Skip to main content

DEFENSE-POSTURE

Layer 2 Procedural File 4 of 6 — The Dash / NornGate at SBS Maps every design decision to the exposure surface it defends.

Purpose

The Dash is not designed for elegance; it is designed to make SBS’s posture defensible — against FCC scrutiny, SOX control-environment review, customer disputes, audit inquiry, and litigation discovery. This file maps the surfaces to the mechanisms.

The Defense Surfaces

Exposure surface

The threat

The operational defense

FCC license & political file

Missed political-file windows, lowest-unit-charge violations, late filings — license risk

Frigg’s statutory clocks (categorical inside her frame); Urd’s sealed proof of timely action; SEV-1 escalation on any statutory breach in progress

SOX control environment

SBS is publicly traded; weak ITGC or unverifiable figures undermine §302/§906 certifications

Sif’s verify-don’t-correct reconciliation; Njord’s permitted flows; Thor’s checkpoints; the four-record sequence; seven-year WORM retention

Customer billing disputes

Double-charges, disputed invoices, missing orders

Thor’s idempotent execution (one double-charge = breach of contract); order-to-cash four-record linkage from order to deposit

Data privacy & access scrutiny

Over-broad access, unlogged reads, surveillance drift

Heimdall’s G0 verification; Tyr’s ABAC with no internal exceptions; audit-of-audit (every access is itself a record); aggregate-only pattern detection

AI-use disclosure

State AI laws and FTC posture on undisclosed AI acting for the company

Take-Notice (root canonical); Baldr’s AI-origin disclosure enforcement; Bragi’s mandatory disclosure slots

HR / payroll data (ADP)

Sensitive employee data exposed to automation

Domain-scoped Mimir access; Tyr’s least-privilege brokering; no standing credentials anywhere

Concentrated authority

Single-approver collapse; unmanaged break-glass

Single-Maintainer-Appendix: roster, dual-agent attestation (reversible only), capacity notation, monthly break-glass review

What’s Not a Defense

The Dash does not defend against:

           Substantive financial error. If a figure is wrong on the substance, the ledger captures the wrong number faithfully. The trail is not a correctness check; Sif flags substance, humans decide it.

           Human-approved malfeasance. If a human approves a bad action, G2 records the authorization — it does not invalidate it. Human sign-off retains all authority and all liability.

           The LaMusica blind spot. The closed boundary means the fleet sees nothing inside LaMusica. That blindness is deliberate constitutional design — and it is disclosed as a blind spot, not papered over as coverage.

           Content error that passes validation. A Bragi draft can be G3-valid and still wrong on the merits; the trail captures what was validated, not whether the validator was right.

           Legacy-system failure. If WideOrbit or Oracle fails to execute its side, the sequence captures the failure; remediation is operational, not defensive.

The Dash’s defense is procedural integrity, not substantive correctness. Substantive correctness depends on agent competence and — finally — on human judgment. Every mechanism in this table exists to make that division of responsibility provable.

Authoritative For

Board and counsel review of the fleet’s posture; auditor orientation; incident-response framing; oversight-package narrative.

What’s Not Here

Mechanisms themselves (10-Audit-Trail-Spec, 10-Governance-Gate-Spec); incident classification (00-Incident-Response-Matrix).

Modification Protocol

Proposal drafted by the responsible agent → legal/sufficiency review where statutory interpretation is implicated → Odin staffs the synthesis pass → G2 request with full evidence package → human decision per the Single-Maintainer-Appendix authority structure. Approved modifications are versioned (1.0 → 1.1 minor; 1.x → 2.0 material) and captured in Urd’s ledger as policy_change-class records. Layer 1 files are not modified by this protocol — they require SBS Board / IT Governance authorization via Asgard Policy Review.


Document Control: SBS-DASH-PROC-04 · v1.1 · 2026-08-05 · SHA-256 (content above): 43e8…31a9 · Sealed under Audit-Trail-Spec § 8.2. Modification authority: SBS Board / IT Governance via Asgard Policy Review (Governance-Gate); revalidation propagates per Tyr-SKILL § 3.4.