Thursday, September 03, 2026

Security & Access Control - People, Ideas & Objects and Oracle Corporation

Date: 2026-08-11

Purpose

Synallagi is based on Oracle Cloud Enterprise Resource Planning and the related capabilities of Oracle Cloud Infrastructure. This provides People, Ideas & Objects with a current, secure and extensible foundation for financial management, procurement, projects, identity, access governance, integration, data protection and cloud operations.

The purpose of this relationship is not to assemble every Oracle security product within Synallagi. It is to use Oracle capabilities where they satisfy the requirements of the application, extend them where Synallagi introduces a distinctive oil & gas operating requirement, and preserve a clear division of responsibility between the Oracle platform and the Synallagi business model.

Oracle provides many of the foundational controls needed to identify users, authenticate them, manage roles, govern access, protect data, monitor activity and maintain cloud services. Synallagi must determine how those controls apply to producers, Joint Operating Committees, service providers, suppliers, temporary working groups, properties, Work Orders, Industrial Command & Control and the other relationships through which the industry conducts its work.

This distinction is essential. Oracle can establish that a person is who they claim to be and provide the mechanisms through which access is granted or denied. Synallagi must establish what authority that person holds, within which organization and Joint Operating Committee, for which property and purpose, during what period, and subject to which business, financial, contractual and operational constraints.

A Capability-Led Architecture

The original People, Ideas & Objects specification is based substantially on the Oracle products available in August 2026. Many of the underlying requirements remain valid, but Oracle's product structure and the delivery of enterprise applications have changed materially.

Synallagi will therefore specify required capabilities before selecting individual Oracle products. A product or service will be included only where its function is required by the target architecture and is not already provided appropriately by Oracle Fusion Cloud Applications or Oracle Cloud Infrastructure.

The architecture will apply the following order of preference:

  • Use the security and business controls delivered with Oracle Fusion Cloud Applications.
  • Use Oracle Cloud Infrastructure identity, governance, integration and security services for Synallagi extensions and connected services.
  • Use Oracle database security and recovery capabilities for databases controlled by People, Ideas & Objects.
  • Introduce Oracle Fusion Middleware identity products only where an on-premises, hybrid or legacy integration requirement makes them necessary.
  • Implement a Synallagi capability where the requirement is specific to the oil & gas operating model and is not the responsibility of the Oracle platform.

This approach reduces duplication, avoids unnecessary product dependencies and allows Synallagi to benefit from Oracle's continuing cloud development without binding its business design to a historical product catalogue.

Identity Across Organizational Boundaries

Synallagi operates across organizational boundaries. Its users include employees and representatives of producers, members of Joint Operating Committees, service providers, suppliers, contractors, professional advisers and participants in temporary research or operating groups. A person may represent more than one organization or exercise different responsibilities in different circumstances.

Oracle Cloud Infrastructure Identity and Access Management identity domains provide the current foundation for authentication, identity lifecycle management, federation, single sign-on and secure application access across Oracle and non-Oracle services. Oracle Fusion Cloud Applications environments are provisioned with an identity domain that is integrated with Fusion Applications and can support authorized extensions and integrations. Oracle identifies a custom partner application connected to Fusion Applications as an appropriate extension use case.

Synallagi will use identity federation so that participating organizations can authenticate their people through trusted organizational identity providers where appropriate. Federation reduces duplicate credentials and allows an organization to remain responsible for the primary employment or affiliation status of its people. It does not, however, automatically grant access to Synallagi or membership in a Joint Operating Committee.

Admission to Synallagi requires a governed relationship among:

  • the person;
  • the organization represented by the person;
  • the trusted source of the person's identity;
  • the person's approved Synallagi participation;
  • any Joint Operating Committee or service-provider relationship;
  • the effective period of that relationship; and
  • the sponsor, approver or agreement under which participation is established.

Separate identity domains may be appropriate for distinct user populations, particularly non-employees and industry participants requiring separate administration, terms of use, profile management or consent. The final identity-domain design will be based on population, trust, administration, privacy, scale, subscription and operational requirements and will be confirmed with Oracle during implementation.

Identity Is Not the Industry Business Directory

An identity service should contain the information required to authenticate a person, associate that person with trusted identifiers and administer access. It should not become the master repository for every supplier profile, professional capability, calendar, commercial relationship or industry contact.

Synallagi will separate identity information from business-party information.

