Trust-Calibration and Dependency Audit¶
Test or assessment — instantiates Evidence-Bounded Trust Governance
Looks back across a whole portfolio of reliance to compare each granted tier against its actual outcomes, monitoring cost, and how dangerously concentrated the dependence has become.
The Trust-Calibration and Dependency Audit is the retrospective, portfolio-level review of reliance that has already been running. Its defining stance is hindsight across many relationships at once: rather than deciding an individual reliance up front or testing a single trustee, it steps back over an interval and asks whether the tiers actually granted have been calibrated to what happened — where reliance was too generous (overtrust that outran the evidence), too stingy (undertrust that imposed needless verification, exclusion, or duplicated work), where evidence has gone stale or drifted, and where dependence has quietly concentrated onto a single point of failure. It grants no reliance and produces no first-time evidence; it is the feedback loop that catches the miscalibrations no single up-front decision could see, precisely because they only become visible in the aggregate and over time.
Example¶
A manufacturer maintains an "approved supplier" list with reliance tiers — some vendors are single-sourced and shipped straight to the line, others are second-sourced and inspected. Once a year, procurement runs the audit. It pulls each tier and lays it against the year's actual outcomes: defect rates, on-time delivery, incidents. Two findings emerge. A high-tier single-source supplier of a critical casting has had a creeping rise in late shipments — the tier was set three years ago and the evidence is now stale; reliance has drifted above what current performance supports (overtrust). Meanwhile a second-tier supplier with a spotless four-year record is still being 100%-inspected, a monitoring burden wildly out of proportion to its outcomes (undertrust that is quietly costing the inspection team hundreds of hours).
The sharpest finding is structural: three of the top five components now come from one industrial park, and one vendor there supplies 60% of a critical part with no qualified alternative — a concentration the firm never chose deliberately, it just accumulated. The audit does not fix any of this; it produces the recalibration worklist — tighten the drifted tier, relax the over-inspected one, and qualify a second source before the concentrated dependence becomes a hostage situation.
How it works¶
- Assemble the portfolio. Pull every active reliance tier and its granted permissions into one view, rather than examining relationships one at a time.
- Compare granted tier to realized outcomes. For each, set the reliance level against the actual results, incidents, and how much of the evidence is now stale — surfacing both overtrust and undertrust.
- Weigh the monitoring burden. Flag verification effort that is disproportionate to stakes and outcomes in either direction: wasteful over-checking of proven parties, or thin monitoring of high-exposure ones.
- Map concentration and alternatives. Trace where dependence has piled onto single points of failure and whether fallbacks still exist, then emit a recalibration worklist — not the changes themselves.
Tuning parameters¶
- Audit interval — how often the portfolio is reviewed. Frequent audits catch drift early but cost effort and can churn stable tiers; rare ones let miscalibration compound.
- Calibration window — how much outcome history each tier is judged against. A long window is statistically stabler but slow to flag recent decay; a short one is reactive but noisy.
- Concentration threshold — how much dependence on one trustee triggers a flag. A low threshold forces expensive diversification early; a high one tolerates fragility longer.
- Undertrust sensitivity — how hard the audit hunts for excessive verification, not just excessive reliance. Raising it recovers wasted effort and reduces exclusion but can read as lowering guard.
- Subgroup disaggregation — whether outcomes and evidence burdens are broken out by subgroup to catch inequitable verification demands. Finer cuts expose disparity at the cost of complexity.
When it helps, and when it misleads¶
Its strength is that it is the only mechanism here that audits undertrust as rigorously as overtrust and that catches concentration risk — the slow accumulation of dependence onto a single supplier, person, or system whose failure would be catastrophic and whose alternatives have quietly decayed.[n1] Because it works across the portfolio and over time, it sees the stale tier, the disproportionate monitoring, and the dependency trap that any single reliance decision, taken on its own, could not.
Its failure mode is that a retrospective review can harden into a metrics ritual — optimizing the tiers that are easy to measure while the qualitative ones (candor, care, psychological safety) go unaudited — or curdle into standing surveillance dressed as calibration. The classic misuse is auditing only overtrust, ratcheting verification ever upward while never asking where distrust is itself doing harm, which reproduces exclusion and defensive cost. The guarding discipline is to hold undertrust and monitoring burden in the same frame as overtrust, to treat concentration and stale evidence as first-class findings, and to keep the audit a periodic review that emits a worklist — not a continuous monitoring apparatus and not the actor that changes the tiers.
How it implements the components¶
trust_calibration_outcome_dependency_and_drift_review— it is this review carried out: comparing tiers and monitoring burdens against outcomes, incidents, stale evidence, subgroup disparity, alternatives, and concentrated dependence, and emitting the recalibration worklist.
