can emit normalized governance fields such as entity_id, rail_id, entity_type, and cia_tier consistently enough for cross-platform aggregation. Justification: the feedback-loop design is not workable without a minimal canonical signal schema.
  • [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] The board or an equivalent executive authority can mandate rail entry for consequential entities where incentives alone do not suppress bypass. Justification: the framework can lower bypass demand, but the mandate power itself sits outside the technical specification.

Analysis:

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html] 1. Scope and governed object, technical specification: a UELGF entity is any consequential socio-technical object or workflow that can create, store, transform, expose, move, delegate, or retire business capability, data, permissions, obligations, or operational risk, and the standard applies without exception to all such entities and all builder personas. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] Board view: coverage follows consequence, so no digital capability gets a governance exemption merely because it was built in a different tool or by a different team.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://handbook.apra.gov.au/standard/cps-234] 2. Taxonomy and CIA, technical specification: each entity receives one canonical type, one CIA score, highest-triggered-axis overall tiering, and automatic floors for intrinsically consequential surfaces, with tier baselines and entity modifiers driving control intensity. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://www.pcisecuritystandards.org/standards/pci-dss/] Board view: control intensity follows consequence rather than builder optimism, so high-risk automation cannot classify itself onto a cheaper path.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] 3. Governed golden rail, technical specification: the rail is a compositional product that emits identity, manifest, promotion, policy, telemetry, ownership, and retirement artefacts at creation time, then adds tier, entity, persona, and platform-specific controls without changing the underlying governed path. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Board view: the approved path has to become the easy path, including for citizen developers, or workaround demand will stay in place.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html] 4. Policy architecture, technical specification: the PAP authors and publishes canonical policy, the PDP evaluates, the PEP enforces, the PIP supplies state, the 8-layer model provides ordered precedence, the typed scope object defines the per-entity envelope, and stale policy or stale licence state fails closed. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://csrc.nist.gov/pubs/sp/800/207/final] Board view: policy must stay central and current, and no local tool should keep acting on stale policy because synchronization was inconvenient.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] 5. Decommission, technical specification: no entity is retired by declaration alone; retirement completes only when admissions are frozen, work is drained or compensated, credentials no longer authorize action, dependencies are handled, and archive evidence is sealed. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://docs.aws.amazon.com/IAM/latest/UserGuide/id-credentials-access-keys-update.html] Board view: digital capability has to leave the estate as cleanly and evidentially as it entered it, because residual credentials, forgotten dependencies, and orphaned entities are governance failures.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] 6. Runtime feedback, technical specification: runtime observations become typed governance findings that can observe, notify, suspend, retire, or reclassify, and the same data closes both to rail product improvement and to systems-capability-debt investment prioritisation. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] Board view: governance has to learn from live friction and live failure instead of waiting for annual review or anecdote.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] 7. Sequencing and limitations, technical specification: institutions should adopt the full target-state framework now, but should sequence rollout by first proving delegated-domain policy coherence, information architecture and access representation, machine identity scoping, governed deployment, telemetry, and revocable credentials, while stating openly that invisible off-rail entities, missing mandate, unmanaged credentials, and discovery lag remain residual risks. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] Board view: the framework is a disciplined target architecture, not permission to declare mature control while foundations are still absent.

Risks, gaps, uncertainties:

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Kill-switch and suspension claims are strong on control shape but remain partly implementation-dependent on short-lived credentials, revocation coverage, and estate-specific connector behavior.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://opentelemetry.io/docs/concepts/signals/] Runtime-feedback effectiveness depends on canonical signal fields across heterogeneous platforms, and the source set supports the pattern more strongly than any universal cross-platform schema standard.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html] The dependency-order conclusion is strong, but estates with partially coherent information architecture may still argue for narrow low-risk deployments, so the standard should separate target architecture from partial present-state allowances rather than deny all nuance.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] Ghost detection can only surface what inventory, runtime, or credential evidence eventually reveals, so entities that never touch visible control points still create residual off-rail risk between creation and discovery.

