Trust Boundaries as a Typed Category: An Open Problem
Table of Contents
1. Abstract
Trust-boundary formalisms: actor model plus ocap as topology spine, IFC plus QIF (Smith 2009) plus DP (Dwork et al. 2006) for structured channels, deterministic simulation testing for invariant-replay under adversarial schedules, CALM for monotonic agent state. No existing formalism bounds the free-text channel emitted by an LLM, so "privacy-preserving" agentic claims are unverifiable at the channel level. Operating-point class (Δvol, τ, ρ_individual, ρ_aggregate, fan-out, schema-churn) is not typed in any current label system; cross-class platform claims are vocabulary, not mechanism. Four archetypes (PetClinic visits, AeroAPI/ADS-B, Arctic tick store, HFT feed) span nine orders of magnitude in latency and eight in volume. Same governance tuple G = ⟨membrane, access, telemetry-allowlist, action-semantics⟩ holds at each; the enforcement primitives don't transfer. Polynomial functors (Niu and Spivak 2023), open games (Ghani et al. 2016), and sheaves over local sections (Curry 2013) are the candidate composition frames. Open problems: free-text channel QIF, operating-point-class typing, locality-of-loop as formal property, sheaf condition under adversarial local sections, requisite variety of control planes.
1.1. Longer register
The trust-boundary literature reads as a stack of terministic screens, each highlighting one element of a four-part governance tuple (membrane, access, telemetry-allowlist, action-semantics) and obscuring the rest. Hewitt's actor model gives the topology stripped to its commitments: bounded entity, controlled channel, dynamic reference graph. Denning's lattice and Myers' decentralized label model add a typing of confidentiality and integrity, qualitative. Quantitative information flow (Smith 2009) and differential privacy (Dwork et al. 2006) give bits-leaked-per-query for structured channels. None of these formalize the operating-point class itself; the parameters (Δvol, τ, ρ_individual, ρ_aggregate, fan-out, schema-churn) under which a governance tuple must hold remain implicit. The agentic turn breaks the existing stack at exactly one point: the free-text channel emitted by an LLM-as-actor has no analogue of ε, no decidable refinement predicate, no compositional bound. Vendor claims of "unified control planes" across operating points spanning nine orders of magnitude in latency are functor-on-objects, same vocabulary at each class, no preserved structure across morphisms. The candidate synthesis: G as a polynomial functor of the operating-point class, with the unification claim becoming an institution morphism in Goguen's sense (Goguen and Burstall 1992), and the federated-agentic problem restated as a sheaf with explicit gluing condition over local sections. The provenance gap is not in any one tradition; it is the absence of a typing of the parameters under which each tradition's guarantees are valid.
2. Problem statement
Status: OPEN. This is a problem statement, not a result. The sections below supply the category, the functor laws, the archetypes, and the questions; none of them closes the problem.
Existing trust-boundary formalisms each type one slot of a four-part governance tuple G = ⟨membrane, access, telemetry-allowlist, action-semantics⟩ and obscure the rest: the actor model, object capabilities, and the π-calculus give topology; Denning lattices and Myers' DLM give qualitative confidentiality and integrity typing; QIF and differential privacy give bits-per-query for structured channels. None types the operating-point class itself, the parameters (Δvol, τ, ρ_individual, ρ_aggregate, fan-out, schema-churn) under which a given G is valid. The provenance gap is the absence of a typing of the parameters under which each tradition's guarantees hold.
The agentic turn breaks the stack at exactly one point: the free-text channel emitted by an LLM-as-actor has no analogue of ε, no decidable refinement predicate, no compositional bound. "Privacy-preserving" agentic claims are therefore unverifiable at the channel level.
3. Thesis
A trust boundary is the same word at every scale and a different mechanism at each. Existing formalisms type the word. None type the scale.
- Governance tuple: \(G = \langle\) membrane, access, telemetry-allowlist, action-semantics \(\rangle\)
- It holds at every operating point. Its enforcement primitives do not transfer.
The four slots. Membrane is the isolation boundary itself: what separates the entity from everything else. The boundary taxonomies in Five Boundaries, Four Isolations live in this slot. Access is who may cross and with what credential. Telemetry-allowlist is what data may leave. Action-semantics is what an action means on the far side and whether it reverses.
4. The existing stack
Five layers, each typing one part of \(G\), each obscuring the rest.
| Layer | Formalism | Types |
|---|---|---|
| Topology | actor model + object capabilities | bounded entity, controlled channel, reference graph |
| Structured channel | IFC (Denning/Myers) | qualitative confidentiality + integrity |
| Quantitative | QIF (Smith 2009) + DP (Dwork 2006) | bits-leaked-per-query, \(\varepsilon\) |
| Agent state | CALM | monotonicity; coordination-free safety |
| Schedules | deterministic simulation testing | invariant-replay under adversarial order |
The stack works for structured channels.
