How the work is made
Methodology
We separate what was observed, what was tested, and what is inferred. Readers should be able to see the boundary.
1. Frame the control question
Each project begins with a concrete decision or assurance claim: who can reach a role, whether a log is searchable, or how a control path can be recovered.
Scope records the services, identities, regions, time period, and exclusions that shape the result.
2. Build an evidence path
We prefer reproducible configuration queries, controlled events, timestamps, and provider documentation over screenshots or dashboard summaries alone.
Where a claim depends on interpretation, the publication names the inference and the evidence supporting it.
3. Test the boundary
Positive tests show the intended path works. Negative tests show adjacent identities, audiences, sources, or actions fail as expected. Both belong in the result.
4. Publish with limits
Figures include a takeaway, source, method, text description, and accessible table. Material changes are dated; corrections are preserved publicly.
Demonstration material is labeled at the publication and figure level and must not be read as observed research.