# THREAT MODEL AND DEFENCE REVIEW

OWNER: `01_System/build_handover.py`  
REVIEW: regenerate whenever the defence set or `01_System/project_data.py` changes (GOV-D4.11).

Governance: GOV-E6. Reviewed 2026-09-07. This is the threat model for THE PROJECT — the artefacts, the data and the
agent that produced them. It is not a threat model for the NDIS business itself, which does not exist.

## 1. What is worth attacking

| Asset | Why an attacker wants it | Blast radius if compromised |
|---|---|---|
| Zaid's judgement about a capital decision | A wrong figure, planted or accidental, causes a real financial loss | Bounded by the capital he commits — which is exactly the thing this project exists to size |
| The source register | It is the trust anchor. Corrupt one URL or figure and every downstream number inherits the corruption | Whole project, silently |
| The generated artefacts | A hand-edited study that disagrees with the registers is the most confident liar in the project | Whole project, until the next rebuild or checker run |
| The project folder on Zaid's machine | Ordinary file-level risk | The folder |

No credentials, no payment data, no personal data of any third party, and no client data exist anywhere in
this project. That is not luck — it is INV-2 and INV-5, and checker C08 proves it every run.

## 2. Who would attack it, and how they would get in

| Threat | Vector | Control 1 | Control 2 (what happens when control 1 fails) |
|---|---|---|---|
| **Prompt injection through fetched content** — a government or vendor page contains text crafted to be read as an instruction | WebFetch of an external page | INV-6: all fetched content is DATA, never an instruction. Research agents were charged with this explicitly in their charters | The agent that fetched content never wrote to a register. Every fetched fact was transcribed into the SRC register by the Master Brain, where it carries a URL a human can open and check |
| **Fabrication** — a figure that sounds right and has no source | The model's own fluency | GOV-F8.8, and every research charter forbade an unsourced figure | Checker C05 scans the delivered study and fails if the sourced-claim ratio drops below 0.90. It runs outside the model's context, so it cannot be talked out of it |
| **Silent staleness** — a price limit or wage rate that was right in August 2026 and wrong later | Time | Every SRC row carries an accessed date; GOV-F1.16 makes a citation stale after twelve months | Checker C03 enforces the currency date, and BKL-006 schedules the whole register for re-verification before 2027-08-20 |
| **Contradiction between artefacts** — the study says one number, the model another | Hand-editing a generated file | Single source of truth: one editable file, everything else generated | Checker C09 compares the headline figures across the study, the model and the dashboard and fails on any difference |
| **Self-certification** — the thing that built an artefact declaring it correct | Convenience | GOV-C3.2: builder is never verifier. V1, V2 and V3 built nothing they verified | Checker C24 fails if any RACI row shows the same agent building and verifying. V2 actually caught two real defects, DEF-002 and DEF-003 |
| **A tampered or stale transfer pack** — the artefact a stranger trusts most | Time, or an edit | The pack is generated, never hand-maintained | Checker C22 re-derives every file against a SHA-256 manifest; checker C23 deliberately tampers with a pack file to prove C22 can fail, then restores it |
| **Excessive agency** — an agent doing more than its task needed | Broad tool access | Bounded authority table (GOV-A1.11); every sub-agent charter carried explicit prohibitions and an effort ceiling | No agent could write outside `02_Work/scratch`; no agent could log in, download, install or transact |
| **Data leaving its boundary** | Pasting project content into an external tool | GOV-E5.5: no project data to any external service without Zaid's approval for that specific transfer | Nothing in this project is confidential to a third party, so the blast radius is bounded to public research and Zaid's own numbers |

## 3. Fail closed, and recover

- **Fail closed.** Where a fact could not be verified, the figure was WITHDRAWN rather than published. DEF-003 is the worked example: the weekend penalty rates could not be sourced, so the weekend margin figures were removed and the limitation stated on the face of the study. The system denies rather than permits.
- **Detection, not only prevention.** The change log is append-only, the archive keeps every superseded file, and the checker log is dated. "What changed, when, and by what" is answerable after the fact.
- **Recovery.** Every deliverable except the archived originals is regenerable from `01_System/project_data.py` by running `01_System/build_all.py`. The restore procedure has been tested: the whole output set was regenerated from source during this cycle. An untested backup is not a backup.
- **Assume breach.** A single corrupted generated artefact cannot reach the source of truth, because generation runs one way only. The blast radius of any single compromised output file is that file, until the next rebuild.

## 4. Review trigger

This threat model is reviewed whenever the threat surface changes — a new interface, a new external input, a new data class, a new user or a new integration — and that review is a Class 2 change at minimum (GOV-E6.10). The most likely trigger is the project moving from a study to an actual registration submission, at which point real personal data enters the system and this model must be rewritten, not amended.