Each layer is a terministic screen in Burke's sense: a vocabulary that selects one slot of \(G\) and deflects the rest. The topology layer sees membranes and reference graphs and says nothing about leakage. The quantitative layer bounds leakage per query and says nothing about what an action means once admitted. Read together they cover all four slots. Read together they still leave the operating-point class unwritten.
The claim that trust boundaries form a category, with operating points as objects and crossings as morphisms, is made precise next.
See also: 3 | 7.1 | Operating-point class | 10
4.1. The typed category
We claim trust boundaries form a category. The claim is not metaphor. A category needs four things: objects, morphisms, identity morphisms, and an associative composition law. We supply each, and we are honest about where the fit is exact and where it is only up to coherence.
4.1.1. Objects: operating points
An operating point is a trust context: a fixed configuration under which claims are evaluated. A tenant, a security zone, a service principal's runtime, a regulatory regime: all are operating points. Each carries a policy that decides which claims it accepts as valid. We write objects as \(A, B, C \in \mathrm{Ob}(\mathbf{C})\). An operating point is static. It does not "do" anything; it is a place where trust has a definite meaning.
4.1.2. Morphisms: boundaries are arrows
A trust boundary is not a wall. A wall is a partition of objects; it has no direction and admits no composition. We model a boundary as an arrow: a directed, type-checked crossing from a source context to a target context. A morphism \(f : A \to B\) is a sanctioned way for a claim asserted in \(A\) to be admitted in \(B\). The direction matters: admission from \(A\) into \(B\) is not admission from \(B\) into \(A\). The set of such crossings is \(\mathrm{Hom}(A, B)\).
4.1.3. Types: what crosses
Each morphism carries a type \(\tau\): the credential or claim being asserted across the boundary. Write \(f : A \xrightarrow{\tau} B\). The type names what \(B\) must believe for the crossing to be sanctioned: an OIDC token with a given audience, a signed attestation, a capability with a scope. This is why the category is typed: morphisms are not bare arrows; they are arrows indexed by the claim they transport.
4.1.4. Composition and the typing discipline
Composition is sequential crossing. Given \(f : A \xrightarrow{\tau} B\) and \(g : B \xrightarrow{\sigma} C\), the composite \(g \circ f : A \to C\) is the crossing that admits an $A$-claim into \(C\) by first admitting it into \(B\), then re-asserting it onward. Composition is partial and type-driven: \(g \circ f\) exists only when the type \(\tau\) that \(f\) delivers into \(B\) is one that \(g\) accepts as its input premise at \(B\). An ill-typed crossing (a token \(B\) cannot exchange for the credential \(g\) requires) has no composite. Ill-typed crossings do not compose. This is the discipline doing real work.
4.1.5. Identity and the axioms
For each object \(A\) the identity \(\mathrm{id}_A : A \to A\) is the trivial crossing: a claim asserted in \(A\) is admitted in \(A\) unchanged, carrying the identity type. It is a left and right unit: \(f \circ \mathrm{id}_A = f\) and \(\mathrm{id}_B \circ f = f\), since prefixing or appending "admit unchanged" alters nothing.
Associativity: for \(f : A \to B\), \(g : B \to C\), \(h : C \to D\), both \((h \circ g) \circ f\) and \(h \circ (g \circ f)\) name the same crossing, which admits through \(A \to B \to C \to D\) in order. Sequencing of admissions is associative because the admission steps are ordered and the parenthesization only groups bookkeeping; the claim transported and the final policy decision at \(D\) are identical. The axioms hold strictly as relations on admissions.
Honesty: if a morphism is taken to be a concrete credential-exchange artifact (a specific minted token, with a nonce or timestamp), then \((h \circ g) \circ f\) and \(h \circ (g \circ f)\) yield artifacts that are equal only up to a coherent isomorphism (re-minting), not on the nose. Read that way \(\mathbf{C}\) is a bicategory / category up to coherent iso. We work in the strict quotient, which identifies crossings that admit the same claim under the same policy, and there associativity is exact.
