Consent & Privacy Service  ·  View 22 of 22  ·  Assurance

Failure Classes

Ten classes, what catches each, what bounds it, and what it costs when the bound fails. Two of them are chosen rather than suffered.

Editable source SVG draw.io All views
Caught by Bounded by Cost when the bound fails Decision plane unreachable cache staleness age per-purpose posture purposes deny; reads degrade Stale consent at the edge lag per enforcement point 15 min ceiling unlawful processing, reportable Partial erasure four-state per target case stays open statutory deadline missed Silent target no ack in window treated as failed a closed case that is not done Resurrection after erasure absence probing suppression on ingest the subject is back, and knows Identity resolution miss post-case re-resolution case reopens erasure that looked complete Jurisdiction misdetermined versioned determination audited re-location unlawful transfer Forged grant anomaly scoring surface + actor on entry processing legalised by an attacker Regional isolation regional health no cross-border failover region-wide denial, by design Control plane unavailable bundle age last-known-good snapshot no new purposes; decisions continue Failure Classes — What Catches Each, and What It Costs The last two rows are green on purpose: the design chooses them. Everything above is a defect with a named owner. v 1.0 · owner Security & Identity Architecture

How to read it

  • The last two rows are green because the design chooses them: a region denying its own subjects' consent-based purposes, and a control plane outage that stops new purposes without stopping decisions.
  • Everything above is a defect with a named owner. "Eventual consistency" is not a cost column entry — unlawful processing is.
  • Each bound is a number stated elsewhere in the set: the staleness ceiling, the 15-minute propagation ceiling, the per-target window, the sampling confidence.

The two that worry most

  • A silent target closing as complete. The platform cannot distinguish a target that finished from one that stopped answering, except by treating silence as failure — which is the rule, and it will be argued with every time a vendor integration is flaky.
  • An identity resolution miss produces an erasure that looks complete to everyone including the subject. It is detected only by re-resolution later, which means the system knowingly ships a class of silent partial failure.

Assumptions

  • Every occurrence of a late ALLOW is a reportable defect rather than a tolerance; the target is zero, not a percentage.
  • Verification sampling is budgeted, so detection is probabilistic and its confidence is stated rather than implied.