Skip to content
Paula Livingstone writing · projects · tools

Attestable Literature Review: The Chapter

What the Survey Establishes: The Composition None of Them Builds

The consolidating section. Figure 4 sets all ten fields against what they establish, what they hand onward, and where they stop. The claim is discharged as the introduction framed it, a composition rather than a universal negative: each field holds one or two parts of a portable, per-claim basis representation supporting action-relative admissibility, derivation-aware inheritance, constrained elevation, and enforcement at an ownership boundary; none holds them together, and none at a machine handover. Why the union does not close it, why the convergence is structural, and the firewall precedent kept in its place.

The chapter has surveyed ten literatures. They differ in method, in vocabulary, in the century they began, and in what they were built to protect. Provenance records what happened; policy decides what is permitted; attestation certifies how an artefact was made; trustworthy machine learning characterises what a model does not know; operational-technology security guards the crossing into the plant; assurance cases argue that a system is acceptably safe; governance mandates that a basis reach whoever must act; explainability tries to convey why a model produced what it produced; trust in automation studies what happens when a person relies on conveyed output; and the epistemology of testimony asks whether a hearer is entitled to believe. This section states what they leave unbuilt, and states it carefully, because the temptation at this point is to claim more than the survey supports.

Where each field stops

Figure 4 sets the survey out in one place. It is worth reading down its final column rather than across its rows, because the columns are where the argument lives: the fields differ in what they establish and in what they hand onward, and they converge on where they stop.

Each field surveyed in this chapter, what it establishes, what it presupposes or hands onward, and the boundary at which it stops.
Field What it certifies or establishes What it presupposes or hands onward Where it stops
Provenance and lineage The recorded history of a value: the entities, activities, and agents that produced it. The trust judgement itself, handed to a later reasoner who applies their own metrics to the record. A logbook informs; the user decides. Retrospective auditing presupposes the record is authentic.
Policy and access control That a request is permitted under authored rules over subject, resource, action, and environment attributes. The basis the rule would need. ABAC has a slot for an assurance attribute; it does not produce one. Evaluation over supplied semantics, not the authoring of what basis suffices for what act.
Attestation and supply chain That an artefact was produced by a declared process, by authorised parties, untampered in transit. The output of each authorised step, which is trusted. SBOM is a foundational data layer for judgements made elsewhere. The integrity of a declared process: the artefact, not the act.
Trustworthy ML How confident, how calibrated, how unlike training data, what set covers the label: the estimation process characterised. That someone downstream converts a distributional statement into a decision to act on this claim. A distributional or procedural question. The field's own survey: not sufficient for safe decision-making.
OT / ICS security That a value crossed into the plant by an authorised path, from an expected source, over a permitted protocol. That an authorised, intact value is one worth acting on. Inaccurate information to operators is named as a hazard, not adjudicated. The crossing, not the act. A learned perimeter inherits the same wrong category.
Assurance cases A structured argument that a system is acceptably safe, over presupposed evidence, about a component at design time. Automation bias: AMLAS names it and hands it to the human-factors literature rather than building a mechanism against it. Design time, not run time. It consumes admissibility judgements rather than producing them.
AI governance That basis must reach the receiver: transparency, disclosure, and contestability mandated at model or decision level. The mechanism. It names the failure, including confabulation and over-reliance, without specifying what would refuse it. It names the boundary; it does not build the gate.
Explainable AI An approximation of how a model behaved, offered post hoc to a human reader. That a plausible account of behaviour is a warrant to act. In practice consumed as an engineer sanity check. Description, not justification: explaining the process, not adjudicating the basis of the claim.
Trust in automation That reliance is a calibrated human behaviour, and that misuse is overreliance on automation the operator cannot appraise. The basis the human would need to calibrate against: purpose, process, and performance. At the human who must calibrate. It describes the reliance failure without supplying the basis.
Epistemology of testimony That a hearer's warrant depends on the speaker's, and that transmission differs from generation of belief. Any engineering mechanism. It has the case, including the persistent believer, but no name for the elevation. It analyses the handover; it does not instrument it.
Figure 4. Where each surveyed field stops. The fields are not deficient: each is doing its own work, and doing it well. What the last column shows is that none of them was built to carry, with a particular value, a judgement of whether its basis suffices for the particular act about to be taken on it. The convergence across ten independent literatures is what makes the absence structural rather than a local gap in any one of them.