Open questions:

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-pdp-universal-policy-synchronisation-integrity.html] What compatibility rules should let policy revisions reuse prior typed scope objects without forcing unnecessary entity re-registration?
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] What diversity threshold across entities, owners, or business units should force a new rail or rail-version case rather than continued repeated exceptions?
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Which connector classes in the target estate support immediate revocation, which support only non-renewal, and which require compensating PEP-side hard blocks for a credible kill switch?

§7 Recursive Review

  • Metadata: companion-item re-scan completed after drafting.
  • Metadata: adjacent prerequisite-item re-scan completed during final review.
  • Metadata: acronym review completed for UELGF, CIA, AI, SaaS, PAP, PDP, PEP, PIP, and RAG.
  • Metadata: claim-label review, Evidence Map audit, and synthesis-to-Findings parity review completed.

Findings

Executive Summary

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html] UELGF is defensible as one lifecycle standard only if every consequential entity, regardless of technology or builder persona, enters through a generative governed rail backed by independent policy, typed scope, continuous authorization, decommission control, and runtime feedback, and only if the institution states clearly that these controls do not substitute for coherent information architecture, access control, and classified data foundations.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-citizen-development-empirical-evidence.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] The framework solves two inseparable problems at once: it creates one governable lifecycle grammar for heterogeneous entities, and it makes the sanctioned path faster and clearer than bypass so that one major driver of off-rail workaround demand is reduced, even though citizen-development and workaround adoption remain multi-causal.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] The complete specification therefore combines one universal entity definition, one canonical taxonomy and CIA model, one compositional rail formula, one policy architecture, one retirement standard, and one learning loop that feeds both rail evolution and systems-capability-debt remediation.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] Its explicit limitations are equally important: the framework governs entities that enter the rail, not entities that remain wholly invisible; mandatory rail entry still requires executive authority; kill-switch strength depends on revocable managed credentials; and ghost-entity control always leaves residual risk equal to detection lag.

Key Findings

  1. [inference; confidence: medium; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] A formal UELGF standard should apply to every consequential entity and every builder persona under one lifecycle grammar, because the companion items only remain internally coherent when entity coverage, rail obligations, and control evidence are universal rather than selectively optional.
  2. [inference; confidence: high; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://www.fedramp.gov/docs/authority/m-24-15/process/; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf] The governed golden rail should be specified as the compliance mechanism itself and should generate a complete governed scaffold before builder-authored logic goes live, because both the UELGF companion items and external high-assurance analogues reject assurance-by-overlay as the primary control shape.
  3. [inference; confidence: high; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://handbook.apra.gov.au/standard/cps-234; https://www.pcisecuritystandards.org/standards/pci-dss/; https://www.faa.gov/documentLibrary/media/Order/FAA_Order_8110.49A.pdf] Governance intensity should be assigned through one canonical entity taxonomy plus highest-triggered-axis CIA scoring with mandatory floors for high-consequence surfaces, because regulated and high-assurance analogues do not allow builders to self-downgrade materially consequential action surfaces.
  4. [inference; confidence: high; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html; https://docs.cedarpolicy.com/policies/validation.html; https://csrc.nist.gov/pubs/sp/800/207/final] The policy architecture should keep the Policy Administration Point (PAP), Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP) separate, encode policy as an ordered 8-layer constraint stack, and evaluate a schema-validated scope object that names allowed actions, resources, data domains, connectors, side effects, approval requirements, and limits, because policy independence and deterministic scope checking collapse if local enforcement surfaces can carry their own unsynchronized policy.
  5. [inference; confidence: high; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://docs.aws.amazon.com/IAM/latest/UserGuide/id-credentials-access-keys-update.html; https://docs.aws.amazon.com/config/latest/developerguide/WhatIsConfig.html] Decommission and runtime feedback must be first-class lifecycle phases, because safe retirement depends on converged registry, runtime, credential, dependency, and archive state, while safe operation depends on typed runtime signals that can suspend, re-evaluate, retire, and feed both rail backlog and systems-capability-debt remediation.
  6. [inference; confidence: medium; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] The framework depends on foundational prerequisites in a strict order, coherent delegated-domain policy, representable information architecture and access boundaries, scoped machine identity, and only then permission-safe retrieval or tool access plus deployment-gate enforcement, because upper-layer controls cannot validate or constrain what lower layers cannot represent.
  7. [inference; confidence: medium; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] A realistic minimum viable governance state can still use UELGF as bounded containment and evidence generation if it has coherent delegated-domain policy, entity inventory, separate machine identities for consequential automation, a governed promotion gate, baseline telemetry, and revocable managed credentials, but it should not claim full safety until broader foundational prerequisites are satisfied.
  8. [inference; confidence: medium; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] The standard must carry an explicit limitations clause stating that the framework cannot govern entities that never enter organisational visibility, cannot replace executive mandate for mandatory rail entry, cannot guarantee immediate stop if credentials were never managed through revocable channels, and cannot remove residual risk during ghost-entity detection lag.

