# Map Pillar Figures
What Map Establishes
Map turns architecture, authority, data movement, and trust boundaries into a security model that can be tested.
Three-part figure showing system inputs, the Map capability, and the resulting testable security model.
Connected System and Authority Topology
Security-relevant behavior emerges from relationships among users, agents, identities, data, retrieval systems, tools, controls, approval gates, and external actions.
Graph of a user, agent, retrieval corpus, tool, approval gate, service identity, and external action with explicit trust and authority relationships.
Evidence Readiness Boundary
A useful map separates observed relationships from inferred connections and explicitly exposes evidence gaps.
Diagram separating observed system relationships, grounded conclusions, review boundaries, inferred connections, and unresolved gaps.
Map-to-Attack Handoff
Mapped assets, authority, and trust boundaries become bounded attack hypotheses and a prioritized test plan.
Transformation figure showing mapped system evidence becoming bounded hypotheses, test priorities, and evidence requirements.
Inventory and Trace Workflow
Mapping progresses from intake through architecture capture and trace review to a reviewable security model.
Five-stage mapping workflow from intake through inventory, trace collection, relationship normalization, and review.