The claim discharged, and the one never made

The introduction stated the organising claim deliberately as a claim about composition rather than a universal negative, and the survey is now in a position to discharge it in those same terms. It would be convenient to conclude that no mature discipline produces admissibility. That claim is not defensible and was not made. It is a universal negative over fields this review has not surveyed, and there are several: evidence theory has spent decades representing corroboration, conflict, and dependence between items of evidence; decision theory relates the sufficiency of a basis to the consequence of the act chosen; trust-management systems formalise delegated authority; contract-based design and runtime assurance enforce pre-conditions at a barrier; proof-carrying code is an architectural precedent for carrying a justification alongside an actionable artefact. Somebody, somewhere, judges evidential sufficiency. To claim otherwise would be to inflate the contribution by declining to look.

What the survey licenses is the bounded claim the introduction made: that no surveyed field supplies, as a single working capability, a portable, per-claim representation of evidential basis, supporting action-relative admissibility, derivation-aware basis preservation, and mechanical evaluation across an ownership boundary. Read that composition against the four parts and the fields divide cleanly. Provenance and attestation carry a representation and are silent on sufficiency. Policy enforces at a boundary and presupposes the model it would enforce. Trustworthy ML characterises the estimation process and answers a distributional question where admissibility asks a singular one. Assurance argues about sufficiency and does so at design time over evidence whose standing it assumes. Each field holds one or two parts of the composition. None holds them together, and none holds them at a machine handover. The individual ingredients exist and are mature; it is the composition that is unfilled, and that this work proposes to build.

The introduction also conceded, and this section repeats, that some of the unsurveyed fields may supply semantics this work should adopt rather than reinvent. Whether evidence theory already has the representation of dependence and corroboration that a basis model needs, whether decision theory already relates sufficiency to consequence in the way an action-relative judgement requires, is not settled here. It is a targeted reading owed before the basis model is fixed, and naming it as owed is part of what makes the claim above bounded rather than convenient.

Why the union does not close it either

The natural rejoinder is that the fields might jointly cover what none covers alone: provenance records the origin, attestation authenticates and carries it, a policy engine decides on it, and uncertainty quantification supplies a number to decide with. Composing them does not manufacture the missing part, because the missing part is not a fourth mechanism of the same kind. It is the model the others would operate on.

Provenance can record that a value was generated by a model; it cannot say what that licenses. Attestation can carry and sign that record across a boundary; it cannot say whether the record is sufficient. A policy engine can refuse an action when a claim's basis falls below a bar, but only once basis, the bar, and the action's requirement are defined, represented, and supplied to it. A conformal set or an epistemic-uncertainty estimate is exactly the kind of thing such a representation could carry, and by itself it is a statement about a procedure's long-run behaviour rather than a judgement about this claim. Each mechanism presupposes the same absent thing. The three are transport, record, and evaluation; what they would transport, record, and evaluate is what does not yet exist.

This also disposes of the idea that the fields are in competition with the contribution. Two of them are better read as components of it. An authenticated attestation envelope is the natural transport for a basis representation once one exists, and a runtime policy engine is the natural evaluator of it. The in-toto specification welds the two together already, naming automated policy engines as an attestation's intended consumers (in-toto, n.d.). The existing machinery composes into a pipeline from transport into evaluation, with one part missing: the model of basis that would give the pipeline something meaningful to carry and to decide.

The shape of the convergence

Three things about the way these fields converge are worth drawing out, because each is evidence that the boundary is real rather than an artefact of how this review chose to look.

The first is that the fields stop at the same place for different reasons. Provenance stops because it is a record and records inform rather than decide. Attestation stops because it is content-agnostic by construction, which is a design virtue and not an oversight. Policy stops because it is deliberately domain-neutral and evaluates whatever semantics it is handed. Trustworthy ML stops because its questions are distributional and admissibility's question is singular. Assurance stops because it operates at design time over evidence whose standing it presupposes. Governance stops because it is a mandate rather than a mechanism. If a single cause produced all of these, the convergence would be suspicious. Independent causes producing one boundary is what a structural absence looks like.

The second is that the fields nearest to the boundary see it most clearly and still hand it on. The machine-learning assurance guidance names automation bias and refers it to human factors. Human factors studies automation bias for forty years and concludes that reliance must be calibrated to the automation's purpose, process, and performance, which is to say to its basis. The generative-AI risk profile names confabulation and over-reliance as official categories. The explainability literature's own critics establish that description is not justification. Each of these is a field arriving at the edge of the question and stopping, not from ignorance, but because answering it was not the job it had. Awareness of the boundary is not the scarce thing.

