# VNWO Technical Architecture Worksheets

**Version:** 3.0.6
**Last reviewed UTC:** 2026-06-20T00:41:09Z

These worksheets are static public guidance. They do not certify an implementation, authorize access, collect telemetry, validate credentials, or guarantee privacy, compliance, deletion, attestation correctness, cloud sovereignty, or safety.

## Technical threat model

- Actor and responsible party
- Resource and requested action
- Stated purpose
- Authority and delegation
- Observation and inference
- Retention and secondary use
- Escalation and approval
- Repair and appeal
- Revocation and exit

## Zero-trust self-assessment

- Is authority resource-specific, action-specific, time-bounded, and revocable?
- Does the design minimize observation, or does it replace broad trust with continuous behavioral scoring?
- Are refusal reasons and correction paths visible?
- Can every human, workload, agent, and endpoint grant expire independently?

## Metadata inventory

Record field name, collection point, sensitivity, inference potential, correlation risk, purpose, necessity, retention, sharing, secondary-use limits, and retirement evidence.

## Monitoring-escalation receipt

Record case, trigger, approving role, scope, fields collected, payload access, expiry, review path, appeal, closure, and disposition.

## Agent authority receipt

Record intent, plan, tools, endpoint scope, memory classes, budgets, approval triggers, action evidence, repair, revocation, and exit.

## Cloud-sovereignty worksheet

Record provider administration, key custody, confidential-computing and attestation scope, infrastructure drift controls, jurisdiction, portability, and offboarding.