Evidence Map

Claim Source Confidence Notes
[inference] UELGF should apply one lifecycle grammar to all consequential entities and all builder personas. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html medium Cross-item internal consistency.
[inference] The rail is the compliance mechanism and must emit a complete governed scaffold before live logic exists. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html ; https://www.fedramp.gov/docs/authority/m-24-15/process/ ; https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_120-92D_FAA_Web.pdf high Companion synthesis plus external analogue support.
[inference] Taxonomy plus highest-triggered-axis CIA scoring with mandatory floors is the right governance-intensity model. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html ; https://handbook.apra.gov.au/standard/cps-234 ; https://www.pcisecuritystandards.org/standards/pci-dss/ ; https://www.faa.gov/documentLibrary/media/Order/FAA_Order_8110.49A.pdf high Strong on floors and consequence logic.
[inference] Policy architecture must keep the Policy Administration Point (PAP), Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP) separate and evaluate a schema-validated scope object with fail-closed freshness. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html ; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html ; https://docs.cedarpolicy.com/policies/validation.html ; https://csrc.nist.gov/pubs/sp/800/207/final high Direct standards and companion convergence.
[inference] Decommission and runtime feedback must be first-class lifecycle phases with registry-to-runtime reconciliation and typed response classes. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html ; https://docs.aws.amazon.com/IAM/latest/UserGuide/id-credentials-access-keys-update.html ; https://docs.aws.amazon.com/config/latest/developerguide/WhatIsConfig.html high Strong lifecycle symmetry and observability support.
[inference] UELGF depends on lower-layer prerequisites in the order policy coherence, information architecture, scoped identity, then permission-safe retrieval or tool access and deployment gating. https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html ; https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html ; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html medium Adjacent prerequisite chain.
[inference] A minimum viable governance state can use UELGF partially, but only as bounded containment and evidence generation rather than full safety. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html ; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html medium Target-state versus readiness distinction.
[inference] The standard needs explicit limitations for invisible off-rail entities, mandate dependence, managed-credential dependence, and detection lag. https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html ; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html ; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html medium Honest residual-risk statement.

Assumptions

  • [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Consequential entities are issued through managed identity and credential channels that the control plane can revoke or refuse to renew. Justification: the source set proves the control model but not universal estate discipline.
  • [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://opentelemetry.io/docs/concepts/signals/] Runtime platforms can emit normalized governance fields such as entity_id, rail_id, entity_type, and cia_tier consistently enough for cross-platform aggregation. Justification: the feedback-loop design is not workable without a minimal canonical signal schema.
  • [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] The board or an equivalent executive authority can mandate rail entry for consequential entities where incentives alone do not suppress bypass. Justification: the framework can lower bypass demand, but the mandate power itself sits outside the technical specification.

