Skip to content

Threat Genome

Phase 9 of the Authority Control Plane gives the network a memory of refusals, the way Authority Memory gives a workspace a memory of its own decisions. It is framed, and built, as rules the network learned: patterns only, opt-in, off by default, and never a monitor.

What a pattern is

When an action is refused, a session terminated or an agent quarantined, the path it took has a structure: the action family, the resource class, the shape of the delegation (how deep, which kinds of authority), the signals that fired, the effect flags (kind, irreversible, external) and the outcome. That structure, and nothing else, is the pattern. It holds no workspace, no agent, no decision id, no content and no argument values. Two organisations that refused the same shape produce the same pattern_id.

{"format": "xybern-genome-pattern-v1", "family": "payment", "resource_class": "bank_account",
 "delegation": {"depth": "1", "kinds": ["charter", "grant", "warrant"]}, "signals": ["argument", "effect"],
 "effect": {"kind": "payment", "irreversible": true, "external": true}, "outcome": "refused", "pattern_id": "gen_…"}

A workspace's own patterns are built from its authority telemetry (refused and terminated decisions) and from the decisions that led to a quarantine. The Threat Genome view under Oversee lists them.

Nothing leaves a workspace, and nothing arrives, until a person decides:

  • Share sends the workspace's patterns to the network. The feed keeps the pattern, a count and the number of contributors, counted through a blinded hash of the workspace so the feed never holds who contributed.
  • Pull reads the network's patterns into the workspace, where they are matched against live requests.

Both are off by default. The choice is recorded with who made it and when, and sealed in the Provenance Vault. A sovereign deployment keeps the network off entirely (XYBERN_GENOME_NETWORK=0): sharing and pulling are refused and the view says so. Because patterns hold no personal data and no identifiers, sharing carries no personal-data transfer under the PDPL; the consent note in the compliance pack records that reasoning.

The genome rule

With pull enabled, every live request's shape (family, resource class, delegation depth, effect flags) is matched against the feed before any rule runs, and the matches go on the Authority Slice and the decision record. A genome primitive in a mandate names its thresholds:

{"type": "genome", "action_types": ["*"], "decision": "escalate",
 "conditions": {"min_contributors": 2, "min_count": 3, "match": ["family", "resource_class", "delegation", "effect"]}}

The rule fires only when the workspace pulls the feed and a matching pattern has been refused at least min_count times across at least min_contributors organisations. Without pull, or below the thresholds, the match is recorded as advisory (E16). The decision record shows a Genome row with the pattern's count and contributors; a genome hold is a definite condition that content verification never lifts.

GET  /v1/enforce/genome/consent                POST /v1/enforce/genome/consent {share, pull}   (approvals)
GET  /v1/enforce/genome/patterns?rebuild=1     POST /v1/enforce/genome/publish                 (approvals, share consent)
GET  /v1/enforce/genome/feed?min_contributors=&min_count=                                      (pull consent)
GET  /v1/enforce/genome/match?action_type=&agent_id=&resource_class=                          pure, records nothing
GET  /v1/enforce/genome/rules                  POST /v1/enforce/genome/rules {decision, min_contributors, min_count, match}   (approvals)

SDK: genome_consent, genome_patterns, genome_publish, genome_feed, genome_match, genome_rule.

The ontology in the SDK

Phase 9 also ships XAO in the SDK as a pure module, xybern.xao: the eight primitives as typed classes, Slice.from_response over an intercept response, a receipt or a decision record, the eight invariants as offline checks that pass the bundle's invariant vectors, family_of, and fingerprint for genome patterns. client.slice_of(decision_id) returns the slice of any decision as of its own time. The ontology itself is published as a draft at XAO 0.9, with XAL, the slice, passports, negotiation and genome patterns as formats in the bundle (56 vectors). It becomes 1.0 when customers run it in production and the formats have not changed for a release.