# Access Control
**Entity class:** Security, Compliance, And Authorization Layer concept
**Access Control** is a governance and assurance mechanism that constrains who may use data, for what purpose, under what controls, and with what audit evidence. Access Control belongs in the ontology because AI can compute over this structure while analysts retain responsibility for interpretation and authorized action.
## Counterterrorism predictive-graph role
Its controls are part of the computational trust fabric, not peripheral paperwork: permissions, provenance, purpose, and auditability must remain machine-enforceable across systems. The analytic state should distinguish ground truth, observed evidence, inferred state, and predicted state.
## Relationships
- **domain router:** [[wiki/Assurance Infrastructure|Assurance Infrastructure]].
- **ontology neighbors:** [[wiki/Identity and Access Management|Identity and Access Management]] and [[wiki/Attribute-Based Access Control|Attribute-Based Access Control]].
- **synthesis:** [[wiki/Counterterrorism Predictive Graph|Counterterrorism Predictive Graph]] and [[wiki/Predictive Intelligence Loop|Predictive Intelligence Loop]].
## Sources
- [NIST SP 800-53 Rev. 5, Release 5.2.0, August 27, 2025](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)
- [ODNI — ICD 503, Intelligence Community Information Technology Systems Security Risk Management, September 15, 2008](https://www.dni.gov/files/documents/ICD/ICD_503.pdf)
**As of:** 2026-09-23