The third is that the endpoint is nearly always a human. The record informs a user who decides. The datasheet advises a person choosing whether to deploy. The safety case persuades a reviewer. The explanation is offered to a reader, and in practice reaches an engineer rather than the affected party. The governance mandate is owed to a deployer so that they may interpret and contest. The human-factors literature stops at the operator who must calibrate. The epistemology of testimony asks whether a hearer is justified. Every one of these is a reasonable place to stop while a person stands at the boundary and can, in principle, ask. The handover this work concerns is the one where no person is standing: where a value passes from a probabilistic producer to a machine consumer that will act on it, with no capacity to ask what it rests on and no representation of the answer if it did.

The precedent, and its limit

One architectural precedent is worth naming precisely because it is easy to over-read. The network firewall establishes that an interposed, default-deny, versioned enforcement point at a trust boundary is a mature and trusted pattern: it applies a policy it did not author, written by an accountable authority, and logs its decisions for audit. That institutional form is a genuine precedent for the enforcement point this work proposes, and it is why the proposal is not architecturally exotic.

The precedent stops exactly there. Such a point has historically been indexed by flow properties, by where a value came from and how it travelled, and never by what the recipient will do with what crosses. Action-relative admissibility is precisely the index the precedent lacks. The firewall lends its maturity to the enforcement point and nothing to the hard part, which is how a claim's basis should be represented. The analogy is a rhyme, not an identity, and it is closed off here deliberately: the moment this work reads as a firewall for AI outputs, the contribution shrinks to tooling and the actual difficulty disappears from view.

What the review establishes

The problem statement asserted that no existing mechanism allows a receiving owner to determine whether the evidence behind a claim is sufficient for the specific action they intend to take. After reading the fields in their own primary sources, that is no longer an assertion, and it is worth being precise about what has replaced it. The near neighbours testify to their own limits in their own words: provenance externalises the assessment to external parties (W3C, 2013a); attestation does not validate whether predicate claims are factually correct (in-toto, n.d.), and makes no claims about fitness for purpose (OpenSSF, 2023); policy offers no built-in semantics for basis or fitness (NIST, 2014); uncertainty quantification is, by its own survey, not sufficient for safe decision-making (Gawlikowski et al., 2021).

One claim softened under the reading, and it mattered: an early universal negative was withdrawn in favour of the bounded claim about composition that the introduction now states and this section has discharged. The remainder held. The fields that produce values do not certify their basis; the fields that carry values do not inspect it; the fields that decide on values presuppose it; the fields that argue about evidence assume its standing; the fields that mandate its disclosure do not specify what would refuse it; and the fields that study reliance on it conclude that a human must supply the judgement.

That is what licenses the research question. Not that the problem is unrecognised, since much of the field recognises it, and names it precisely. Not that no one has ever judged evidential sufficiency, since several fields have and some may hold machinery this work should adopt. The question is licensed because the composition that would carry such a judgement to the point of action, portable, action-relative, derivation-aware, and mechanically enforced at a boundary where the receiver is a machine, does not exist as a working capability in the fields that would be expected to contain it. Whether it can be built is the question the rest of this work asks.

References

in-toto (n.d.). in-toto Attestation Framework: Specification. github.com/in-toto/attestation

W3C (2013a). PROV-DM: The PROV Data Model. W3C Recommendation. w3.org/TR/prov-dm

in-toto (n.d.). in-toto Attestation Framework: Specification. github.com/in-toto/attestation

OpenSSF (2023). Supply-chain Levels for Software Artifacts (SLSA): Threat Model, v1.0. slsa.dev

NIST (Hu, V. C., et al.) (2014). Guide to Attribute Based Access Control (ABAC) Definition and Considerations. NIST SP 800-162. doi.org/10.6028/NIST.SP.800-162

Gawlikowski, J., Njieutcheu Tassi, C. R., Ali, M., Lee, J., Humt, M., Feng, J., Kruspe, A., Triebel, R., Jung, P., Roscher, R., Shahzad, M., Yang, W., Bamler, R. and Zhu, X. X. (2021). A Survey of Uncertainty in Deep Neural Networks. Artificial Intelligence Review. arXiv:2107.03342. arxiv.org/abs/2107.03342