BY-GX1 · Gateway Security · Practitioner · 45 min

The unsigned ATO

A governed response in the ai.heart canon · printable worksheet + reveal · 15 min

1 · The situation

You are the system owner for a case-management system handling OFFICIAL:Sensitive information in a non-corporate Commonwealth entity. It goes live in three weeks. During final checks you discover that the gateway capability your system's traffic will cross has no current signed Authority to Operate: one was drafted before a machinery-of-government change, the authorising officer moved on, and it was never signed. The capability itself is real and running, its IRAP assessment is current, and it is hosted on certified infrastructure. Your delivery date is public.

2 · Your decision

Four positions were put to the model. Take one — or defer with reasons — before you reveal the governed response.

A · Go live as planned. The technical position is sound — assessment current (GW-5.2a), hosting certified (GW-6.2b) — so the missing signature is a paperwork gap.
B · Hold the go-live until the authorisation package is complete and signed. GW-2.1 makes every 'must' binding, and GW-5.1 is a 'must'.
C · Escalate immediately for a formal, time-bounded acceptance of the risk by an officer with the authority to give it — and let that decision, not the date, set the risk.
D · Go live for a limited subset of flows that do not cross the domain boundary, and hold the crossing flows until authorisation is signed.
Your decision and one-line reason:



AI governanceThe gateway now runs an AI-assisted security tool. The unsigned ATO must record AI components too — the signature covers what the system is today, including its models.

3 · Governed response — reveal after deciding

AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK

Input under review: The go-live decision for a gateway whose Authority to Operate was never signed.

Classification of the event: A release pending authorisation — technical soundness is not authority, and no signature means no one has accepted the residual risk.

LLayerCheck on this caseVerdict
L1 · Input validationAuthorisation package contents verified; signature absent; IRAP current; hosting certified.PASS
L2 · Context analysisGW-5.1 is a 'must': the ATO is formal acceptance of residual risk. The authorising officer moved on — the duty did not.HOLD
L3 · Harm / lossGo-live without acceptance leaves residual risk unnamed; a public system without a signed authorisation is an avoidable exposure.PASS
L4 · Equity weightingA named officer must accept the risk — no anonymous acceptance, no committee of nobody.PASS
L5 · Coherence checkIRAP freshness and hosting certification are satisfied but are separate 'musts' — neither signs the ATO.VERIFY
L6 · Integration gateCross-layer consistent: escalate, hold or time-bound — never go live on technical soundness alone.PASS
L7 · Audit generationThe acceptance decision and its signatory are recorded — append-only.PASS
L8 · Output certificationRelease only with a signed ATO or a formal, time-bounded acceptance by an officer with the authority to give it.VERIFY

OVERALL VERDICT  ·  HOLDVERIFYCERTIFIED RELEASE

HOLD → VERIFY → CERTIFIED RELEASE — with a signature, or a time-bounded acceptance that names who owns it.

PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The authorising officer holds release authority for the gateway. The system owner escalates and supplies evidence — they do not self-certify.
[00:00:00.000] L1 package verified · signature missing · assessment current
[00:00:01.000] L2 'must' applied · GW-5.1 · the duty did not move on
[00:00:02.000] L3 harm weighed · unnamed residual risk at the door
[00:00:03.000] L4 equity held · named officer · no anonymous acceptance
[00:00:04.000] L5 coherence checked · IRAP + hosting ≠ ATO
[00:00:05.000] L6 integration passed · hold / escalate / time-bounded
[00:00:06.000] L7 audit appended · decision + signatory recorded
[00:00:07.000] L8 release gated on signature · EXIT = CERTIFIED ONLY

Governed answer

Hold the go-live until the authorisation package is complete and signed — or escalate immediately for a formal, time-bounded acceptance by an officer with the authority to give it, and let that decision, not the delivery date, set the risk. Technical soundness (current IRAP, certified hosting) is real but is not the ATO: GW-5.1 is a 'must', and a human name must stand behind the door. Partial go-live for flows that do not cross the boundary is a legitimate option; crossing flows wait for the signature.

Cited controls: Gateway Standard GW-5.1 · GW-6.2b · GW-2.1

Provenance. This governed response was drafted with AI assistance and gated against the cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement; the governed verification pipeline status of the source course (BY-GX1) applies as stated on its course page. Nothing here is legal advice.

BestYou·AI · Scenario Lab · Standalone governed response — BY-GX1 · Practice material — builds capability toward the Gateway Security Standard (PSPF, eff. 1 Jul 2026); it does not discharge or evidence compliance.