Compatibility: Pactmark 0.1.x. No row on this page transfers legal, regulatory, security or
availability responsibility to a framework test result.
The matrix
Reading it correctly
The left column is a set of mechanisms. The right column is a set of decisions and running systems. Mechanisms do not run themselves.Identity — the most commonly misread row
Identity — the most commonly misread row
Pactmark gives you
AuthorityContext, Principal, Tenant, AuthenticationStrength and
DecisionRole, and enforces that every store and command carries them.It has no opinion about whether your IdP correctly told you that this person is a finance
approver. If that mapping is wrong, every downstream control faithfully enforces the wrong
answer.Models — the contract is yours
Models — the contract is yours
The model security profile records provider, region, retention, logging and training as a
digested claim. Pactmark cannot verify that your provider honours it. The
contractReference
field exists so a reader can go and check.Tools — the blast radius is yours
Tools — the blast radius is yours
Policy decides whether a tool may run. What that tool then does to your production database is a
property of your implementation. A correctly authorised destructive tool is still destructive.
Durability — the mechanism is not the service
Durability — the mechanism is not the service
Fenced leases and atomic command units are correct. They run on a database you operate, back up
and fail over. Local crash tests are design evidence, not a promise about your topology.
Artifacts — addressing is not truth
Artifacts — addressing is not truth
Content addressing guarantees you are looking at the same bytes. It says nothing about whether
those bytes are correct, and verification only checks what its rubric names.
Operations — primitives are not a practice
Operations — primitives are not a practice
/healthz, /readyz, stable error codes, an effect ledger and a replay command are primitives.
Someone still has to be paged, and someone still has to resolve parked effects.Three specific things you own that people assume are handled
Your risk-class mapping
Pactmark ships R0–R5 and refuses to define them. If R4 means the wrong thing in your policy,
everything below it is precisely wrong.
Grant breadth
An allowed model action can still be undesirable inside an over-broad host grant. Nothing in the
framework narrows a grant you issued too widely.
What evidence is used for
Threat model row TM-18 names misrepresentation of evidence as a high risk. Human marketing or
governance misuse cannot be prevented in code.
Using this in a review
1
Assign a named owner to every right-hand cell
A team name is not an owner.
2
Link environment-specific evidence to each one
Not a link to this documentation. Evidence from your environment.
3
Cross-check against the limits page
Anything on what Pactmark does not prove that you were relying on is a gap,
not a nuance.
4
Re-run it when the architecture changes
New adapter, new provider, new data class, new platform — the matrix moves.
Readiness checklist
The operational form of this matrix.
Threat model
Owners and residual risk for each high and critical row.