Analysis

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html] 1. Scope and governed object, technical specification: a UELGF entity is any consequential socio-technical object or workflow that can create, store, transform, expose, move, delegate, or retire business capability, data, permissions, obligations, or operational risk, and the standard applies without exception to all such entities and all builder personas. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-foundational-definitions-principles.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] Board view: coverage follows consequence, so no digital capability gets a governance exemption merely because it was built in a different tool or by a different team.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://handbook.apra.gov.au/standard/cps-234] 2. Taxonomy and CIA, technical specification: each entity receives one canonical type, one CIA score, highest-triggered-axis overall tiering, and automatic floors for intrinsically consequential surfaces, with tier baselines and entity modifiers driving control intensity. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-entity-taxonomy-cia-classification.html; https://www.pcisecuritystandards.org/standards/pci-dss/] Board view: control intensity follows consequence rather than builder optimism, so high-risk automation cannot classify itself onto a cheaper path.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] 3. Governed golden rail, technical specification: the rail is a compositional product that emits identity, manifest, promotion, policy, telemetry, ownership, and retirement artefacts at creation time, then adds tier, entity, persona, and platform-specific controls without changing the underlying governed path. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Board view: the approved path has to become the easy path, including for citizen developers, or workaround demand will stay in place.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html] 4. Policy architecture, technical specification: the PAP authors and publishes canonical policy, the PDP evaluates, the PEP enforces, the PIP supplies state, the 8-layer model provides ordered precedence, the typed scope object defines the per-entity envelope, and stale policy or stale licence state fails closed. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://csrc.nist.gov/pubs/sp/800/207/final] Board view: policy must stay central and current, and no local tool should keep acting on stale policy because synchronization was inconvenient.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] 5. Decommission, technical specification: no entity is retired by declaration alone; retirement completes only when admissions are frozen, work is drained or compensated, credentials no longer authorize action, dependencies are handled, and archive evidence is sealed. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://docs.aws.amazon.com/IAM/latest/UserGuide/id-credentials-access-keys-update.html] Board view: digital capability has to leave the estate as cleanly and evidentially as it entered it, because residual credentials, forgotten dependencies, and orphaned entities are governance failures.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html] 6. Runtime feedback, technical specification: runtime observations become typed governance findings that can observe, notify, suspend, retire, or reclassify, and the same data closes both to rail product improvement and to systems-capability-debt investment prioritisation. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html] Board view: governance has to learn from live friction and live failure instead of waiting for annual review or anecdote.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] 7. Sequencing and limitations, technical specification: institutions should adopt the full target-state framework now, but should sequence rollout by first proving delegated-domain policy coherence, information architecture and access representation, machine identity scoping, governed deployment, telemetry, and revocable credentials, while stating openly that invisible off-rail entities, missing mandate, unmanaged credentials, and discovery lag remain residual risks. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] Board view: the framework is a disciplined target architecture, not permission to declare mature control while foundations are still absent.

Risks, Gaps, and Uncertainties

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Kill-switch and suspension claims are strong on control shape but remain partly implementation-dependent on short-lived credentials, revocation coverage, and estate-specific connector behavior.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://opentelemetry.io/docs/concepts/signals/] Runtime-feedback effectiveness depends on canonical signal fields across heterogeneous platforms, and the source set supports the pattern more strongly than any universal cross-platform schema standard.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-permission-safe-rag-enterprise-information-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-foundational-conditions-dependency-ordering.html] The dependency-order conclusion is strong, but estates with partially coherent information architecture may still argue for narrow low-risk deployments, so the standard should separate target architecture from partial present-state allowances rather than deny all nuance.
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html] Ghost detection can only surface what inventory, runtime, or credential evidence eventually reveals, so entities that never touch visible control points still create residual off-rail risk between creation and discovery.

Open Questions

  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-policy-architecture-8-layer-context.html; https://davidamitchell.github.io/Research/research/2026-04-27-pdp-universal-policy-synchronisation-integrity.html] What compatibility rules should let policy revisions reuse prior typed scope objects without forcing unnecessary entity re-registration?
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-runtime-feedback-loop.html; https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-governed-golden-rails.html] What diversity threshold across entities, owners, or business units should force a new rail or rail-version case rather than continued repeated exceptions?
  • [inference; source: https://davidamitchell.github.io/Research/research/2026-04-27-uelgf-decommission-lifecycle.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html] Which connector classes in the target estate support immediate revocation, which support only non-renewal, and which require compensating PEP-side hard blocks for a credible kill switch?

Output

Navigation

Home

By Tag

bureaucracy

change-management

coase

constraint-analysis

control-model

decision-rights

delegation

delivery-risk

demand-segmentation

enterprise

exception-handling

execution

flow

flow-design

flow-metrics

governance

governance-patterns

incentives

instability

institutional-economics

leading-indicators

operating-model

organisation

organisational-design

queue-design

queueing

regulated-enterprise

routing

throughput

throughput-risk

transaction-costs

triage

williamson

Clone this wiki locally