Oracle Fusion Cloud Procurement and Oracle Supplier Portal provide current capabilities for supplier registration, supplier-maintained profiles, contacts, products and services, user provisioning and controlled supplier access. The Resource Marketplace and other Synallagi capabilities will add the industry-specific descriptions, qualifications, availability, performance evidence and relationships needed by producers and Joint Operating Committees.

This separation allows a supplier or service provider to maintain relevant business information without being permitted to alter the security decisions of a producer or Joint Operating Committee. It supports data minimization: identity systems retain the minimum information needed for trust and access, while authoritative business applications retain the richer information needed for transactions and operating relationships.

One User Experience Without Repeated Authentication

Users should be able to move among authorized Oracle Fusion Cloud Applications, Synallagi extensions and connected services without repeatedly entering credentials. Current identity domains, federation and token-based authentication replace the former dependence on desktop-oriented enterprise single sign-on products.

The experience must remain secure and convenient. Sign-on policies, multi factor authentication, adaptive security, device and network conditions, session controls and stronger verification for sensitive actions will be applied according to risk. A routine inquiry and a material change to financial authority should not necessarily require the same level of assurance.

Authentication establishes confidence in identity. Synallagi must still evaluate authorization for every material request. A successful sign-on must never be treated as authority to view every record or perform every function available through the application.

The Oracle Fusion Cloud Application Security Foundation

Oracle Fusion Cloud Applications provide the first layer of application security. The Security Console supports user and role administration, role analysis, role hierarchies, role assignments, privileges, data security policies and related security management. Oracle Cloud Enterprise Resource Planning applies a relationship among the user, the role and the applicable data context. Oracle summarizes this as who can do what on which data.

Synallagi will use delivered Oracle roles, privileges and data-security mechanisms where they correspond to the required business responsibility. Custom roles will be created only where the delivered design does not meet the requirement, and they will grant the minimum privileges necessary.

Oracle's delivered data contexts include structures such as business units, ledgers, data access sets, asset books, legal entities, intercompany organizations, project organizations and other enterprise structures. These controls will be used wherever they align with Synallagi's financial, procurement, project and organizational requirements.

A Joint Operating Committee and its property context introduce additional relationships that cannot be assumed to exist in every delivered Oracle security structure. Synallagi must therefore supplement Oracle application security with its own governed context. The two layers must operate together:

Oracle security determines whether the user may perform the underlying application function and access the applicable Oracle business data.

Synallagi determines whether the user may perform that function for the selected Joint Operating Committee, property, role, purpose, Work Order, command assignment and effective period.

Neither decision is sufficient by itself when an action crosses both layers.

Joint Operating Committee Context and Authority

The Joint Operating Committee is a central authority boundary within Synallagi. When a user enters a Joint Operating Committee workspace, the system must establish a signed and time-bounded operating context containing the selected property, participating organization, active role, command assignment, governing agreement, ownership version, information classifications and allowed capabilities.

Every material request must be evaluated against that context. The evaluation may include:

  • authenticated identity and current identity assurance;
  • organization and representation relationship;

Joint Operating Committee membership;

  • selected property and applicable agreement;
  • active role and command assignment;
  • delegated decision authority;
  • technical, operational and financial authority;
  • Work Order or other authorization;
  • record ownership and relationship;
  • information classification and Intellectual Property permission;
  • purpose of access;
  • effective date and time;
  • segregation-of-duties restrictions;
  • location, device or session risk where applicable; and
  • emergency or exceptional authority.

Changes to any of these conditions must be reflected promptly in access. If a person leaves an organization, a producer withdraws from a property, a command assignment ends, a Work Order closes or delegated authority is revoked, the related access must expire without depending on a manual review of every application screen.

This dynamic evaluation is the modern expression of the objective originally assigned to Oracle Entitlements Server. Oracle roles and Oracle Access Governance provide important parts of the solution. The complete decision remains a combination of Oracle controls and Synallagi's business context.

Industrial Command & Control

Industrial Command & Control establishes operational roles, reporting relationships, delegation, escalation and effective assignments among the people and organizations participating in work. Security & Access Control ensures that those assignments are reflected in access to information, decisions and application functions.

  • The two capabilities are related but must not be confused.
  • Identity confirms the person.
  • Industrial Command & Control establishes operational position and direction.
  • Joint Operating Committee governance establishes decision rights.
  • A Work Order authorizes participation, scope, funding and charging.
  • Security & Access Control permits the information and system actions required to exercise valid authority.

