01 / Research

Authorization as a research question.

From deterministic access rules to explainable, policy-bounded adaptation. A research program grounded in comparison, transparency and reproducibility.

The problem

Decisions in changing systems.

Research Problem

Cloud-native distributed systems make access decisions while identities, request context and operational conditions change. Roles and attributes provide explicit policy boundaries, but understanding how authorization should respond to abnormal behavior remains a research challenge.

AegisAI investigates whether behavioral evidence and operational system state can inform useful adaptations while preserving deterministic constraints and understandable decisions. The benefits and tradeoffs remain to be tested.

Research Question

How does explainable, policy-bounded, closed-loop adaptive authorization perform relative to RBAC, ABAC and deterministic risk-aware authorization under behavioral and operational anomalies in cloud-native distributed systems?

Comparative foundation

Baselines

Implementation status refers to the separate AegisAI research/application repository. This portal presents the research program.

Model A

RBAC

Role-based access control establishes the deterministic authorization baseline.

Implemented
Model B

RBAC + ABAC

Attribute-based conditions extend role-based authorization with request context.

Implemented
Model C

Contextual Risk

Deterministic contextual risk adds explicit risk rules to role-based authorization.

Implemented
The next investigation

Proposed Model D

Planned Research

RBAC + ABAC + behavioral adaptive risk. The proposed model investigates behavioral intelligence, operational state and continuous feedback within explicit authorization policy boundaries.

AI-derived evidence would inform a decision; deterministic policy would constrain the available actions. The research must establish whether this approach improves security outcomes and at what operational cost. Model D is not implemented.

How we investigate

Research Principles

01

Policy remains explicit

Investigate adaptation constrained by deterministic rules and reviewable decision boundaries.

02

Evidence before claims

Separate implemented capabilities, planned designs and experimentally supported findings.

03

Explain the decision

Make the contributing policy, context and proposed risk evidence understandable to reviewers.

Open methodology

Reproducibility

The intended experimental program compares models under documented scenarios and controlled conditions. Methods, configurations and limitations should accompany results so others can assess and reproduce the work.

View the experimental plan →
In Preparation

Research hypotheses

Research hypotheses will be published after the research specification is finalized.