The Closed-World Bargain
Why bounded pre-execution authorization does not establish authorization infrastructure
Version 1.1 · August 2026 · CC BY 4.0 · Concept DOI 10.5281/zenodo.21643658
A bounded gate can issue a valid pre-execution authorization verdict within a fixed environment. Authorization infrastructure begins with a different architectural burden: preserving authority-bound, fail-closed, and independently reconstructable authorization across changes in action, meaning, policy, authority, state, and execution topology, while establishing the origin of the inputs on which each verdict rests.
The bargain
The authorization category is filling with systems that perform genuine pre-execution authorization within a fixed scope. This article names the trade those systems make. A bounded gate purchases simple authorization by accepting closure along six dimensions: a finite action vocabulary, structured facts, an internally consistent policy, a single governing authority, one controlled execution path, and stable state between evaluation and use. Within a wired workflow, the bargain is a fair trade.
The failure mode of the bargain is that it fails silently. Each expansion in meaning, policy, authority, state, or execution scope breaks one of the assumptions without announcing itself. The gate keeps returning verdicts. The verdicts keep looking valid. What has changed is that the object the verdict binds is no longer the object that governs.
What the bargain conceals
Each fixed dimension conceals an assurance object: a thing that must be made stable before authorization can bind it. The action, the meaning, the policy, the authority, the path, and the state are different objects, and each is a distinct technical problem. Ambiguity is one of them, because a binary gate is structurally pressured to mishandle it. The verdict space that treats ambiguity as a governed state is ALLOW, DENY, ABSTAIN. ABSTAIN blocks execution pending authorized human override, and the override is itself a governed authorization event that produces its own authorization artifact. Escalation is the consequence of ABSTAIN, not a fourth verdict.
Integrity is not reconstruction
A signature can protect the integrity of an authorization artifact, but signature verification and independent reconstruction answer different questions. Integrity mechanisms prove that what was recorded has not changed since capture. Reconstruction requires that the artifact carry or reference the bounded inputs, policy state, evaluator state, authority chain, and decision procedure sufficient to reproduce or re-check the verdict, without dependence on the original vendor. Reconstruction may proceed under either replay mode defined by the Five Tests Standard: State-Replay, which requires byte-exact artifact reproduction, or Protocol-Replay, which re-evaluates deterministic acceptance gates over frozen verifier materials. A system can satisfy integrity verification completely while failing reconstruction completely.
The depth of authorization
Provenance is not a layer above authorization. It is the depth of authorization. A bounded gate can validate every field perfectly while no field has an established origin, and integrity mechanisms cannot repair this, because they operate on the record after capture. Provenance establishes origin, not truth, and origin is the property a verdict rests on. Authorization that cannot establish the provenance of its inputs is authorization in form, not in substance.
The Composition Test
Authorization infrastructure, as used here, is a scoped threshold claim, not a marketing tier: an architecture warrants the term when it preserves authority-bound, fail-closed, and independently reconstructable authorization across changing assurance objects, establishes the origin of the inputs grounding each verdict, and passes this test within a declared scope.
The test has an operational form that any architecture can attempt. Two assurance functions operate under one authorization and evidence discipline, and the first artifact is materially consumed by the second assurance function. A verdict is independently reconstructed by a third party from the artifact and verifier materials alone, under the declared replay mode. Fail-closed behavior is demonstrated directly across a declared execution-path scope. Any claim based on the test must identify the assurance objects, governed effect, replay mode, and execution-path scope demonstrated.
The Composition Test is a scoped demonstration, not a universal security proof. It applies to FERZ, Inc. as it applies to any other vendor in the category. FERZ has committed its own demonstration program to this test and has not yet passed it. The test is published before the result.
Five questions to ask any authorization system
- Which verdict is returned when policy does not address the proposed action, and does that verdict block execution pending an authorized human override?
- Can a third party reconstruct the verdict from the artifact and verifier materials alone, without access to the governed system and without dependence on the original vendor?
- How is the origin of the inputs grounding a verdict established, beyond proving that the record was not altered after capture?
- What prevents the same governed effect from being reached through a path that bypasses the gate?
- Can the architecture carry its authorization and evidence discipline across a second assurance object, or does the discipline end where the wired workflow ends?
Read the full article
Download the article (PDF, Version 1.1)
Zenodo record (timestamped record of publication)
Published under CC BY 4.0.
Frequently asked questions
What is the closed-world bargain?
The closed-world bargain is the trade a bounded authorization gate makes: simplicity of authorization purchased by holding six conditions fixed, action vocabulary, meaning, policy, authority, state, and execution topology, while assuming the origin of the inputs grounding the verdict. The bargain is rational within its scope and fails silently outside it.
What is the Composition Test?
A falsifiable test of whether an architecture carries a common authorization and evidence discipline across changing assurance objects. It requires material consumption of the first artifact by the second assurance function, independent reconstruction under a declared replay mode, and fail-closed behavior demonstrated across a declared execution-path scope.
Does the article argue that bounded authorization gates are invalid?
No. The article concedes that a bounded gate can provide real pre-execution control within its scope. The argument is narrower: bounded authorization does not establish authorization infrastructure, because the properties that make authorization reusable are the ones the bargain gives away.
What is the ABSTAIN verdict?
ABSTAIN is the blocking verdict when the authorization evaluation cannot resolve to ALLOW or DENY under the applicable policy and evidence. It blocks execution pending authorized human override, and the override is itself a governed authorization event that produces its own authorization artifact. Escalation is the consequence of ABSTAIN, not a fourth verdict.
How does integrity verification differ from independent reconstruction?
Integrity verification establishes that a record has not changed since capture. Independent reconstruction requires that a third party re-derive the verdict from the artifact and verifier materials alone, without access to the governed system and without dependence on the original vendor. A system can satisfy the first completely while failing the second completely.
Related concepts
- Five Tests Standard (5TS)
- A Taxonomy of AI Governance Approaches
- Authorization Boundary Integrity Model
- Authority versus Authorization
- LLM-as-a-Judge Is Not Authorization
Cite this article
FERZ, Inc. (2026). The Closed-World Bargain: Why Bounded Pre-Execution Authorization Does Not Establish Authorization Infrastructure. Version 1.1. https://doi.org/10.5281/zenodo.21643658
@techreport{ferz2026closedworldbargain,
author = {{FERZ, Inc.}},
title = {The Closed-World Bargain: Why Bounded Pre-Execution Authorization Does Not Establish Authorization Infrastructure},
institution = {FERZ, Inc.},
year = {2026},
note = {Version 1.1},
doi = {10.5281/zenodo.21643658},
url = {https://ferz.ai/articles/closed-world-bargain}
}