4.1.6. Worked example
Three contexts: edge (E), app (A), db (D). A request bearing a session
JWT crosses from edge to app; the app exchanges it for a scoped DB capability
to reach the database.
jwt cap
E ---------> A ---------> D
\ ^
\ cap∘jwt |
\_____________________|
(composite)
The lower arrow is \(\mathrm{cap} \circ \mathrm{jwt} : E \to D\). The triangle
commutes: admitting an edge request straight to the DB capability equals
going through the app, provided the types line up: jwt delivered at A is
exactly what the cap mint at A consumes.
jwt scope:read
E ---------> A -----------------> D
scope:write
E ---------> A -----------------> D'
If E instead carries a read-only jwt but the onward arrow demands
scope:write, no composite exists: the crossing is ill-typed and the diagram
does not commute. The boundary did its job by failing to compose.
5. The break
The agentic turn breaks the stack at exactly one point.
The free-text channel emitted by an LLM-as-actor has no analogue of \(\varepsilon\), no decidable refinement predicate, no compositional bound.
Structured channels compose. The text channel does not, yet.
Consequence: "privacy-preserving" agentic claims are unverifiable at the channel level.
- A tool call is auditable. A side effect is auditable. The sandbox decompositions in Agent Sandbox Architectures bound the filesystem, network, and compute channels one cell at a time.
- The text the model emits is the one channel with no leakage bound.
- Every guarantee above the text channel inherits its unboundedness.
In the language of 4.1: an agentic crossing is a morphism whose type \(\tau\) is "whatever the model said." No policy at the target can decide whether to admit it, so the composite with any onward crossing is undefined. This is why the morphism map of 7.1 cannot be written down for agentic hops.
6. The missing type: operating-point class
No current label system types the class a boundary operates in.
\[ \text{class} = (\Delta\text{vol},\ \tau,\ \rho_{\text{individual}},\ \rho_{\text{aggregate}},\ \text{fan-out},\ \text{schema-churn}) \]
ingest rate, latency, per-individual sensitivity, aggregate sensitivity, fan-out, schema churn.
The provenance gap: the parameters under which each tradition's guarantee is valid are never written down. Differential privacy's composition theorem holds for a stated ε and a stated query count. Nothing in the label says what ingest rate or fan-out that ε was calibrated against. A class is the missing index: the point in this six-dimensional space at which a given \(G\) is asserted, and outside which the assertion has no stated validity.
Whether the six parameters are independent axes, and whether a class is a quotient of the continuous space by threshold strata, is 10 item 4.
7. "Unified" is vocabulary, not mechanism
Cross-class platform claims spanning many orders of magnitude reuse one vocabulary at every class.
- Same vocabulary at each object. No structure preserved across morphisms.
- Categorically: functorial on objects, not on morphisms.
- "Unified control plane" is the (unproven) claim that a single functor \(F: \mathbf{C} \to \mathbf{Gov}\) satisfies the functor laws.
Stated fully: a unified platform asserts a functor \(F: \mathbf{C} \to \mathbf{Gov}\), where \(\mathbf{C}\) is the typed category of operating points and trust crossings and \(\mathbf{Gov}\) is governance tuples under refinement, and asserts that \(F\) satisfies the functor laws. "Unified" is exactly that assertion, and each failure is a square that does not commute. The laws, and the squares, follow.
See also: 4.1 | 3 | Operating-point class | Archetypes
7.1. Functorial requirements
The preceding sections give us two categories. C (4.1)
has operating points as objects and trust crossings as morphisms. Gov has
governance tuples G = <membrane, access, telemetry-allowlist, action-semantics>
(3) as objects and refinement relations as morphisms: G ⊑ G' when
every slot of G' is at least as tight as the same slot of G. Slot-wise
join and meet make Gov a lattice. This section states the structural claim
that connects them: a "unified" cross-class platform is exactly a functor
F: C -> Gov, and "unified" is the assertion that F satisfies the functor
laws.
A functor needs two maps. An object map sends each operating point p to its
governance tuple. A morphism map sends each trust crossing f to a tuple
transformation. Both maps must preserve identities and composition. Nothing
else. The discipline of this section is to take those two laws literally and
read them as compliance obligations.
7.1.1. The functor F
Object map. F sends an operating point p to the governance tuple of its
operating-point class class(p) (6),
the point (Δvol, τ, ρ_individual, ρ_aggregate, fan-out, schema-churn) at which
p runs:
F(p) = G_{class(p)} = <membrane, access, telemetry-allowlist, action-semantics>_{class(p)}
Morphism map. A trust crossing f: p -> q is sent to a tuple transformation
F(f): G_{class(p)} -> G_{class(q)} in Gov. F(f) is the governance change
the platform actually imposes when a principal crosses from p into q:
a membrane change (new isolation boundary), an access change (re-authentication,
scope narrowing or widening), a telemetry-allowlist change (what may now leave),
an action-semantics change (what an action means and whether it reverses).
