# Threat Model Scope Must Include Delegated Emergency Authority

- **Artifact ID:** CHQ-SM-2026-004
- **Canonical source ID:** CHQ-ANRM-2026-003
- **Version:** v1.0
- **Status:** ISSUED
- **Public record:** https://record.cybersecurityhq.com/memoranda/chq-sm-2026-004
- **Machine-record SHA-256:** `fd130c5062a7fac414d05c02934946112a6903a4f519a8758b1a76fd7358cab5`

## Complete structured record

```json
{
  "id": "CHQ-ANRM-2026-003",
  "aliases": [
    "CHQ-SM-2026-004"
  ],
  "title": "Threat Model Scope Must Include Delegated Emergency Authority",
  "descriptor": "Delegated Emergency Authority in Threat Models",
  "issued": "2026-02-08",
  "classification": "Analytical Research / Non-Advisory",
  "status": "ISSUED",
  "version": "v1.0",
  "memo_type": "ANRM",
  "authority_level": "ANALYTICAL",
  "inherits_from": "CHQ-ACJ-2026-001",
  "related_artifacts": [
    "CHQ-ANRM-2026-001",
    "CHQ-ANRM-2026-002"
  ],
  "citable_assertion": "Third-party incident responders granted privileged access during incident conditions operate inside the organizational threat model based on capability class and failure-mode equivalence, not contractual relationship.",
  "purpose": "This memo applies the principle that threat model scope is determined by capability class and failure-mode equivalence to a specific actor class: third-party entities granted privileged access during incident response, crisis operations, or emergency remediation.\n\nIt does not prescribe remediation actions, assess vendor performance, evaluate organizational maturity, or determine contractual liability.",
  "statement": "Third-party entities granted privileged system access under incident conditions should be treated as operating inside the organizational threat model. The access path is evaluated by its properties, not by the relationship that authorized it.",
  "observability": "",
  "boundary": "",
  "reliance_language": "",
  "reliance_boundary": "",
  "revision_history": "v1.0 (February 8, 2026): Initial issuance",
  "scope": "This memo applies the inherited principle to a specific actor class: third-party entities granted privileged access during incident response, crisis operations, or emergency remediation.\n\nIt does not prescribe remediation actions, assess vendor performance, evaluate organizational maturity, or determine contractual liability.",
  "governance_condition": "Incident response access introduces privileged access paths under conditions where governance is structurally weakened: oversight is compressed, exception-mode permissions are granted rapidly, and revocation depends on post-incident process rather than real-time enforcement.\n\nAny actor that can execute, persist, or delay its own revocation without real-time organizational oversight is inside the threat model. This test is binary. It does not admit degrees of trust, reputation, or contractual intent.\n\nOnce privileged access is granted under emergency authority, any governance framework that treats the granting organization as retaining exclusive execution control is internally inconsistent unless contemporaneous authority transfer is explicitly recorded.\n\nThis test applies uniformly. It does not distinguish between external incident responders and internal administrators operating under emergency authority. Any argument that excludes external responders from threat model scope on the basis of contractual relationship necessarily excludes internal emergency administrators on the basis of employment relationship. The logic is symmetric or it is broken.\n\nThe structural condition is not the trustworthiness of the responding entity. The structural condition is the properties of the access granted under incident conditions.\n\nIn most incident engagements, no contemporaneous artifact records which entity held execution authority over recovery actions at any given point during the response window. Accountability is commonly evidenced by engagement letters and post-incident reports, neither of which establishes who controlled what, when. Where no contemporaneous authority record exists, execution authority is treated as having defaulted to whichever entity held active credentials with the capability to act.",
  "inherited_principle": "From CHQ-ACJ-2026-001 (Capability-Determined Threat Model Scope):\n\nThreat model scope is determined by capability class and failure-mode equivalence, not by trust, intent, contractual relationship, or organizational proximity.",
  "classification_consequences": [
    "Incident response access paths are classified as threat model surfaces subject to the same architectural evaluation as internal privileged access paths.",
    "Accountability for access-path risk is classified as residing with the delegating organization. Contractual scope limitations do not alter the classification of the access path's capability.",
    "Absence of real-time revocation capability does not reduce an access path's threat model classification. Classification is determined at the point of access grant, not at the point of revocation.",
    "A signed incident response retainer with scope limitations, access controls, and contractual liability provisions does not satisfy the threat modeling requirement established by this memo. Contractual governance of a relationship is not architectural governance of an access path.",
    "Governance assertions that rely on contractual scope, engagement letters, or post-incident reporting as evidence of retained execution control are classified as non-contemporaneous and insufficient to establish authority at time of action."
  ],
  "exclusions": [
    "Trust or integrity assessments of specific incident response providers",
    "Commercial liability allocation between contracting parties",
    "Regulatory safe harbor or leniency claims arising from use of third-party responders",
    "IR tooling risk transference between provider and organization",
    "Prescriptive controls, vendor selection criteria, or remediation actions",
    "Whether incident response should be performed internally or externally"
  ],
  "historical_context": "This memo supersedes the operational territory previously addressed by CHQ-J-2026-006 (Third-Party Incident Response Operates Inside the Threat Model, Legacy). CHQ-J-2026-006 is retained as historical context.\n\nAssumption retired: that the temporary nature of emergency access reduces its threat model relevance. Duration does not constrain capability. Emergency delegation compresses time, not authority. An access path that exists for four hours with domain administration rights produces the same failure modes as one that exists permanently.",
  "example_reference": "\"Per CHQ-ANRM-2026-003, third-party incident response access paths are evaluated inside the organizational threat model based on capability class and failure-mode equivalence, not contractual relationship.\""
}
```
