statements ยท statement-BATCH-2026-003-024

source-BATCH-2026-003-002

Organizations should classify access by the potential impact of misuse and apply controls proportionate to the resulting risk tier.

Statement context

Statement type
strategic framework
Exact source locator
Chapter 5 > Classifying Access Based on Risk
Source date
2020-04-08
Role at source time
Named book author or chapter contributor
Evidence character
Risk-tiering framework
Scope
Privileged operations

Indexed source: Building Secure and Reliable Systems: Best Practices for Designing, Implementing, and Maintaining Systems

Evidence lineage and transparency

Relationship fieldLinked identifiers
topic idstopic-ai-agents, topic-ai-governance, topic-cybersecurity, topic-non-human-identity, topic-enterprise-infrastructure

Machine review: ready for human review. Human review: approved. Workflow: published.

Complete structured record
statement id
statement-BATCH-2026-003-024
source id
source-BATCH-2026-003-002
person id
Unknown
institutional author
Oliver Barrett, Aaron Joyner, and Rory Ward, with Guy Fischman and Betsy Beyer
book edition id
book-edition-BATCH-2026-002-007
speaker role at source time
Named book author or chapter contributor
organization at source time
Unknown
statement type
strategic_framework
neutral paraphrase
Organizations should classify access by the potential impact of misuse and apply controls proportionate to the resulting risk tier.
direct quote
Unknown
direct quote rights note
No direct quotation used; original OEII paraphrase only.
exact locator
Chapter 5 > Classifying Access Based on Risk
locator type
chapter_section
source date
2020-04-08
topic ids
topic-ai-agents, topic-ai-governance, topic-cybersecurity, topic-non-human-identity, topic-enterprise-infrastructure
executive role context
CISO, CIO, CTO, CEO, General Counsel, Board Director
industry context
Technology, Financial services, Healthcare, Public sector, Critical infrastructure
geographic context
Primarily United States and global technology operations
evidence character
Risk-tiering framework
factual verification status
Verified against the exact locator in the complete edition
statement scope
Privileged operations
uncertainty
Unknown
extraction method
Manual semantic extraction after complete-edition reading, followed by locator replay and separate review pass
machine extraction confidence
0.94
independent agent review status
Pass after independent-review correction
publication status
published
workflow status
published
machine review status
ready_for_human_review
human review status
approved
reviewed by
Murray Newlands
reviewed at
2026-08-16T23:17:22Z
Provenance and revision history
{
  "provenance": [
    {
      "source_url": "https://google.github.io/building-secure-and-reliable-systems/raw/ch05.html#classifying_access_based_on_risk",
      "accessed_at": "2026-08-15",
      "retrieval_method": "Complete exact edition retrieved from an official public source and reviewed in full",
      "exact_locator": "Chapter 5 > Classifying Access Based on Risk",
      "content_hash": "6bf5050c08be0bced81767ac14bd9b3303e34b3efb667806b3c9e9d6b0ed8cf1",
      "batch_id": "BATCH-2026-003",
      "prompt_id": "OEII-BOOK-DEEP-ANALYSIS",
      "prompt_version": "2.0",
      "notes": "Locator replayed; paraphrase checked for attribution and scope"
    }
  ],
  "revision_history": [
    {
      "changed_at": "2026-08-15T00:00:00Z",
      "changed_by": "independent machine review response",
      "summary": "Removed a specific control list not established by the access-classification section.",
      "batch_id": "BATCH-2026-003"
    },
    {
      "changed_at": "2026-08-16T23:17:22Z",
      "changed_by": "Murray Newlands",
      "summary": "Approved for the governed-identities pilot release under the exact scope, exclusions, rights treatment, and limitations recorded in issue #18.",
      "batch_id": "BATCH-2026-003"
    }
  ]
}

Open machine-readable record