AEGIS Risk Scoring Model

Architectural Enforcement & Governance of Intelligent Systems

Version: 0.2
Status: Informational
Part of: AEGIS Architecture
Author: Kenneth Tannenbaum
Last Updated: March 6, 2026


Purpose

This model defines how risk is represented conceptually and mapped to governance outcomes. Numerical implementation details are specified in:

Risk Model Dimensions

Risk is determined by five dimensions:

  1. Actor trust posture.
  2. Capability intrinsic risk.
  3. Resource sensitivity.
  4. Environment modifier.
  5. Behavioral history modifier.

These dimensions provide contextual risk beyond static permissions.

Risk Bands

BandScore RangeMeaningDefault Outcome
Low0-30Routine, bounded operationALLOW
Medium31-60Elevated but manageable riskCONSTRAIN
High61-80Significant risk requiring oversightESCALATE
Critical81-100Unacceptable riskDENY

Conceptual Risk Factors

Actor Trust

Capability Risk

Resource Sensitivity

Environment Modifier

History Modifier

Risk-to-Governance Mapping1

Risk is advisory to policy, but binding to outcome thresholds.

Model Invariants

  1. Risk score must remain in bounded range [0, 100].
  2. Same risk inputs must produce same score.
  3. Missing high-impact factors cannot default to low risk.
  4. High and critical bands must produce non-allow outcomes.

Operational Uses

Risk outputs are used for:

Calibration and Drift Control

Model maintenance requirements:

Verification Criteria

The risk model is considered healthy when:


References

Footnotes

  1. National Institute of Standards and Technology, Zero Trust Architecture, NIST SP 800-207, Aug. 2020. [Online]. Available: https://doi.org/10.6028/NIST.SP.800-207. See REFERENCES.md.