/technical-appendixTechnical appendix

The architecture,boundaries andintegration model.

A public, ungated reference for architecture, security and assurance reviewers. It describes conceptual patterns and boundaries. It does not claim specific production deployments, connectors or certifications.

Public & ungatedArchitectureIntegrationAssurance
01

Platform architecture

Institutional Role Nodes, a Role-to-Role lifecycle protocol, the Control Decision Envelope, a shared proof & receipt layer, and execution / interoperability adapters. KATLAS records the governed action — it is not a central store of raw private evidence.

02

Control Decision Envelope

A standardisable object consumed before a consequential action executes, expressing authority, policy, evidence references, decision and privacy boundary. Outcomes: allowed, blocked, review required, released, refused.

03

Data custody and trust boundaries

Evidence remains with its custodian. Only metadata, roles, permissions and evidence references cross the boundary. Raw private data and withheld assets are never sent to the node.

04

Authority and policy model

Stakeholder-defined roles, mandates, scopes and purposes. Authority gates are explicit and visible. Policy and current-state conditions are evaluated at the point of action. Institutional policy and authorised roles decide; KATLAS makes that boundary executable.

05

Receipt model

A public-safe receipt records who acted, when, under what authority, which evidence references were used and what was withheld — with a verification status. Full signed envelopes are not exposed publicly.

06

Integration patterns

Conceptual patterns only — REST APIs, backend-only authentication, execution adapters, and event / webhook integration where actually supported. Standards examples where relevant: ISO 20022 (value movement) and FHIR (health records). No specific production APIs or connectors are claimed here.

07

Authentication and secrets

Any node credential is backend-only (server-side). The public website never holds or requests it, never calls the signing node, and never generates signed receipts. Legacy credential aliases are prohibited.

08

Deployment modes

Showcase, governed sandbox and pilot. Simulated operation demonstrates governed journeys with synthetic data; live-node operation is provisioned separately and never runs on the marketing site.

09

Sandbox model

A synthetic but realistic governed journey with separate role identities and devices. Access is provisioned on request via a governed process — not self-serve — until automated, governed provisioning exists.

10

Pilot acceptance framework

One bounded problem and one consequential handoff, with agreed acceptance criteria and the measurement framework below. Outputs: role-network blueprint, receipt model and operational acceptance evidence.

§ measurementPilot measurement framework

Pilots are measured against agreed categories rather than pre-stated ROI figures. KATLAS does not claim to have achieved these outcomes unless evidence is supplied.

Time from exception to accountable owner

First-time condition pass rate

Manual reconciliation steps

Time to prove readiness

Unresolved authority exceptions

Evidence shared versus withheld

Receipt verification rate

Time from proposed change to safe release

Controlled documents · available on request

Placeholder

Sample statement of work (SOW)

Provided under NDA during a pilot engagement — not published here.

Placeholder

Data processing agreement (DPA) template

Provided under NDA during a pilot engagement — not published here.

Placeholder

Security questionnaire pack

Provided under NDA during a pilot engagement — not published here.

Placeholder

Pricing options

Provided under NDA during a pilot engagement — not published here.

Placeholder

Detailed pilot acceptance criteria

Provided under NDA during a pilot engagement — not published here.