Relational Zero-Trust: Re-erecting the Premises at the Accountability Layer — An Open Drawing Convention for Online Provision
Abstract
Zero-trust architecture was founded on the abandonment of a metaphor: the castle-and-moat was declared dead, the perimeter dissolved, and trust relocated from network location to continuously verified identity. This paper argues that the metaphor was rightly abandoned at the technical layer and wrongly abandoned at the accountability layer. Machines do not need walls to verify identity; humans need walls to understand who is responsible for what. When a school's premises become software, as in fully online alternative provision, the governing question is not only whether every request is verified, but whether the people accountable for children can see, contest, and inspect the architecture that verifies them. We present Relational Zero-Trust as a design stance, and an open drawing convention (Drawing Nos. OAP-001 and OAP-002, CC BY 4.0) that expresses a zero-trust specification in the language of a building: rooms, gates, valves, seals, an inspection chamber, and a revision table naming who has standing to change the drawing. A crosswalk maps the convention to the NCSC zero-trust design principles and NIST SP 800-207. The convention is situated within the Verse-ality research programme on school-grade safety for AI systems. The drawings themselves, their editable sources and the zero-trust crosswalk are published openly under CC BY 4.0 at https://github.com/TheNovacene/open-provision-drawings
// Source
Authors: Kirstin Stevens, The Novacene Ltd