F(f) is what the platform does at the boundary; the laws below constrain
what it is allowed to be.
7.1.2. Law 1: identity preservation
For every operating point p, C has an identity crossing id_p (staying put;
4.1). The law requires:
F(id_p) = id_{G_class(p)}
Operationally: remaining within a context imposes no governance change. No spurious re-auth, no silent scope shift, no tuple mutation for a no-op. If a principal does nothing, its governance tuple is exactly the one for its class.
Identity failure: a no-op crossing that silently alters the tuple. A session
left idle inside one context gets its access slot quietly widened by a
token-refresh path, or its telemetry-allowlist dropped. F(id_p) ! idG_k=.
The "do nothing" arrow moved in Gov. The platform is not a functor.
7.1.3. Law 2: composition preservation
For composable crossings f: p -> q and g: q -> r, C has the composite
g∘f: p -> r (4.1, composition is associative). The law
requires:
F(g∘f) = F(g) ∘ F(f)
Operationally: the governance of a multi-hop crossing equals the composite of
the per-hop governance. Going p -> q -> r as one declared journey must land on
the same tuple as doing the two hops in sequence. There is no shortcut whose
governance is weaker than the path it stands in for.
Composition failure: governance launders away across a hop. Each hop looks
locally compliant, but the composite is not. Canonical case: a dev-class
operating point composes with a deploy crossing that, per hop, looks like a
narrowing of the access slot, yet the composite reaches prod credentials.
F(g∘f) grants prod scope; F(g) ∘ F(f), honestly composed, would deny it.
The composite tuple is strictly below where refinement should place it.
7.1.4. Tie to monotonicity
Order Gov by refinement and expect a crossing into a higher-trust class to
move up the lattice (tighten every slot), never down: k ≤ k' implies
G_k ⊑ G_{k'}. Functoriality makes that expectation checkable. If every
crossing is monotone in Gov, then F(g) ∘ F(f) is monotone, so F(g∘f)
must be too. A laundering composite that lands below both hops violates
monotonicity and composition at once. The two diagnoses coincide: a downward
composite is a broken law, not an edge case.
7.1.5. The commuting square
Take crossings f: dev -> staging and g: staging -> prod. The square that
must commute:
F(f) F(g)
G_dev ----------> G_staging ----------> G_prod
| ^
| |
+------------------ F(g∘f) --------------+
COMMUTES iff F(g∘f) = F(g) ∘ F(f)
When it commutes, the direct dev->prod journey and the two-hop path produce the identical prod tuple. A genuinely unified control plane makes this square commute for every composable pair across every class boundary — consumer and regulated, dev and prod, internal and partner.
Where it fails:
per-hop path: G_dev --narrow--> G_staging --narrow--> G_prod (access: none)
direct path: G_dev --------- F(g∘f) ---------------> G_prod' (access: prod creds)
G_prod != G_prod'
The platform advertises one F. The square does not commute. "Unified" is
false here not as a matter of policy taste but as a matter of arithmetic: two
paths in C with the same source and target map to two different objects in
Gov. A single well-defined F cannot send one morphism to two tuples.
7.1.6. What "unified" claims, restated
A cross-class "unified" platform claims a single F that is total: defined on
every operating point and every crossing, one control plane spanning all classes
at once. That claim is precisely the claim that F is a well-defined functor
— total, identity-preserving, composition-preserving. The seed's sharper
diagnosis is that vendor platforms are functorial on objects only: the object
map exists (a tuple per class, the same vocabulary at each), and the morphism
map does not. 8 grounds this: each
archetype is an object F must cover, and each enforcement primitive that fails
to transfer between rows is a morphism F cannot define.
8. Four archetypes across operating points
One governance tuple \(G\). Nine orders of magnitude in latency, eight in volume (\(10^1\) to \(10^9\) records per day). Three of the four are radar or feed archetypes; PetClinic is the low-volume, high-sensitivity control.
| Archetype | Latency \(\tau\) | Volume \(\Delta\)vol | Dominant risk |
|---|---|---|---|
| PetClinic visits | seconds | ~10¹/day | per-individual PII |
| Arctic tick store | minutes to hours | ~10³ | aggregate inference |
| AeroAPI / ADS-B | ~1 s | ~10⁶ | fan-out, schema churn |
| HFT feed | microseconds | ~10⁹ | τ, action-semantics |
Same \(G\). The enforcement primitives that work at one row are unavailable at the next. A per-record consent check that is free at ten records a day is unaffordable at a billion; a microsecond kill-switch that defines action-semantics for the HFT row has no meaning for a veterinary visit. Each row is an object \(F\) must cover. Each primitive that fails to transfer between rows is a morphism \(F\) cannot define.
