Synthesis publication
Bounded Trust Framework
A practical analytical framework for examining whether a consequential trust decision is supported, bounded, fresh enough, and still valid for the consequence being taken.
For decisions that should not borrow more certainty than they earned.
The CBRS Bounded Trust Framework brings ideas from the research series into one analytical model. It asks what was established, by whom, for what consequence, and how long continued reliance remains justified.
The framework is meant for architects, reviewers, implementers, auditors, and researchers evaluating composed systems where trust is not one event, but a chain of evidence, interpretation, authority, state, and time.
It is not a product design, protocol, certification scheme, or replacement for Zero Trust, PKI, RATS, or existing standards work. It is a way to inspect the decision layer those systems create or depend on.
The framework does not turn incomplete evidence into certainty, extend an actor’s authority beyond its boundary, or make an old result permanently fresh because that would be convenient.
Bounded decision lifecycle
A trust decision is a lifecycle, not a single check.
The stages are logical accounting questions. A real implementation may loop, branch, revisit earlier questions, or evaluate several stages at once.
- 01QuestionWhat must be answered?
- 02PropositionWhat must be established?
- 03EvidenceWhat supports it?
- 04AuthorityWho may establish it?
- 05AppraisalWhat does evaluation show?
- 06PolicyWhat local rule is added?
- 07DecisionWhat is justified now?
- 08ConsequenceWhat may follow?
- 09PersistenceWhat state must survive?
- 10InheritanceWhat may rely on it later?
- 11Material changeWhat can invalidate reliance?
- 12Reevaluation / RecoveryWhat must be re-established?
Across every stage: provenance · dependency · uncertainty · root assumptions
Research and validation posture
Stable enough to challenge. Not declared finished by applause.
BTF v1.2 is the reviewed synthesis of the frozen twelve-paper series. Its current form incorporates scope corrections, counterarguments, internal red-team review, and a formal adversarial stress test.
An external standards mapping has tested the framework against established architectures including RATS/EAT, Zero Trust, NIST digital identity, Shared Signals/CAEP, SPIFFE, TUF, and operational technology guidance. That work found strong alignment and a useful cross-system accounting role—not evidence that BTF replaces those architectures.
External validation remains active. The framework is being offered for hostile application, correction, and standards-facing technical review. Future corrections will be versioned rather than quietly rewritten into the record.