Skip to research content

Decision authority

ADR Registry

A scan-friendly register of the decisions that define the experiment and research program.

Confirmed and tentative states make committed experiment choices distinct from scope still under consideration.

Published records

14 decisions
ADRDecisionAreaState
ADR-0063
IoT experiment entity
IoT remains a tentative breadth extension and is not part of the confirmed core entity roster unless a later scope decision promotes it.
EntitiesTentative
ADR-0062
Windows experiment entity
Windows remains a tentative breadth extension until its experimental role, telemetry surface, time budget, and evaluation value are formally confirmed.
TelemetryTentative
ADR-0061
E2 — build/CI entity
E2 is a confirmed Linux build/CI entity for the experiment and will be provisioned from the documented experimental base with its own workload and reset contract.
EntitiesConfirmed
ADR-0060
E1 — developer workstation entity
E1 is a confirmed Linux developer-workstation entity for the experiment and will receive a reproducible provisioning and reset contract.
EntitiesConfirmed
ADR-0059
Track C — semantic telemetry stream
Track C provides semantic auth, DNS, and related host context that cannot be represented cleanly by the kernel event stream alone.
TelemetryConfirmed
ADR-0058
Track B — periodic magnitude/rate stream
Track B covers periodic magnitude and rate counters that may capture behavior not recoverable from the event stream; the collect-now versus defer decision remains open before corpus collection.
TelemetryTentative
ADR-0057
Track A — kernel behavioral event stream
Track A is the primary Tetragon kernel-behavior stream, designed around behavior-plane coverage, broad modifications, narrow high-volume reads, redaction, lineage correctness, and runtime loss validation.
TelemetryConfirmed
ADR-0056
Documentation and repository architecture
Separates implementation evidence, the formal thesis record, and the curated committee portal.
Research ProgramAccepted
ADR-0055
Detector and evaluation protocol
Defines the model-evaluation discipline used after the thesis corpus is frozen.
Modeling & EvaluationAccepted
ADR-0054
Agentic attack campaign
Defines the high-level agentic attack campaign, deterministic target model, and provenance requirements used by the future harness sprint.
Attack HarnessAccepted
ADR-0053
Kernel telemetry design tracks
Establishes the Track A/B/C framing that the current telemetry sprint is now decomposing into track-specific decisions.
TelemetryAccepted
ADR-0052
Collection topology and window
Defines the per-entity collection topology and establishes the baseline collection-window requirement subject to telemetry validation.
TelemetryAccepted
ADR-0051
Full recollection and provenance labeling
Requires a fresh thesis corpus with provenance labels rather than relying on the earlier time-window labeling approach.
Research ProgramAccepted
ADR-0050
Thesis scope and research questions
Defines the bounded thesis contribution and RQ1–RQ4 used by the v0.3 research program.
Research ProgramAccepted