Module 4 · The Authority Layer

Lecture 4.1

The Reference Architecture

The discipline builds many parts — decomposed rules, compiled artifacts, verification records. This lecture assembles them into one named model: six layers running from the authoritative source to the institutional record, with a clear statement of what each layer is responsible for and where authority actually becomes operational.

Supports Law 4Authority Must Precede Automation.
Lesson 21 / 39Start the course to keep your place and get the rest by email.

Learning objectives

After this lesson, the reader should understand:

  • 01Name the six layers of the reference architecture and the question each answers.
  • 02Locate where existing Law-as-Code work sits, and where computable authority adds.
  • 03Identify the layer at which an institution's authority becomes machine-operational.

Concept framework

Six layers

  1. 01Authoritative sources — statutes, regulations, institutional policy, delegations
  2. 02Computational representation — rules, conditions, exceptions, evidence requirements
  3. 03Authority artifact — issuer, scope, delegation, version, constraints, integrity
  4. 04Runtime authorization — agent, action, context, evidence presented for evaluation
  5. 05Deterministic decision — authorised, denied, or escalated, by declared semantics
  6. 06Institutional record — what was decided, under which authority, on what evidence

Case study

Where the boundary actually is

An institution has machine-readable rules and an audit log. It says its AI decisions are governed. Which layers does it actually have?

Usually two: a computational representation and an institutional record, with the four layers between them missing. The rules are readable but not issued under a versioned authority artifact; the runtime evaluates them but carries no representation of the delegation or the evidence boundary; the decision is produced by a model's response rather than by declared execution semantics; the log records outcomes it cannot reproduce. The architecture is not a maturity ladder to climb slowly — the middle four layers are where authority becomes operational, and an institution that skips them has automated interpretation, not governed it.

Discussion questions

  • Can the layers be adopted incrementally, or do the middle four only work together?
  • Which layer does your sector's current 'digital rulebook' work actually reach?
  • Who owns each layer inside an institution — and what breaks when one owner is missing?
  • Is the institutional record a byproduct of the architecture or a design input to it?

Exercise

Map one governed decision onto the six layers.

  1. 01Name the authoritative source and the instrument version.
  2. 02Describe the computational representation and who maintains it.
  3. 03State whether an authority artifact exists, and what metadata it carries.
  4. 04Describe the runtime request: agent, action, evidence.
  5. 05Identify which layer, today, is absent or informal.

Research notes

  • Reference architectures in regulated-systems engineering.
  • Law as Code — pipeline models from source to executable rule.
  • Policy decision point / enforcement point separation in access architectures.
  • OECD consultation on the Digital Provision of Law — shared reference framework goals.
  • Computable Authority, §7 — 'The Reference Architecture'.