Published openly by BlockSiFr · Identity and Execution Governance

THE IEG FIELD MANUAL

Identity and Execution Governance
for Autonomous Systems

AI systems do not fail loudly. They fail quietly, and still act.

The public practitioner field manual for identifying, containing, governing, remediating, reversing, and proving failures across the AI execution stack.

Govern what systems may cause.

  • 40 chapters
  • 220+ vulnerabilities
  • Protected Actions
  • practitioner resources
  • publicly accessible
IEG Field Manual hardcover: Field Manual of AI Security and Countermeasures
Fig. 01 · Hardcover front · Reconstruction pending official cover asset

01 · Thesis

The assistant did not merely make a mistake. The assistant executed.

Classical software security assumes deterministic behavior: bounded inputs, explicit logic, and predictable execution paths. Those assumptions break when probabilistic inference systems can call tools, use identities, modify systems, move data, initiate transactions, and alter infrastructure.

If it can execute, it can be exploited.

If it cannot be proven, it cannot be governed.

Shift from Is the model safe? to Is this system authorized to cause this consequence under these exact conditions?

02 · Contents

What the IEG Field Manual contains

Failure pathways

Exploit paths, root causes, and blast-radius analysis across agent runtimes.

Countermeasures

Numbered controls, detection guidance, and remediation playbooks for practitioners.

Evidence artifacts

ExecutionReceipt patterns for proving what executed, under what authority, with what result.

Framework alignment

Cross-walks to MITRE ATLAS, OWASP LLM Top 10, and NIST AI RMF.

03 · Execution stack

Eight layers from input to memory

An apparently minor input or context failure can propagate into tool selection, execution, and persistent memory.

  1. 01 Input
  2. 02 Tokenization
  3. 03 Context Assembly
  4. 04 Inference
  5. 05 Planning
  6. 06 Tool Selection
  7. 07 Execution
  8. 08 Memory
Open the interactive stack

05 · Audiences

Built for practitioners who govern execution

Security architects

Map failure pathways across the AI execution stack and prioritize controls that bind inference to authority.

Platform and agent engineers

Treat tool selection, memory, and orchestration as security surfaces, not product features alone.

Risk, compliance, and audit

Demand ExecutionReceipt-grade evidence for consequential AI actions under exact conditions.

Executives and operators

Shift the question from “is the model safe?” to “is this system authorized to cause this consequence?”

06 · Frameworks

Aligned to the references defenders already use

  • MITRE ATLAS
  • OWASP LLM Top 10
  • NIST AI RMF

07 · Open chapter

Chapter 1: AI Is Not Software

Educational and practitioner content is public. Open Chapter 1 with no account, email gate, or unlock step.

Open Chapter

08 · Authority

Author and publisher

Founder, BlockSiFr

Maurice Witten

BlockSiFr LLC · Publisher

Maurice Witten is the founder of BlockSiFr, the company defining Identity and Execution Governance, a new infrastructure category designed to govern what humans, AI agents, software systems, and non-human identities are authorized to execute.

His work focuses on a critical architectural problem created by autonomous systems: authentication alone cannot determine whether an action should be allowed at the moment of execution. Through BlockSiFr, Maurice is building the infrastructure required to evaluate identity, authority, trust, consequence, and risk before consequential actions occur, while generating verifiable Execution Receipts after every decision.

Maurice’s professional background includes enterprise identity, service-account governance, and security operations work at Federated Hermes. That experience exposed the limitations of static access controls in environments where machine identities, automation pipelines, and autonomous software operate continuously across critical systems.

Read full biography →

09 · Resources

Field resources

10 · Doctrine and enforcement

Read the doctrine. Assess the system. Govern the execution. Prove the decision.

The doctrine is public. Production assessment, integration, enforcement, evidence operations, and enterprise support are delivered by BlockSiFr.

  1. IEG Field Manual Defines the doctrine
  2. Protected Actions Consequences that require governance
  3. CortexTrace Discovers execution activity and evidence
  4. Execution Exchange Decides allow, constrain, step up, escalate, throttle, deny, or revoke
  5. ModelMeter Measures computational and business consequence
  6. FrontDesk Surfaces requests, decisions, approvals, and receipts
Run the Self-Assessment

Govern what systems may cause.

Free doctrine. Open knowledge. Paid enforcement.