STARTMAKINGSENSE

Inter-Pillar Interfaces

The seams where capability domains intersect. These interfaces define how identity context, policy decisions, telemetry, and governance signals move between IAAI pillars.

Policy - Data

A to B interface diagram

A to B: Entitlement definitions and runtime policy decisions consumed by data enforcement points, including policy for read, transform, and reveal rules plus clearance tiers.

B to A: Retrieval coverage gaps, prompt-injection-induced bypasses, ungoverned access paths, abstraction tier compliance gaps, and seal-break events identified during Pillar B operations, surfaced back to Pillar A for policy correction, control-plane hardening, and tier model evolution.

Commons DraftEditorial research

Policy - Services

A to C interface diagram

A to C: Entitlement definitions and runtime policy decisions consumed by AI-initiated service and tool-invocation enforcement points, governing which actions an agent may call, on whose behalf, and under what scope.

C to A: Service invocation attempts, tool-call authorization denials, and scope-exceeded events from Pillar C service operations, surfaced back to Pillar A for policy correction and delegation-scope tuning.

Detail page coming soon.

Commons DraftEditorial research

Policy - SecOps

A to D interface diagram

A to D: Policy version metadata, entitlement baselines, and credential or access change events consumed by Pillar D for anomaly detection and SOC workflows.

D to A: DLP violations, abuse patterns, red-team findings, and DSPM discoveries used by Pillar A to adjust entitlements, segmentation, and technical controls—the core technical feedback loop from operations to policy.

Commons DraftEditorial research

Policy - Governance

A to E interface diagram

A to E: Implementation status, coverage metrics, and certification results for identity and authorization policies consumed by E-AIG for AI risk assessment and reporting.

E to A: Governance decisions, control objectives, and prohibited use cases translated into specific policy-engine rules, IGA roles, and technical constraints in Pillar A.

Commons DraftEditorial research

Data - SecOps

B to D interface diagram

B to D: Retrieval audit logs -- who retrieved what, from which corpus, using which policy version -- plus output classification, clearance tiers, and redaction actions for each AI response, all consumed by SIEM, DLP, and anomaly detection.

D to B: Retrieval-scope anomalies, prompt-injection-derived bypasses, data exfiltration patterns, output DLP violations, and disclosure anomalies used to tune retrieval filters, corpus partitioning, abstraction schemas, and redaction rules in Pillar B, in parallel with D's technical feedback to Pillar A.

Commons DraftEditorial research

Data - Governance

B to E interface diagram

B to E: Retrieval coverage reports, ungoverned AI access paths, corpus risk profiles, abstraction tier compliance, seal-break events, and disclosure patterns provided to Enterprise AI Governance for the AI risk register and use case decisions.

E to B: Governance directives on which corpora may be used for which AI use cases, jurisdictions, and tenants, and governance decisions on acceptable abstraction tiers, redaction defaults, and disclosure constraints -- typically expressed via Pillar A policy or GRC workflows that then drive changes in Pillar B configuration.

Commons DraftEditorial research

SecOps - Governance

D to E interface diagram

D to E: AI security incident summaries, DLP trends, red-team results, and operational risk metrics delivered to Enterprise AI Governance for AI risk register updates and board-level reporting.

E to D: Governance-defined AI risk tiers, escalation thresholds, and reporting expectations that shape alert severity, playbooks, and SOC workflows in Pillar D.

Commons DraftEditorial research