AEGIS Risk Scoring Model

Architectural Enforcement & Governance of Intelligent Systems

Version: 0.2
Status: Informational
Part of: AEGIS Architecture
Author: Kenneth Tannenbaum
Last Updated: March 6, 2026


Purpose

This model defines how risk is represented conceptually and mapped to governance outcomes. Numerical implementation details are specified in:

Risk Model Dimensions

Risk is determined by five dimensions:

  1. Actor trust posture.
  2. Capability intrinsic risk.
  3. Resource sensitivity.
  4. Environment modifier.
  5. Behavioral history modifier.

These dimensions provide contextual risk beyond static permissions.

Risk Bands

Band Score Range Meaning Default Outcome
Low 0-30 Routine, bounded operation ALLOW
Medium 31-60 Elevated but manageable risk CONSTRAIN
High 61-80 Significant risk requiring oversight ESCALATE
Critical 81-100 Unacceptable risk DENY

Conceptual Risk Factors

Actor Trust

Capability Risk

Resource Sensitivity

Environment Modifier

History Modifier

Risk-to-Governance Mapping1

Risk is advisory to policy, but binding to outcome thresholds.

Model Invariants

  1. Risk score must remain in bounded range [0, 100].
  2. Same risk inputs must produce same score.
  3. Missing high-impact factors cannot default to low risk.
  4. High and critical bands must produce non-allow outcomes.

Operational Uses

Risk outputs are used for:

Calibration and Drift Control

Model maintenance requirements:

Verification Criteria

The risk model is considered healthy when:


References

Footnotes

  1. National Institute of Standards and Technology, Zero Trust Architecture, NIST SP 800-207, Aug. 2020. [Online]. Available: https://doi.org/10.6028/NIST.SP.800-207. See REFERENCES.md.