Skip to content
Paula Livingstone writing · projects · tools

Attestable Design & Artefact

The Basis Model: What It Must Represent, Before Its Structure Is Fixed

This is the first artefact in the project whose downstream is rigid against it: the inheritance method, the admissibility method, the evaluation, and the conclusion are all built on top of the basis model, so oversizing it here is not a trim to undo later but a demolition. That is why the model is built minimal, and why this spine names what it must represent and to what standard rather than fixing its structure. It sets the elements the typing chapter already gestured at, the guardrail the claims register recorded against a premature inheritance rule, and the stopping condition that keeps the model minimal. It fixes no structure, sketches no library, and lists no fields of any class, because the moment it does it stops being an attackable skeleton and becomes a design fixed before it was argued.

This is the first artefact in the project whose downstream is rigid against it. Everything published so far has been about the basis model without depending on its internals: the review named the composition, the methodology typed it, the scenario protocol tests it by outcome without knowing its structure. That is why the front half condensed cleanly when it was tightened, because nothing load-bearing sat on top of it. The moment the basis model exists, that ends. The inheritance method operates on its elements, the admissibility method reads its fields, the evaluation defines error over what it claims to represent, and the conclusion argues about what those elements achieved. So the model is the one place in the work where oversizing is not a trim to undo in revision but a structure the rest of the dissertation would have to be rebuilt around. It is built minimal for that reason, and reading the dependency graph correctly is what makes minimal here a discipline rather than a timidity.

What the model answers, and how small it may be

The model answers the first research question and no more than that: what minimal representation of a claim's basis is sufficient to decide admissibility for an intended action, and what must it capture beyond origin and integrity. The phrase beyond origin and integrity is not rhetorical. Origin is what the provenance standard records, and it places the assessment built on that record outside itself (W3C, 2013a); integrity is what attestation certifies, and the framework states that it does not validate whether the claims it carries are correct (in-toto, n.d.). The model must exceed both, and the two specifications fix what exceeding them means. The word minimal is in the question, and it is taken literally. The model is the smallest structure that lets the inheritance method and the admissibility method operate and that gives the discrimination evaluation something to run against. It is not a general theory of evidence, and the temptation to make it one is exactly the drift this work's deliberately bounded scope rules out: a richer model earns its richness only when the minimal one is shown to lack a semantics it needs, on evidence, not when a richer one would be more interesting.

What the model must represent

The typing chapter committed the work to naming the basis in nameable terms rather than as a scalar or a score. Those terms are the elements the model must represent, stated as requirements: what the model must be able to say about a claim.

The model must represent what the claim rests on, how that evidence was acquired, and what operation produced the claim from it, because the whole problem begins in the difference between a value that was measured and one that was generated. It must represent what independent support a claim has, because corroboration that is really a single source counted twice is the failure an inheritance rule most needs to see. That much is a requirement. But telling genuine independence from shared ancestry requires knowing where a claim came from, and how that ancestry is known is not a requirement on what the model says about one claim; it is the largest structural choice the drafting will make, and it is named as a choice here rather than settled. The model could hold the ancestry itself, so that each basis record carries the derivation that produced it; or it could hold only a claim's position in a derivation graph that lives elsewhere, in the library or the transport, with the basis record carrying a reference into it; or it could hold something between the two. These are different models with different costs, and the whole downstream inherits whichever is chosen. What is fixed here is only that the model must be able to distinguish genuine independence from shared ancestry at all. How it knows the ancestry that lets it do so is settled by the origin equation, which is argued in the structure that follows rather than assumed here. It must represent what authority stands behind the claim and on whose say-so. It must represent when the basis was established and how quickly the underlying condition changes, because a basis has a shelf life that varies by what it is about, and a freshness that is adequate for a slow condition is not adequate for a fast one. And it must represent the scope within which the basis was established, because a claim true of a sample is not true of a population and a claim true at one point in a plant is not true of the plant.

These are the elements, and naming them is a commitment the drafting is held to, not a structure the drafting is handed. Whether they are complete, whether any collapses into another, and how they compose is the work of fixing the model. What is fixed here is that the model must be able to speak about each of them, and that a model unable to represent any one of them has failed to represent basis in the sense the work requires.

