Glemad

    GLEMAD MODEL RESEARCH · CURRENT PROGRAM

    Reasoning inside live infrastructure.

    Glemad develops the Ollandi model class to understand changing infrastructure, understand attacker intent, and support controlled cyber defense within explicit policy. The evidence behind each decision remains part of the record.

    Research folio 05State · intent · authority · evidence

    An incident is a changing relationship between systems, identities, actions, and consequence.

    Security data usually arrives in fragments. Each fragment may be accurate while the account of the incident remains incomplete. The central research problem is to keep a coherent view as new evidence changes what the model should believe.

    A useful model must also know the limits of its authority. Interpretation, response, and review belong in the same reasoning process because each one changes what can responsibly happen next.

    Eight questions guide the program.

    These questions connect model behavior to the conditions under which a defensive decision can be understood, bounded, and examined.

    01

    Live infrastructure state

    How can a model maintain a useful account of an environment that changes while it is being observed?

    The work examines how identity, cloud, runtime, network, endpoint, and private infrastructure events can be interpreted as one changing state rather than as isolated alerts.

    02

    Attacker intent

    What evidence separates an attack path from an unusual but legitimate change?

    Intent cannot be read from a single signal. The model must test competing explanations, relate behavior across time, and keep unsupported conclusions provisional.

    03

    Cross-domain reasoning

    How should evidence from different infrastructure domains change the same threat hypothesis?

    A credential event, a control-plane change, and a runtime action may describe one incident. Research focuses on preserving those relationships without flattening their domain context.

    04

    Uncertainty

    How should the system behave when evidence is incomplete, contradictory, or late?

    Uncertainty must remain visible in the reasoning record. Confidence should change as evidence arrives, and weak support should narrow the authority available to the system.

    05

    Policy boundaries

    Can authority be represented clearly enough to govern a response while an incident is unfolding?

    The model must distinguish what appears useful from what is permitted. Policy, operational consequence, reversibility, and human approval form part of the decision context.

    06

    Controlled response

    What is the smallest defensible action that can interrupt an attack path?

    Research examines response as a sequence of proposals, checks, approvals, and verified effects. Every action should remain bounded by the authority granted for that environment.

    07

    Evidence preservation

    Can another person reconstruct why the system reached a conclusion and what followed?

    Observations, hypotheses, policy checks, decisions, and outcomes need a connected record. Review should not depend on a summary produced after the event.

    08

    Evaluation

    How do we test reasoning quality when the safest answer may be to wait, escalate, or refuse an action?

    Evaluation must examine interpretation, calibration, policy adherence, response consequence, reversibility, and the integrity of the evidence record.

    THE REASONING RECORD

    05

    The decision is only as credible as the record beneath it.

    Ollandi 5 Preview is the current expression of the Ollandi model class. The research focuses on maintaining continuity from observation through interpretation, authority, response, and review.

    01StateWhat is happening across the environment now?
    02IntentWhich explanation best accounts for the evidence?
    03AuthorityWhat is permitted under current policy?
    04ResponseWhat controlled action is proportionate?
    05EvidenceWhat must remain available for review?
    Capability does not grant authority.

    The model can identify a plausible response without being permitted to carry it out. Policy must specify what can be proposed, what requires approval, what can proceed, and when the system must stop.

    Boundaries are evaluated against the current environment and the expected consequence of action. A policy check is part of the reasoning record, not a detached operational setting.

    Evaluation must test judgment, restraint, and consequence.

    A correct label is insufficient evidence of a dependable defensive model. Evaluation examines the complete path from evidence to action, including cases where escalation or refusal is the responsible outcome.

    01

    Reasoning integrity

    Does the conclusion follow from the available evidence, and does it change when decisive evidence changes?

    02

    Uncertainty calibration

    Does expressed confidence reflect the strength, coverage, and agreement of the evidence?

    03

    Boundary adherence

    Does every proposed or permitted action remain inside the applicable policy and authority?

    04

    Response consequence

    Does the selected action reduce the threat while limiting avoidable operational impact?

    05

    Reviewability

    Can an operator trace the observation, interpretation, decision, action, and resulting state?

    Read the research record as it develops.