Its nearest twin is the graduated trial, and the split is temporal: the trial expands a tier prospectively through live recoverable steps, whereas this audit reviews existing tiers retrospectively in aggregate and grants no reliance itself (domain_specific_trust_tier_and_reliance_envelope, trustor_exposure_recoverability_power_and_alternative_profile — the trial's). It also does not decompose behaviors and dimensions up front (trust_purpose_relationship_domain_and_stakes_frame, trustee_ability_reliability_honesty_care_and_constraint_profile — the matrix), authenticate individual claims (proportional_evidence_signal_verification_and_privacy_plan — verification), or respond to an active breach (trust_breach_containment_revocation_and_repair_path — the protocol).
Related¶
- Instantiates: Evidence-Bounded Trust Governance — the audit is the calibration feedback loop that keeps the whole portfolio of reliance honest over time.
- Consumes: Commitment, Disclosure, Exception, and Outcome Log — the ledger of promises, exceptions, and outcomes is the audit's raw material.
- Sibling mechanisms: Domain-Specific Trust Evidence and Exposure Matrix · Graduated Reliance and Bounded-Exposure Trial · Independent Reference, Claim, and Conflict Verification · Commitment, Disclosure, Exception, and Outcome Log · Trust-Breach Triage, Containment, and Repair Protocol
Editorial Notes¶
Form Classification¶
Form family: Assessment, Review & Assurance
Rationale: Trust-Calibration and Dependency Audit operates as a bounded evaluation of existing evidence or work that produces a finding or disposition because it looks back across a whole portfolio of reliance to compare each granted tier against its actual outcomes, monitoring cost, and how dangerously concentrated the dependence has become.
Independent corroboration: The frozen evidence defines Trust-Calibration and Dependency Audit as 'Looks back across a whole portfolio of reliance to compare each granted tier against its actual outcomes, monitoring cost, and how dangerously concentrated the dependence has become', so its operative form is Assessment, Review & Assurance.
Nearest alternative: Analysis, Modeling & Optimization — Trust-Calibration and Dependency Audit includes features of an analytical, modeling, inference, comparison, or optimization procedure that derives insight or a solution, but its defining operation is a bounded evaluation of existing evidence or work that produces a finding or disposition.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Security Studies & Intelligence Analysis
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Universal
Rationale: Comparing reliance tiers with observed outcomes, switching cost, and dependency concentration is an assurance and dependency-risk audit aimed at appropriate reliance. Lee and See define calibrated trust as matching reliance to system capability; NIST supply-chain guidance adds upstream concentration and assurance risk.
Related originating lineages:
- Accounting & Auditing — accounting_auditing contributes accounting, auditing, and controlled-resource stewardship to this mechanism's defining operation—Looks back across a whole portfolio of reliance to compare each granted tier against its actual outcomes, monitoring cost, and how dangerously concentrated the dependence has become—without displacing the selected primary historical lineage.
- Computer Science & Software Engineering — Software systems, algorithms, and data structures supplies a distinct formative lineage for the mechanism's trust calibration and dependency audit logic.
- Organizational & Management Science — organizational_management contributes organizational design, management, and operational governance to this mechanism's defining operation—Looks back across a whole portfolio of reliance to compare each granted tier against its actual outcomes, monitoring cost, and how dangerously concentrated the dependence has become—without displacing the selected primary historical lineage.
- Psychology — Experimental, clinical, and behavioral psychology supplies a parallel or contributing lineage for the mechanism's defining operation: looks back across a whole portfolio of reliance to compare each granted tier against its actual outcomes, monitoring cost, and how dangerously concentrated the dependence has become.
- Systems Thinking & Cybernetics — Systems thinking, feedback control, and cybernetics supplies a parallel or contributing lineage for the mechanism's defining operation: looks back across a whole portfolio of reliance to compare each granted tier against its actual outcomes, monitoring cost, and how dangerously concentrated the dependence has become.
Review resolution: The blind reviewers disagree on primary lineage (security_intelligence versus organizational_management). Authoritative or primary research supports security_intelligence as the best historical origin: Comparing reliance tiers with observed outcomes, switching cost, and dependency concentration is an assurance and dependency-risk audit aimed at appropriate reliance. Lee and See define calibrated trust as matching reliance to system capability; NIST supply-chain guidance adds upstream concentration and assurance risk. The cited Lee and See, Trust in Automation: Designing for Appropriate Reliance directly supports the mechanism's defining operation. All independently supported contributing domains are retained without an arbitrary cap. origin_mode=cross_disciplinary_synthesis records lineage, while domain_reach=universal records later applicability separately from provenance.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
Notes¶
[n1] Concentration risk, a staple of financial and supply-chain governance, is the danger created when exposure piles onto a single counterparty, source, or point of failure, so that one default or outage produces outsized loss. Reliance concentrates the same way — silently, through convenience and dependence — which is why a portfolio audit tracks it explicitly and asks whether alternatives still exist. ↩