Availability of a person or capability does not grant operational authority. Operational authority does not automatically grant authority to spend. Permission to view a record does not grant authority to approve it. One person may hold several roles, but Synallagi evaluates the role being exercised for the particular action.

Oracle's identity and governance services reduce the technical effort required to administer users and access. They do not replace the research, user-community design and application development required to model effective command and collaboration across independent organizations.

Temporary Working Groups and Work Orders

For innovation to be dispersed broadly throughout the industry and become a major focus of scientific development, substantially more collaborative research is required. Producers must be able to contribute to working groups formed through ad hoc relationships that are temporary and have a defined short-term purpose.

These working groups are not Joint Operating Committees. They are not organized around the governance and operation of a jointly owned property, and an Authorization for Expenditure is generally inappropriate. Participants may instead contribute assets, facilities, data, Intellectual Property, specialist talent, services or cash. Those contributions may need to be valued to establish each participant's entitlement to the resulting research, knowledge, Intellectual Property or other output.

Synallagi must therefore recognize the working group as a distinct organizational construct. It must establish its purpose, participants, contributions, decision rights, confidentiality, authority, duration, output ownership, permitted use, accounting treatment and completion conditions without forcing the relationship into a Joint Operating Committee or conventional capital-project model.

In the assessment of People, Ideas & Objects, these working groups have largely ceased to exist. A principal cause is the accounting burden placed upon contributors and originators. Their unusual and temporary relationships produce repeated questions about how contributions are authorized, valued, recorded, shared, recovered and reported. The administrative burden can become so great that the initiative is no longer worth pursuing.

One of the two principal purposes of the Synallagi Work Order is intended to resolve this problem. The Work Order may govern a temporary research or innovation collaboration, or authorize work undertaken for a property or Joint Operating Committee. For a working group, it establishes the common record through which participation, contributions, valuation methods, budgets, cost sourcing, charging, rights to output, approvals and closure are defined.

Federated identities and supplier or capability profiles provide trusted information about prospective participants. The Work Order establishes the business basis for their participation, including scope, funding, contribution, cost sourcing, charging and effective period. Industrial Command & Control assigns the operational structure. Security & Access Control grants the minimum access required for each participant's work.

Temporary access must therefore be:

  • sponsored and approved;
  • linked to a specific purpose and organizational relationship;
  • limited to any relevant project, working group, Joint Operating Committee, property, records or functions;
  • effective for a defined period;
  • reviewed when the assignment changes;
  • automatically removed when the assignment or Work Order ends; and
  • retained in the audit evidence after the access itself expires.

Emergency access may be permitted where delay would create unacceptable operational, safety, environmental or financial risk. It must be time-limited, conspicuous, fully recorded and subject to prompt review and confirmation by the appropriate authority.

Identity Lifecycle and Delegated Administration

Access must follow the lifecycle of the person and the business relationship. Synallagi requires controlled processes for registration, sponsorship, verification, approval, provisioning, modification, suspension, recertification and removal.

Oracle Access Governance provides a current cloud-native foundation for identity orchestration, access requests, policy-based access, access reviews, access certification and remediation across cloud and on-premises systems. It integrates with Oracle Fusion Cloud Applications and can manage application accounts and role assignments.

Delegated administration is necessary because People, Ideas & Objects cannot maintain every participant's information centrally. Producers, suppliers and service providers should be able to maintain approved portions of their organizational and contact information and request access for their people. The receiving producer, Joint Operating Committee or People, Ideas & Objects authority retains control over what access is granted.

Delegation itself must be governed. A supplier administrator may manage eligible people from that supplier but must not assign internal producer roles, expand access beyond the supplier's permitted scope or approve the supplier's own exceptional privileges without independent control.

Access Requests, Reviews and Segregation of Duties

Oracle Access Governance and Oracle Fusion Cloud Risk Management provide current capabilities for access requests, access certification, sensitive-access analysis and segregation-of-duties controls. Preventive analysis can identify conflicting access before a requested role is provisioned. Periodic, event-based and targeted reviews can determine whether existing access remains necessary.

Synallagi will apply these capabilities to both conventional corporate responsibilities and the smaller, cross-company organizations formed through Joint Operating Committees.

Small organizations create a particular challenge because a limited number of people may perform several functions. Synallagi must identify material conflicts, prevent combinations that cannot be accepted and document compensating controls where complete separation is impractical. Compensating controls may include an independent approval, lower transaction limit, additional evidence, retrospective review, restricted duration or participation by another producer.