What the model deliberately does not represent

A reader who notices that every element above is about the basis, and none about the act the basis is judged against, is noticing something real, and the omission is a decision rather than a gap. Admissibility is a relation between a basis and an intended action, and a relation is not stored in either of the things it relates. The basis model represents the basis; the action's demand, what this particular act requires of the evidence behind a value, is the other argument to the admissibility method, supplied at the point of judgement. Putting the act's demand inside the basis record would be a category error, because it would make a claim's basis depend on what someone intends to do with the claim, which is backwards. The same value with the same history has the same basis whether the reader is deciding what to investigate next or whether to act on it physically; what changes between those is the demand, and the demand belongs to the act. This is worth stating positively rather than leaving as a silence, because the exclusion is load-bearing: the model is kept to the basis side on purpose, and the action-relativity the work turns on is a property of the judgement, not of the record judged. One distinction guards against the obvious objection. Scope is in the model, but it is the scope within which the basis was established, a property of the basis; the scope an act requires is a demand of the act, and it lives with the act. The two are not the same thing wearing one name, and keeping them apart is part of why the act's demand can stay outside the model without anything being lost.

The guardrail the model carries in

One constraint was recorded during design as a guardrail rather than asserted as a rule, and it shaped the model before the inheritance method was written. It recorded this as a question about when a derived claim's standing may exceed its weakest ancestor's, on the reasoning that corroboration, testing or proof can strengthen a claim and that a model unable to represent this would forbid the ordinary business of establishing things. The design chapter answers it by rejecting the premise: no descriptive field of a basis is ever raised, so there is no promotion for the model to represent. What the model must represent instead is which supports a basis contains and how that set may change, which means evidential independence, transformation, scope, fresh acquisition, and explicit ancestry reset. Mutually dependent sources still do not corroborate at all, and the origin set settles that mechanically. The guardrail is a constraint on the model's expressiveness, not yet an inheritance rule, and stating it here keeps the model from being fixed in a shape the inheritance method would then have to fight.

The standard the model is held to, and where it stops

Two standards govern the model, and they are the ones the methodology already committed the work to. The model must be precise enough to be implemented and therefore precise enough to be argued with, because a basis described in vague terms is both weak prose and uncodeable, and the same vagueness that protects it from criticism makes it useless to build against. And the model must not collapse into any of the fields the review distinguished it from, a standard that is testable because each of those fields states its own limit. If the model reduces to a provenance record that hands the judgement on, it has become what the provenance survey describes, a history that lets a user apply their own metrics to decide whether data is acceptable (Simmhan et al., 2005). If it reduces to a confidence score, it has become what the uncertainty survey concludes is not sufficient for safe decision-making (Gawlikowski et al., 2021). If its criteria are supplied from outside, it has become an attribute-based access control decision over attributes someone else defined (NIST, 2014). In each case the field itself supplies the refutation, which is what makes the standard a test rather than a preference.

Where the model stops is fixed by the frame. It stops when it can represent the elements above to that standard, when the inheritance and admissibility methods have something to operate on, and when the scenario set can be run against it to read the operating points. It does not continue into a general semantics of evidence. Where a neighbouring field is shown to hold a semantics the model genuinely needs, that field is engaged on evidence of the need rather than on spec. If the model begins pulling the dissertation toward a scale the bounded scope does not hold, that is the signal a field has quietly become a chapter, and the response is to stop and check rather than to follow the model wherever it grows.

References

W3C (2013a). PROV-DM: The PROV Data Model. W3C Recommendation. w3.org/TR/prov-dm

in-toto (n.d.). in-toto Attestation Framework: Specification. github.com/in-toto/attestation

Simmhan, Y. L., Plale, B. and Gannon, D. (2005). A Survey of Data Provenance Techniques. SIGMOD Record, 34(3). doi.org/10.1145/1084805.1084812

Gawlikowski, J., Njieutcheu Tassi, C. R., Ali, M., Lee, J., Humt, M., Feng, J., Kruspe, A., Triebel, R., Jung, P., Roscher, R., Shahzad, M., Yang, W., Bamler, R. and Zhu, X. X. (2021). A Survey of Uncertainty in Deep Neural Networks. Artificial Intelligence Review. arXiv:2107.03342. arxiv.org/abs/2107.03342

NIST (Hu, V. C., et al.) (2014). Guide to Attribute Based Access Control (ABAC) Definition and Considerations. NIST SP 800-162. doi.org/10.6028/NIST.SP.800-162