9. Candidate composition frames
What could make \(G\) compose across class?
- Polynomial functors (Spivak and Niu): \(G\) as a poly functor of the class; positions and directions carry the interface.
- Open games (Ghani, Hedges, Winschel, Zahn): governance as a lens; play and coplay across a hop.
- Institutions (Goguen and Burstall): the unification claim as an institution morphism between per-class governance logics.
- Sheaves over local sections (Curry): federated agents as local sections; the gluing condition is the unification test.
None shown to fit. This is the work.
10. Open problems
The questions were produced by applying the paper-analysis framework in gist
jensengrey/23c46e1f to the seed, with each question grounded in a five-agent
cross-reference of the existing site. The cross-reference found anchors for
two of them and none for the rest.
- Is the free-text channel's unboundedness a theorem or an open
construction? The seed states the LLM free-text channel has "no analogue
of ε, no decidable refinement predicate, no compositional bound." Is this a
claim of non-existence (provably no compositional QIF bound can exist for
an expressive text channel), or a claim of current absence (none is
known)? The distinction sets the whole research program: the first is an
impossibility result to prove; the second is a construction to attempt.
The site has ε-DP for structured channels (
static/js/adtech/clean-room.js) and nothing on the text channel. - What are the positions and directions of the polynomial functor G? "G as a polynomial functor of the operating-point class" needs its Poly data named: what set indexes positions, and what is the direction set at each position? Does the four-slot tuple sit in positions, directions, or the operating-point base? Retraction: the seed's original citation for this frame was Spivak's Seven Sketches, which does not cover Poly. The intended reference is Niu and Spivak, Polynomial Functors: A Mathematical Theory of Interaction (Niu and Spivak 2023).
- Which institution makes "unified" an institution morphism? Goguen and Burstall's institutions are (signatures, sentences, models, satisfaction ⊨). To make a unified platform an institution morphism, name these four for governance: what is a governance signature, what are its sentences, what are its models, and what is ⊨? The cross-reference found zero supporting material on the site for this claim. It is the most unsupported item in the seed.
- Are the six operating-point parameters orthogonal, and how do continuous parameters yield discontinuous obligation? Are (Δvol, τ, ρ_individual, ρ_aggregate, fan-out, schema-churn) independent axes, or do some determine others (does τ bound fan-out)? Obligation jumps discontinuously (consumer to regulated) while the parameters are continuous. Is a class a quotient of ℝ⁶ by threshold strata, and where do the thresholds come from: physics, regulation, or modeling choice?
- What is the sheaf's base space, and what is the gluing obstruction under adversarial local sections? Name the base (operating points, or a topology on them) and the sections (local governance assignments). When two agents' local sections disagree on an overlap, is the failure to glue a genuine cohomological obstruction (H¹ ≠ 0), and is that obstruction the formal content of "the enforcement primitives don't transfer"? A site anchor exists: the wwn sheaf model already builds sections and fibers over a base.
- Is "requisite variety of control planes" Ashby taken literally? Does the seed mean Ashby's law quantitatively: a control plane's variety must match the variety of the operating-point space it governs, so a single unified plane is necessarily under-varied across nine orders of magnitude? If so, this is an information-theoretic lower bound on control-plane count, not a metaphor. Neither "requisite variety" nor "terministic screens" (Burke) has an anchor on the site.
- Locality-of-loop as a formal property of an agent. The deck lists it; the questions above do not reach it. What predicate on an agent's observe-act loop says the loop closes inside one operating point, and does that predicate compose across a crossing?
The ask. A trust boundary is an arrow, not a wall. We have the topology, the structured-channel bits, the monotonicity. We are missing a bound on the text channel, and a typing of the class the bound must hold in. Everything else is composition.
11. Provenance
- Seed: the 1 above, D5 of the FM x Systems Design Lab (two-day: Hewitt and π-calculus; IFC and QIF; agentic FM with CALM, DST, DSPy, Liquid; category-theoretic synthesis and the algebraic-topological angle; operating-point-indexed governance).
- Draft scaffold: five section files written before the seed. Two are carried here as includes (4.1, 7.1), re-slotted to the four-part tuple. Three are dropped: they defined a five-slot tuple, a qualitative six-class taxonomy, and invented archetypes, all superseded by the seed.
- Questions: the paper-analysis framework in gist
jensengrey/23c46e1f, applied to the seed. - Site cross-reference: five grep audits over the corpus. Anchors exist for ε-DP on structured channels and for sheaf sections over a base. No anchors for institutions, terministic screens, or requisite variety.