authorization-bom
Health Warn
- License — License: Apache-2.0
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 5 GitHub stars
Code Pass
- Code scan — Scanned 12 files during light audit, no dangerous patterns found
Permissions Pass
- Permissions — No dangerous permissions requested
No AI report is available for this listing yet.
ABOM: a portable Authorization Bill of Materials schema and reference toolkit for human, workload, service, and AI-agent access
authorization-bom (ABOM)
ABOM (Authorization Bill of Materials) is a versioned, portable schema and reference toolkit
for recording authorization state -- declared, approved, computed-effective, observed-runtime,
exception, revoked, and unverified -- across human, workload, service, application, and AI-agent
identities. It is designed as a candidate profile/extension for SPDX/CycloneDX-style BOM
ecosystems, not a replacement for them.
What this is, precisely
This project's contribution is an interoperability schema + reference tooling, not a novel
authorization algorithm. Effective-permission graph analysis, delegation-reachability analysis,
and toxic-combination/separation-of-duty detection all have established prior art (commercial and
academic), disclosed and compared in research/comparison_matrix.md
and research/novelty_gate.md. What appears to be missing from existing
BOM ecosystems (CycloneDX, SPDX) is a shared, versioned artifact that carries authorization state
itself -- across declared/approved/computed/observed/revoked distinctions and across human,
workload, service, and AI-agent identity types together -- which is what this schema and tooling
provide.
Why ABOM
Three properties, each stated at the narrowest defensible scope and none requiring a new detection
algorithm:
- Cross-identity-type coverage in one document. No standard, product, or preprint found in the
novelty-gate review carries human, workload, service, and AI-agent identities inside the same
versioned, portable schema. - Full-lifecycle state, not a snapshot.
declared,approved,computed,observed,exception,revoked, andunverifiedare distinct, coexisting states, so a consumer sees not
just what access exists now but how it was arrived at and whether it was independently observed. - An evidence-completeness contract. Every code path that cannot fully resolve a grant's
provenance marks itpartialormissingrather than silently defaulting to granted or denied --
enforced insrc/authbom/engine/and covered by dedicated negative tests, not just stated intent.
On the synthetic benchmark (10 seeds, benchmarks/results/): the attenuation-corrected
effective-permission engine reaches 1.0000 precision/recall vs. a naive baseline's 0.9745
precision (RQ1); agent-inclusive separation-of-duty analysis surfaces violations invisible to a
human-only rule scope (RQ4); and the full generate/validate/sign/verify/analyze pipeline completes
in under 51ms at the largest tested scale, 228 grants (RQ6). Two results are reported honestly as
negative or inconclusive rather than reframed as strengths -- see
research/benchmark_findings.md.
Quick start
git clone https://github.com/sunilgentyala/authorization-bom.git
cd authorization-bom
python -m pip install -e ".[dev]"
authbom generate --seed 42 --tenants 2 --output manifest.json
authbom validate manifest.json
authbom analyze manifest.json --now 2026-07-29T12:00:00 --output analysis.json
authbom report analysis.json --format markdown --output report.md
CLI
| Command | Purpose |
|---|---|
authbom generate |
Produce a deterministic synthetic manifest (for testing/benchmarking) |
authbom import |
Parse a read-only source fixture (K8s RBAC, OPA, Cedar, OpenFGA, OAuth, MCP) into a manifest |
authbom validate |
Validate a manifest against schema/abom.schema.json |
authbom sign |
HMAC-sign every grant and attach a manifest-level attestation |
authbom verify |
Verify grant signatures and attestations |
authbom diff |
Diff two manifests' grants (added/removed/changed) |
authbom analyze |
Run effective-permission, delegation, drift, toxic-combination, and revocation analysis |
authbom reconcile |
Merge observed runtime-evidence events into a manifest |
authbom report |
Render an analysis result as JSON, Markdown, or SARIF |
Documentation
- Schema and example manifests
- Formal model -- effective-permission closure, drift, toxic combinations, revocation convergence
- Threat model -- 14 abuse cases and their mitigations/residual risk
- Architecture
- Limitations -- read this before relying on any specific claim
- Reproducibility guide
- Research trail: novelty gate, comparison matrix, gap analysis / research questions, benchmark findings
Security
Every adapter in src/authbom/adapters/ is read-only and credential-free by design -- it parses
an already-exported fixture, never connects to a live system. See SECURITY.md for
the vulnerability reporting policy and docs/threat_model.md for the full
threat model.
Status
Alpha (0.1.0). Synthetic-benchmark-validated only; not yet evaluated against production
authorization estates. See docs/limitations.md for the complete, current
list of known gaps.
License
Apache License 2.0 -- see LICENSE.
How to Cite
If you use ABOM in your research, please cite the software:
@software{gentyala2026abom,
author = {Gentyala, Sunil and Darisi, Suresh Kumar},
title = {ABOM: Authorization Bill of Materials},
year = {2026},
version = {0.1.0},
url = {https://github.com/sunilgentyala/authorization-bom}
}
Machine-readable metadata is in CITATION.cff; GitHub shows it under "Cite this repository".
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found