Oracle products can support internal control and provide compliance evidence, but their use does not make an organization compliant by itself. Compliance depends upon the complete design and operation of policies, responsibilities, controls, evidence, review and remediation.

Understanding Who, What, Why and How

The Security & Access Control strategy must explain more than whether access is technically allowed. Synallagi must preserve enough evidence to determine:

  • who performed or attempted the action;
  • which organization the person represented;
  • which role and authority were exercised;
  • which Joint Operating Committee and property were active;
  • what information, function or transaction is involved;
  • when and from what session the activity occurred;
  • why access is required;
  • which agreement, assignment, Work Order, decision or approval supported it;
  • what policy decision is made;
  • what result or change followed; and
  • whether an exception, conflict or override occurred.

Raw technical logs cannot establish all of this meaning. Oracle services can record authentication, role, application and database activity. Synallagi must connect those records to its business context, authority records and transaction history.

Audit evidence must be protected from inappropriate alteration and retained according to legal, regulatory, contractual and business requirements. Amendments correct or supersede prior information without erasing the record that was effective when the original action occurred.

Access analytics should identify excessive privileges, unusual activity, dormant accounts, repeated denials, conflicting roles, inappropriate administrator activity and access that no longer corresponds to a valid business relationship. Analytics and artificial intelligence may assist reviewers, but material access and remediation decisions remain governed, explainable and reviewable.

Information Classification and Confidentiality

Synallagi will protect information according to its ownership, business relationship, sensitivity and permitted purpose. Relevant classes include producer-private information, Joint Operating Committee information, service-provider working information, market-disclosure information, confidential technical and reserve information, financial information, personal information, strategy and Intellectual Property.

Classification must apply consistently to transaction processing, search, reporting, analytics, notifications, documents, exports, caches, training data and generated content. Moving information into a report, analytical model or artificial intelligence process must not weaken its original restrictions.

Oracle Fusion Cloud application security and data contexts will protect information held in delivered applications. Synallagi-controlled databases may additionally use Oracle Database security capabilities. Transparent Data Encryption protects information stored in database files and backups. Oracle Database Vault can restrict inappropriate privileged-administrator access. Data Redaction or application controls may be used where particular displayed values require protection.

Encryption at rest and in transit is a baseline requirement, but encryption alone does not determine who may see information after it is legitimately decrypted. Identity, authorization, context, classification, auditing and key management remain necessary.

Database Security, Monitoring and Configuration

Oracle Data Safe provides a current cloud service for database security assessment, user assessment, sensitive-data discovery, masking, activity auditing, alerts, security policies and centralized management of Oracle Database firewall controls for structured query language activity. It will be evaluated as the principal security-management service for Synallagi-controlled Oracle databases.

Oracle Audit Vault and Database Firewall may be appropriate where Synallagi requires centralized audit collection and database activity monitoring across on-premises, hybrid, Oracle and non-Oracle databases. It is not automatically required for Oracle Fusion Cloud Applications, where the underlying database is operated as part of Oracle's cloud service.

Database firewall controls operate through configured or learned policies. They should not be described as automatically knowing every statement that is valid for every user and application. Their effectiveness depends upon deployment architecture, policy quality, monitoring, exception handling and continued maintenance.

Configuration security will be based on approved baselines, controlled changes, environment separation, automated deployment where appropriate, security assessment, drift detection, remediation and evidence. A configuration-management service should not be assumed to reverse every incorrect change automatically. Oracle Data Safe, Oracle Cloud Infrastructure services and Oracle Enterprise Manager may each contribute depending upon which party operates the database or platform.

Backup, Recovery and Historical Information

Backup and recovery are business-continuity capabilities, not simply storage functions. The Synallagi recovery architecture must establish:

  • which information and services must be recoverable;
  • acceptable data loss and restoration time;
  • backup frequency and retention;
  • encryption and key availability;
  • administrative separation;
  • protection against deletion, compromise and ransomware;
  • regional and service-failure scenarios;
  • long-term retention requirements;
  • restoration testing; and
  • evidence that recovery objectives are being met.

For Oracle Cloud databases, Oracle Database Autonomous Recovery Service provides a current managed backup and recovery capability with enforced backup encryption and isolation of backup infrastructure. The final service selection will reflect the databases used by Synallagi and the applicable subscription and recovery requirements.

