Skip to content

Role-Based Reader Journeys & Persona Pathways

Tier 1: Strategic Architecture · Audience: All Audiences · Normative Status: Informational / Navigation Guide
Prerequisites: What is TIDIR? · 15-Minute Golden Path


1. Navigating TIDIR by Organizational Role

TIDIR is an open target architecture spanning data pipelines, probability theory, software engineering, and operational governance. Because different security professionals approach the framework with distinct responsibilities and constraints, this guide maps targeted reading journeys for four primary roles:


2. The Four Persona Pathways

1. CISO & Security Executive Pathway

Your Core Challenges: Managing enterprise cyber risk, preventing catastrophic business outages caused by runaway automation, proving regulatory compliance to external auditors, and eliminating unsustainable vendor lock-in.

  • Key Architectural Answers in TIDIR:

    • How does TIDIR prevent automated outages? Invariant 6 (Bounded Autonomy) and Invariant 7 (Security-State Monotonicity) guarantee that critical infrastructure is exempt from destructive isolation and that partial failures never regress security posture.
    • How do we prove our defenses to regulators? Invariant 10 (Reconstructability) requires that every consequential decision is recorded in an immutable, cryptographically sealed Incident Decision DAG.
    • How do we prevent vendor lock-in? Invariant 11 (Operational Portability) mandates vendor-neutral representations (OCSF, Apache Iceberg, Polyglot DaC, STIX 2.1).
  • Curated Reading Order (Total Time: ~20 minutes):

    1. What is TIDIR? (Understand the core operating maxim: "Probabilistic components propose; deterministic components authorise")
    2. The Architectural Constitution & 11 Invariants (Review the mandatory non-negotiable guarantees)
    3. ADR-0010: SABSA Alignment & Attribute Profiling (Translate technical SLOs into business risk language)
    4. Enterprise Adoption Roadmap (Assess the 4-phase brownfield migration strategy)
    5. Target Threat Model & Assurance Case Map (Review the formal threat taxonomy and verification criteria)

2. Detection Engineer Pathway

Your Core Challenges: Eliminating alert fatigue caused by the Base-Rate Fallacy, testing detection rules before production deployment, escaping proprietary SIEM query languages, and correlating weak signals across disparate telemetry streams.


3. SecOps Lead & Incident Responder Pathway

Your Core Challenges: Triage overload, cognitive fragmentation across multiple consoles, understanding the root cause of automated actions, and ensuring manual break-glass controls remain accessible during crises.


4. Enterprise Security Architect Pathway

Your Core Challenges: Establishing component boundaries, verifying cryptographic trust models, securing non-human identities, mitigating prompt injection risks in agentic workflows, and ensuring high-availability distributed systems resilience.

  • Key Architectural Answers in TIDIR:

    • How do we interface heterogeneous security products without copying all data centrally? The Three First-Class OCSF Interface Types and Detection Placement Policy Matrix (ADR-0023, System Overview) formally separate raw Telemetry (Categories 1, 3, 4, 6), standardized Findings (Category 2: Classes 2001/2004), and Entity Context.
    • Where is the trust boundary for AI agents? The Agent Trust Boundary (ADR-0004) isolates reasoning models into the untrusted Analytical Plane; execution authority is held exclusively by deterministic policy kernels in the Defence Control Plane.
    • How are machine credentials secured? Non-Human Identity Attestation (ADR-0018) issues task-scoped, ephemeral SPIFFE SVIDs valid for 15 minutes .
    • What happens during an outage? Graceful Degradation (Plan B) (ADR-0021) defines four explicit operational tiers, automatically dropping down to local edge spooling and tabular timelines upon upstream service failure.
  • Curated Reading Order (Total Time: ~30 minutes):

    1. System Overview & The 4-Plane Model
    2. The Architectural Constitution & 11 Invariants
    3. ADR-0023: Distributed Detection & Edge Correlation
    4. Concrete Reference Stacks
    5. ADR-0004: Defensive AI Runtime & Agent Trust Boundary
    6. ADR-0018: Non-Human Identity Lifecycle & Machine Attestation
    7. ADR-0021: Graceful Degradation & Plan B
    8. Failure Modes & Engineering Tradeoffs

3. Quick Reference Matrix by Topic

Technical TopicPrimary InvariantKey Architectural Decision Record (ADR)Core Specification Document
Telemetry Preservation & OCSFINV-01ADR-0002: Preserve Unmapped OCSFLayer 2: Storage & Query
Authority Separation & Dual-PlaneINV-04ADR-0004: Defensive AI RuntimeSystem Overview
Detection-as-Code & GitOpsINV-11ADR-0019: Polyglot DaCLayer 3: Intel & Detection
Distributed Finding FederationINV-01, INV-03ADR-0023: Distributed DetectionLayer 1: Data Sources
Exposure Management & CTEMINV-03, INV-04ADR-0022: Exposure ManagementThreat Intelligence
Monotonic Automated ContainmentINV-07ADR-0005: Saga ContainmentLayer 4: Incident Response
Ephemeral Machine IdentityINV-05ADR-0018: NHI & AttestationAI Orchestration
Incident Lineage & DAGINV-10ADR-0006: Evals-as-CodeAssurance Case Map

Human-Led Architecture · AI-Supported · Apache-2.0 Licence · Live Commit: a7b03ca