Releases: sajjad47/AITIR-Framework
Release list
AITIR Framework 2.0.0
AITIR Framework 2.0.0
Adaptive Identity-and-access Threat Intelligence and Response
AITIR 2.0.0 is a major reference-architecture release for converting identity-centered security telemetry into provenance-linked evidence, a bounded policy decision, an authorized response, and independently reviewable assurance.
Evidence in, authority out. Analytics produce evidence; authorized policy decides; enforcement acts; assurance verifies.
Major changes since v0.1
- Replaces the early four-layer conceptual pipeline with a seven-plane architecture spanning governance, telemetry, analytics, authorization, orchestration, assurance, and continuity.
- Separates event, evidence, decision, action/outcome, and feedback contracts.
- Introduces calibrated uncertainty and abstention as first-class decision states.
- Defines T0-T3 response tiers, named authority, twelve response guards, expiration, idempotency, failure refresh, rollback, and independent outcome verification.
- Adds controlled identity-graph remediation decision support and quarantined feedback/release gates.
- Provides Draft 2020-12 JSON Schemas and matching synthetic JSON/CSV examples.
- Adds a standards crosswalk, migration guide, pilot evaluation protocol, research provenance ledger, roadmap, and explicit status/limitation boundary.
- Adds reproducible architecture/PDF sources, pinned build tooling, automated repository validation, artifact integrity checks, community templates, private vulnerability reporting, and a documented release process.
Included release assets
AITIR-Technical-Exhibit.pdf- six-page technical review exhibit.AITIR-Future-Development-Plan.pdf- six-page evidence-gated development plan.aitir-framework-architecture.png- 1920 x 1080 seven-plane architecture diagram.ARTIFACTS.sha256- SHA-256 integrity manifest for the public artifacts, schemas, and examples.
GitHub's automatically generated source archives contain the complete tagged repository, including all documentation, schemas, examples, source HTML, scripts, citation metadata, and research records.
Validation record
The release commit passed:
- 245 offline repository checks;
- 254 schema-enabled repository checks;
- 61 generated-artifact structure checks;
- JSON Schema Draft 2020-12 validation for all examples;
- CFF 1.2 citation validation;
- Ruff and Markdownlint checks;
- GitHub workflow security audit with SHA-pinned actions and least-privilege permissions;
- repeated same-environment artifact rebuilds with byte-identical outputs;
- external standards and DOI link review;
- visual review of the architecture image and every page of both PDFs.
ARTIFACTS.sha256 authenticates the reviewed, checked-in artifacts. PDF and raster bytes may differ when rebuilt across operating systems because native rendering libraries and fonts differ.
Compatibility and migration
This is a major semantic change. Existing CSV filenames remain for continuity, but their columns and meanings are not positionally compatible with the pre-2.0 conceptual examples. Read the Version 1 to Version 2 migration guide before adapting prior material.
The historical repository contained tag v0.1; no formal v1.0.0 tag existed. "Version 1" in migration documentation refers to the pre-2.0 conceptual baseline and does not rewrite repository history.
Evidence and use boundary
AITIR 2.0.0 is a vendor-neutral reference architecture and research preview, not a production service, certification, compliance determination, agency endorsement, or evidence of operational effectiveness. Synthetic examples establish repository and contract conformance only. Submitted manuscripts remain labeled as submitted rather than accepted.
Operational adoption requires local security authorization; privacy, legal, records, labor, accessibility, and continuity review; independent assessment; least-privileged integration; and tested rollback.
Documentation: https://sajjad47.github.io/AITIR-Framework/
Full changelog: https://github.com/sajjad47/AITIR-Framework/blob/v2.0.0/CHANGELOG.md
AITIR Framework v0.1 - Public Proof-of-Concept Release
AITIR Framework v0.1 - Public Proof-of-Concept Release
This release provides the initial public proof-of-concept package for the AI-Assisted Adaptive Threat Intelligence and Response (AITIR) Framework.
Included materials:
- public framework documentation;
- framework architecture and technical overview;
- public-sector use cases;
- NIST RMF and control-alignment notes;
- synthetic proof-of-concept demonstration;
- sample identity/access event dataset;
- sample risk scoring output;
- sample risk scoring model;
- pilot evaluation protocol;
- status and limitations documentation.
Scope note: This release uses synthetic data only. It does not include real agency records, employer logs, sensitive public-sector systems, credentials, or operational security information. It is not a claim of completed external adoption, live deployment, or certified product status. The purpose of this release is to make AITIR reviewable, testable with synthetic data, and ready for further tabletop evaluation or controlled pilot review.