FAILURE CONTROL
Technical failure cannot create authorization.
Security-critical failure is never treated as permission. Failure behavior is explicit for each workload and action class. Missing policy, required verification, release authentication or other mandatory security dependencies cannot become an implicit allow. Critical paths hold or fail closed, while lower-risk paths follow explicitly configured failure behavior.
Failure
Enforced Response
Security Principle
External verifier unavailable
→
A critical operation requiring authoritative verification remains on HOLD.
→
Missing facts cannot become approval.
Control Plane unavailable
→
Runtime uses the last valid signed known-good policy bundle according to defined operational policy.
→
Mutable Control Plane state is not runtime authority.
No valid policy available
→
Protected release is denied.
→
No trusted policy means no release authority.
Customer analysis unavailable
→
The configured failure policy for that action class determines the outcome.
→
A required analysis result cannot silently disappear from authorization.
Required release authentication unavailable
→
The protected operation cannot be released through that path.
→
Required release prerequisites cannot be bypassed.
Evidence dependency unavailable
→
Critical operations follow explicit failure policy; lower-risk events use durable buffering where configured and supported.
→
Evidence failure cannot be silently ignored.