Historical query is separate from backup. Oracle Flashback Data Archive can preserve database changes for authorized historical access where it is appropriate to the data model. It does not replace backup, an application transaction history, immutable audit evidence or formal records management.

Extending Oracle Fusion Cloud Applications

The Synallagi requirements that are not delivered directly by Oracle Fusion Cloud Applications will be implemented through supported cloud configuration, extension and integration methods.

Oracle Visual Builder Studio supports application extensions and additional application interfaces within the Fusion Applications ecosystem. Oracle Integration and secured application programming interfaces support controlled information exchange and process coordination. These capabilities provide the technical means to develop Joint Operating Committee workspaces, Industrial Command & Control, Resource Marketplace interactions, Work Order relationships and other Synallagi functions while continuing to use Oracle applications as authoritative sources for the business information they own.

Extensions must not duplicate or bypass Oracle controls. They must preserve:

  • the authenticated user and active identity domain;
  • Oracle application roles and data access;
  • the selected Joint Operating Committee and property context;
  • source-system ownership of records;
  • transaction and approval controls;
  • information classification;
  • traceability across interfaces; and
  • the security effects of changes in either Oracle or Synallagi authority.

Configuration and extension designs must accommodate Oracle's cloud update lifecycle. Security-critical workflows and integrations will be tested against scheduled Oracle updates before production adoption.

Conditional Use of Oracle Fusion Middleware

Oracle continues to provide Oracle Identity and Access Management products for on-premises and hybrid environments. These products remain relevant where Synallagi must integrate legacy applications, locally operated directories or customer-controlled infrastructure. They are not the default foundation for a cloud-first Synallagi implementation.

Where such requirements exist:

  • Oracle Access Management may protect on-premises web applications.
  • Oracle Identity Governance may support provisioning and governance across locally operated systems.
  • Oracle Internet Directory or Oracle Unified Directory may provide directory services.
  • Oracle Unified Directory virtualization may present controlled views across existing directories.
  • Oracle Advanced Authentication and Oracle Adaptive Risk Management replace the former Oracle Adaptive Access Manager direction.
  • identity federation is provided as an integrated capability rather than requiring the former standalone Oracle Identity Federation architecture.

The former Oracle Enterprise Single Sign-On Suite, Oracle Identity Analytics and Oracle Total Recall names should not be used as target-architecture products. Their required capabilities are now met through current identity domains, Oracle Access Governance, Oracle Fusion Cloud Risk Management, current database services and Oracle Flashback technology.

Every middleware addition creates licensing, operation, patching, availability, integration and specialist-support obligations. Its inclusion must therefore be justified by an explicit requirement and confirmed with Oracle.

Development With Oracle and the User Community

Oracle's current platform substantially reduces the amount of foundational security technology that People, Ideas & Objects must develop. It does not remove the need for sustained design and research.

The most difficult questions concern how independent organizations should work together: how authority originates, how it is delegated, how temporary groups form, how costs and obligations are accepted, how operational direction is exercised, how trust is established and how accountability is preserved. Those questions must be resolved with producers, engineers, geologists, service providers, security specialists, auditors, legal advisers and Oracle Services specialists.

People, Ideas & Objects will use our user community to test these requirements through representative operating scenarios. Development costs can then be amortized across the producer community while each participating producer receives the benefit of the common architecture and accumulated industry learning.

Implementation Principles

The following principles govern the relationship between Synallagi and the Oracle platform:

  • Business authority is explicit and cannot be inferred solely from identity or organizational membership.
  • Every material action is evaluated in the correct Joint Operating Committee, property, organizational and temporal context.
  • Oracle-delivered controls are used before equivalent custom controls are developed.
  • Synallagi extensions preserve rather than bypass Oracle application security.
  • Identity information is separated from supplier, capability, contact and transaction information.
  • Access is limited to the minimum information and functions required for an approved purpose.
  • Temporary and delegated access has an owner, reason, effective period and automatic end condition.
  • Authority to view, decide, direct, perform, approve and spend remains distinguishable.
  • Segregation of duties and compensating controls are evaluated in the complete cross-company process.
  • Audit evidence connects technical activity with business purpose, authority and result.
  • Encryption, backup, recovery and historical access are designed as separate but coordinated controls.
  • Analytics and artificial intelligence do not weaken confidentiality, authority or accountability.
  • On-premises middleware is introduced only for a demonstrated hybrid or legacy requirement.

