Research evaluation brief

Do not believe the claim. Test the missing fact.

The evaluation does not ask an organization to replace its network, credentials, applications, roles, policies, or business processes. It asks one narrower question: can a separate existence channel make the required employee absolutely and verifiably absent when that employee is not there?

A 40-hour employee is absent for 128 hours.

A week contains 168 hours. If an employee works 40 of them, the employee is absent for the remaining 128. Existing controls govern the employee’s authorized work, but credentials, identity data, and apparent authority may remain usable long after the employee has left.

Existence-as-a-Factor adds the fact those controls do not independently establish. At an existence-required decision point, the organization can know whether the assigned EAID is present or absent now.

40 HOURS — PRESENT

Channel A maintains existence while Channel B operates under the organization’s ordinary controls.

128 HOURS — ABSENT

Channel A returns verified absence, so an impersonated action cannot cross an existence-required boundary.

The claim is not that one factor solves cybersecurity. The additive value is that the 128 absent hours can be protected as decisively as the 40 present hours wherever the organization requires existence.

Existence is Channel A. Everything on the network proceeds through Channel B.

Channel A — Existence

Channel A establishes and maintains only the binary existence condition. The EAID is not an access credential, and a found identification does not authorize Channel B. Channel A does not authenticate the user, grant permission, carry application content, or execute business activity.

Channel B — Network and application

Once Channel B opens, the network takes over. Credentials, authentication, authorization, RBAC, application logic, transactions, data, workflows, and organizational policy operate there.

The transition

The first successful heartbeat releases the private Rendering Agent. When the agent and the organization’s page are loaded, existence establishment is complete and Channel B begins ordinary governed activity.

The continuing relationship

Channel A remains separate after Channel B opens. It continues maintaining existence while the organization observes the current result at the decision points it selects.

PRESENT maintains the baseline. ABSENT supplies the new fact.

Repeated PRESENT results are operationally necessary because they keep Channel A current, but they add no new substantive authority. They do not re-authenticate the employee, reassign a role, or approve another action.

The consequential result is ABSENT. When the required EAID is no longer present, Channel A establishes a state change that Channel B cannot create, imitate, or override.

Channel A = ABSENT

The result is absolute and verified within the bounded condition being tested: the assigned EAID is not present. The system does not need to identify an attacker before denying the selected consequence.

An impersonator may reproduce apparent authority. The impersonator cannot manufacture existence.

Stolen credentials, copied identity information, a captured session, or convincing behavior may satisfy controls inside Channel B. None can convert Channel A from ABSENT to PRESENT while the legitimate EAID is absent.

Channel B presents apparently valid authority
Selected action requires current existence
Channel A returns ABSENT
Protected action deniedVerified absence recorded

Existence-as-a-Factor does not have to prove who the impersonator is. It proves the immediately useful fact: the required existence condition is absent.

The organization is not asked to surrender a control that already works.

Channel B remains intact. The organization keeps its identity systems, credentials, applications, permissions, workflows, protected data, network ownership, and policy. Channel A is added around selected decisions without taking over the network or application.

The evaluation is not costless. It requires defined participants, bounded integration, operating attention, and honest measurement. What it does not require is architectural abandonment or a leap of faith.

The organization does not have to believe the explanation in advance. It only has to identify one protected decision and test whether verified absence changes the result when the employee is not there.

The pilot uses the operating relationship rather than a staged imitation.

  1. 1

    Keep Channel B unchanged.

    Existing credentials, authorization, applications, roles, data, workflows, and policy remain the organization’s controls.

  2. 2

    Add Channel A at selected decisions.

    The organization chooses where current existence must be present before a consequence is allowed.

  3. 3

    Test the 40 present hours.

    Confirm that ordinary work proceeds through Channel B while Channel A maintains the existence condition separately.

  4. 4

    Test the 128 absent hours.

    Remove or terminate the EAID, present apparently valid Channel B authority, and verify that the selected action encounters ABSENT.

  5. 5

    Inspect the evidence.

    Review assignment, session, heartbeat, presence, absence, decision, and collapse records retained under organizational control.

  6. 6

    Continue without rebuilding.

    If the organization accepts the result, the Beacon, integrations, policy, decision points, and operational knowledge remain. Transition to live use replaces P2L EAIDs with live EAIDs rather than replacing the architecture.

The in-house examination may extend to 1,000 participants for six months without an additional organizational-scale test charge. The point is to allow the organization to determine the value under its own conditions before it is asked to rely upon the result.

The method succeeds or fails in observable operation.

Channel separation

Confirm that Channel A carries existence only and that Channel B retains all network, application, credential, and authorization functions.

Private arrival

Confirm that Channel B does not open before the first successful heartbeat releases the Rendering Agent and the organization loads its page.

Maintained PRESENT

Confirm that recurring heartbeat keeps Channel A current without creating new identity, permission, or transaction authority.

Verified ABSENT

Remove the required EAID and confirm that Channel A returns ABSENT rather than inheriting the prior PRESENT result.

Impersonation attempt

Present credentials or apparent Channel B authority while the legitimate EAID is absent and confirm that the existence-required action is denied.

Deterministic consequence

Confirm that ABSENT produces the organization’s selected denial, collapse, termination, or other bounded consequence.

Organizational custody

Confirm that protected content and operational control remain with the organization while Channel A supplies only the binary condition.

Recorded evidence

Confirm that presence, absence, session, decision, and collapse events can be examined rather than accepted as an undocumented assertion.

A skeptical reviewer should know what would disprove the claim.

  • Channel A remains PRESENT after the required EAID is absent.
  • Channel B opens before the Rendering Agent and organization page are released by a valid first heartbeat.
  • The EAID alone grants application access without the organization’s credentials and authorization.
  • Repeated PRESENT results are represented as new authentication or new authority.
  • An impersonated Channel B action crosses an existence-required boundary while Channel A is ABSENT.
  • The network is represented as the source of existence rather than the place where the organization observes it.
  • The pilot requires replacement of the organization’s working Channel B environment before the existence condition can be evaluated.

Verified absence proves one fact absolutely—not every fact universally.

Within the protocol, ABSENT proves that the assigned EAID is not present. It does not identify the impersonator, establish the employee’s intent or attention, prove rightful possession, guarantee endpoint integrity, validate transaction correctness, or solve every cybersecurity problem.

The finding is narrower and more useful because it does not need those additional conclusions before the organization can deny an action that requires existence.

Not “Do I believe this?” but “What must I give up to test it?”

The organization keeps Channel B and adds Channel A at a boundary it chooses. If verified absence does not appear and control the selected consequence, the method has failed its own test. If it does, the organization has gained a fact it did not possess before without rebuilding the environment it already trusts.