Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

KRYOS-XS Hypercube method

Policy and Authority Evaluation

Before any action is prepared, the engine determines whether policy permits it and which named role is entitled to approve it.

What it is

The method in plain terms

Authority is modeled explicitly: which role may approve which class of action, at what consequence threshold, and with what separation between requesting, approving, and executing.

Actions outside policy are never prepared for execution. Actions inside policy are routed to the correct approver with the evidence attached.

Why it matters

In organizations without a security function, authority is ambiguous and decisions default to whoever is present. Making authority explicit is what converts an ad hoc reaction into a governed decision.

Applied

How it is used in a nonprofit environment

  • Ensuring an action affecting field staff safety reaches a duty-of-care approver, not only the IT lead
  • Preventing a single person from requesting, approving, and executing a high-consequence change
  • Providing an approval record that satisfies audit and trustee oversight

Limits

Where the method stops

  • The model reflects the authority structure the organization defines
  • The overlay cannot compel an organization to follow its own policy outside the systems it mediates

Policy and authority configuration is owned by the grantee. The overlay enforces the organization's model rather than imposing one.