- Commercial availability, licensing and supported configurations are confirmed with Oracle before implementation commitment. 

- People, Ideas & Objects Intellectual Property ownership and permitted use are explicit, controlled, auditable and enforceable.

- The architecture is reviewed continuously as Oracle services and Synallagi requirements develop.

Current Oracle Direction

The Oracle product direction in this section is validated against Oracle documentation available in August 2026. At that time, the principal Oracle capabilities applicable to this architecture were:

  • Oracle Cloud ERP
  • Oracle Fusion Cloud Applications Security Console, application roles and data security;
  • Oracle Fusion Cloud Applications identity domains and Oracle Cloud Infrastructure Identity and Access Management;
  • Oracle Access Governance;
  • Oracle Fusion Cloud Risk Management, including access requests, access certifications and advanced access controls;
  • Oracle Fusion Cloud Procurement and Oracle Supplier Portal;
  • Oracle Visual Builder Studio and Oracle Integration;
  • Oracle Database encryption, Database Vault and Oracle Data Safe;
  • Oracle Audit Vault and Database Firewall where hybrid monitoring is required;
  • Oracle Database Autonomous Recovery Service; and
  • current Oracle Identity and Access Management middleware for justified on-premises or hybrid requirements.
  • Oracle's services will continue to change. Synallagi therefore treats these products as the present means of satisfying durable requirements, not as permanent substitutes for those requirements.
  • Oracle Reference Material
  • Oracle Fusion Cloud Applications Security Console
  • Oracle Fusion Cloud Applications data access
  • Oracle Fusion Cloud Applications identity domain for extensions
  • Oracle Cloud Infrastructure Identity and Access Management identity domains
  • Oracle identity-domain types
  • Oracle Access Governance
  • Oracle Access Governance integration with Fusion Cloud Applications
  • Oracle Fusion Cloud Risk Management advanced controls
  • Oracle Supplier Portal user provisioning
  • Oracle Visual Builder Studio
  • Oracle Integration
  • Oracle Data Safe
  • Oracle Data Safe activity auditing
  • Oracle Transparent Data Encryption
  • Oracle Data Redaction
  • Oracle Database Vault
  • Oracle Audit Vault and Database Firewall
  • Oracle Database Autonomous Recovery Service
  • Oracle Database Flashback technology

Wednesday, September 02, 2026

Security & Access Control - Architecture Brief

Architecture Brief

Date: 2026-06-27

This brief establishes the target direction for the Security & Access Control module and defines the architectural structure through which its business vision is to be implemented. The module is a central specification for trust, authority, accountability, cybersecurity, markets, transactions, artificial intelligence and cross-organizational participation in Synallagi.

Governing thesis

Security and Access Control in Synallagi is not only the administration of users, roles, passwords, or screens throughout North American oil & gas. It is the operating policy system that determines:

- who or what is acting;

- whom they represent;

- which organization, Joint Operating Committee, market, transaction, asset, or assignment is in scope;

- what duty they are performing;

- which information and functions they may use;

- what business authority they possess;

- what accountability attaches to the action;

- what evidence must be retained; and

- when access must be denied, escalated, reviewed, suspended, or revoked.

The intended outcome is to enable the right person, with the right access, to the right information, at the right time, in the right place, on the right device, with the right authority, and through the right method of engagement.

Design posture

Synallagi should pursue quality of architecture over quantity of prose. The module should be built in layers:

1. Conceptual model.

2. Target architecture brief.

3. Technical companion specification.

4. Section-by-section expansion.

5. Traceability back to the original specification and related modules.

The immediate objective is not to finalize every rule. It is to establish a strong enough structure that later sections can be developed without repeatedly reopening the foundation.

There are few short-term solutions to the shortfall in geologists and engineers over the next twenty years. It takes the better part of that time to train them to operate in the industry. What we do know are several "things" being applied in the People, Ideas & Objects Synallagi. Many of these concepts are based on what we call Industrial Command and Control. Which is a method developed in the Security & Access Control module of imposing command and control over any and all Joint Operating Committees, working groups, producer firms, service providers or internal or external organizations the producer may need to add structure to. The concepts are the further hyper specialization and division of labor, and a reduction in the redundant building of capabilities within each oil & gas producer, or as we describe it, a pooling of resources in the Joint Operating Committee.

