This chapter surveys the fields a reader must understand to judge the contribution that follows, and it is organised around a claim the survey is designed to test rather than assume. The claim is deliberately a claim about composition, not a universal negative. The judgement at issue is admissibility: whether the basis for a particular output suffices for the particular, often irreversible, action about to be taken on it. Several mature fields supply parts of what such a judgement would need, and some, examined later, may supply semantics this work should adopt rather than reinvent. What no surveyed field supplies as a single working capability is the composition this work names: a portable, per-claim representation of evidential basis, supporting action-relative admissibility, derivation-aware basis preservation, and mechanical evaluation across an ownership boundary. The review's purpose is to walk the neighbouring literatures, establish what each does build, and locate precisely which part of that composition each does and does not provide, so that the gap the contribution occupies is shown by survey rather than asserted. The claim is bounded accordingly: not that no one judges evidential sufficiency anywhere, but that this particular composed capability, enforced at a machine handover, is unfilled.
The distinction that runs through the whole chapter is between integrity and admissibility. Integrity is the property that a value arrived intact, from an authorised source, by an approved path, through a declared process. It is the property provenance records, policy engines enforce, attestation certifies, and network perimeters guard. Admissibility is a different property: not whether a value arrived correctly, but whether its basis is sufficient to act on. A value can have impeccable integrity and no admissible basis at all: a probabilistic inference no measurement supports, conveyed intact to the point of action (Figure 1). The fields surveyed here are, almost without exception, integrity disciplines. They are mature, effective, and necessary, and they are answering a question adjacent to the one this work asks.
Scope and method
The review engages eight bodies of work, each entered through its standard or its founding survey rather than through commentary on it: data provenance and lineage, through the W3C data model (W3C, 2013a) and the field's canonical surveys (Simmhan et al., 2005); policy and access control, through the attribute-based model (NIST, 2014); software supply-chain integrity and attestation, through the in-toto framework and the SLSA threat model (in-toto, n.d.) (OpenSSF, 2023); operational-technology and cyber-physical security, through the authoritative guidance (Stouffer et al., 2023); safety assurance and assurance cases, through the guidance for machine learning in autonomous systems (Hawkins et al., 2021); trustworthy machine learning, covering calibration, uncertainty quantification, and abstention, through the field's comprehensive survey (Gawlikowski et al., 2021); trust in automation and the human-factors literature on reliance, through its foundational taxonomy (Parasuraman and Riley, 1997); and, as a bounded coda, the epistemology of testimony (Leonard, 2021). Two further bodies, examined because they use the same vocabulary as this work and are most likely to be mistaken for it, are the artificial-intelligence governance frameworks (NIST, 2023) and the explainable-AI literature (Mittelstadt et al., 2018).
Sources were gathered by structured, per-field search across arXiv, open-access journals, standards bodies, and open conference proceedings, with backward and forward citation chasing from the seminal works in each field. Two standing rules governed inclusion. First, open access: every cited source is reachable in full, so that the review is auditable rather than resting on abstracts. Second, read before cited: every source was read in full before any claim was attached to it, and preprints were interrogated rather than taken at face value. Where a seminal source is paywalled, that is stated and the substance is carried through open secondary sources rather than quoted from an abstract. The aim of stating the method is to answer, in advance, the question that most often sinks a review, namely whether its coverage was systematic or merely convenient.
How the chapter is organised
The chapter proceeds from the mechanisms closest to the contribution outward to its wider context. It opens with the three integrity disciplines the contribution most directly builds on and departs from, provenance, policy, and attestation, and states the gap they leave. It then turns to trustworthy machine learning, the field that supplies the confidence signal the whole problem begins with, and argues that confidence is the wrong category for the judgement admissibility requires. It follows integrity from software into the physical world, through supply-chain security and operational technology, where a false value stops being a corrupted record and becomes an irreversible physical act. It then examines the governance and explanation literatures, which mandate that basis reach the receiver and even name the failure, but do not adjudicate it, alongside the neighbouring fields of assurance, automation trust, and testimony that each approach the boundary from a different side. A closing synthesis states what the surveyed fields collectively leave unbuilt.
Throughout, the review's task is neither to defeat these literatures nor to claim they overlooked something obvious. Each is doing its own job well. The task is to show, field by field and then in aggregate, that the judgement this work provides is one none of them was built to make, and that the boundary at which they all stop is the same boundary.
References
W3C (2013a). PROV-DM: The PROV Data Model. W3C Recommendation. w3.org/TR/prov-dm
Simmhan, Y. L., Plale, B. and Gannon, D. (2005). A Survey of Data Provenance Techniques. SIGMOD Record, 34(3). doi.org/10.1145/1084805.1084812
NIST (Hu, V. C., et al.) (2014). Guide to Attribute Based Access Control (ABAC) Definition and Considerations. NIST SP 800-162. doi.org/10.6028/NIST.SP.800-162
in-toto (n.d.). in-toto Attestation Framework: Specification. github.com/in-toto/attestation
OpenSSF (2023). Supply-chain Levels for Software Artifacts (SLSA): Threat Model, v1.0. slsa.dev
Stouffer, K., Pease, M., Tang, C., Zimmerman, T., Pillitteri, V., Lightman, S., Hahn, A., Saravia, S., Sherule, A. and Thompson, M. (2023). Guide to Operational Technology (OT) Security. NIST SP 800-82r3. doi.org/10.6028/NIST.SP.800-82r3
Hawkins, R., Paterson, C., Picardi, C., Jia, Y., Calinescu, R. and Habli, I. (2021). Guidance on the Assurance of Machine Learning in Autonomous Systems (AMLAS). University of York. arXiv:2102.01564. arxiv.org/abs/2102.01564
Gawlikowski, J., et al. (2021). A Survey of Uncertainty in Deep Neural Networks. Artificial Intelligence Review. arXiv:2107.03342. arxiv.org/abs/2107.03342
Parasuraman, R. and Riley, V. (1997). Humans and Automation: Use, Misuse, Disuse, Abuse. Human Factors, 39(2), pp. 230-253. doi.org/10.1518/001872097778543886
Leonard, N. (2021). Epistemological Problems of Testimony. Stanford Encyclopedia of Philosophy. plato.stanford.edu/entries/testimony-episprob
NIST (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. doi.org/10.6028/NIST.AI.100-1
Mittelstadt, B., Russell, C. and Wachter, S. (2018). Explaining Explanations in AI. FAT* 2019. arXiv:1811.01439. arxiv.org/abs/1811.01439