The first concept of specialization and division of labor is well known as a principle of economics that brings about greater economic productivity from the same volume of resources. Given that the volume of earth science & engineering resources is known for the foreseeable future. Specialization and the division of labor will provide industry with a tangible means to deal with oil & gas industry productivity. In today’s marketplace, approaching a heightened level of specialization and division of labor without software to define and support it would be unproductive.

The pooling concept is the solution to the current desire that each producer firm acquires the earth science & engineering capabilities necessary to deal with all the needs of their “operated” properties. This creates unneeded “just-in-time” capabilities for scarce scientific resources. When each producer within the industry pursues this same strategy substantial redundancies are built into the industry's capabilities. Redundancies that are left unused and unusable. What is proposed through the People, Ideas & Objects software application modules is that the producer's operational strategy avoids the “operator” concept. Instead, it pools their specialized technical resources through the Joint Operating Committee partnership. That way the redundancies that would have been present in the industry can be made available to the producers and used by the producers through hyper-specialization and division of labor.

These same principles are present in the second issue noted above. The administrative and accounting capabilities acquired through industry-wide capabilities provide the producer with the flexibility to address operational concerns. Issues such as today’s low natural gas prices can be addressed through this revised structure. By having administrative and accounting service providers charge their service fees directly to the Joint Operating Committee. The producer gains the ability to shut-in unprofitable production with only positive effects on their financial performance. Administrative, accounting, and production costs are eliminated during shut-in production. Providing the most profitable means of oil & gas operations when unprofitable properties no longer dilute profitable properties. Producers can save their reserves for the time when they can be produced profitably. Reserves costs don't have to carry additional losses if unprofitable production continues. Reserves can be seen as a low-cost solution to production and storage. Commodity prices will have less volatility due to producers removing marginal production from the marketplace. And petroleum reserves values are maximized when prices determine reserves value and the volume of commercial reserves available.

Domain position

Synallagi is ecosystem-informed, user community-led, service provider-enabled, and technologically supported. Producers are essential participants, but they are not the exclusive source of operating knowledge.

The Security and Access Control module must therefore support a larger operating community:

- producers;

- Joint Operating Committees;

- working-interest participants;

- service providers;

- suppliers;

- engineers;

- geologists;

- accountants;

- administrators;

- auditors;

- financial participants;

- market participants;

- technology providers;

- artificial intelligence specialists;

- cybersecurity specialists; and

- People, Ideas & Objects.

The module must preserve independence, information rights, authority limits, and accountability while allowing these parties to collaborate through common transactions, markets, infrastructure, and evidence.

Being able to provide service providers with access to and security during these day-to-day operations will be a unique situation for the oil & gas producer. Service providers will aggregate data industry wide. Although the data they access will be voluminous, unattributable to its owner and of a specialized nature. And there will be many service providers involved in providing administrative and accounting services to the producer firm and Joint Operating Committees. Consideration of the security, access control and proprietary nature of the information will be priorities for Synallagi.

A quick note on mobility. People are provided with new devices that enable them to work anywhere. These phones and tablets, in addition to laptop computers, open up security and access control concerns for the innovative and profitable oil & gas producer. Some producers enable their staff with policies that allow them to bring their own devices to work. The fact is these devices provide enhanced productivity and are appropriate for an innovative and profitable oil & gas producer. People, Ideas & Objects Synallagi includes an understanding that these devices will be part of the day to day used in the oil & gas industry.

What these concepts require is what the Security & Access Control module is designed to provide. The system must provide access to the right person at the right time and at the right place, on the right device with the right authority to the right information and through the right method of engagement. With the Industrial Command & Control there will be a manner in which the technical, and all the resources, that have been pooled from the producers, interact with an appropriate governance and chain of command.

Organizational constructs

The module shall align with the nine organizational constructs currently identified for Synallagi:

1. Joint Operating Committee.

2. Endogenous Technical Change and sharing of infrastructure.

3. Hyper-specialization and division of labor.

4. Markets.

5. Innovation.

6. Intellectual Property.

7. Information Technology.

8. Trust.

9. Transactions.

These constructs are not merely labels. They define, support, and constrain what Synallagi recognize as legitimate organization, work, information, authority, access, and accountability.

Architectural principles

Explicit representation

Every consequential action must identify the party, organization, Joint Operating Committee, market, transaction, or other construct on whose behalf the action is performed.

No authority by implication

Access to a function does not by itself grant authority to commit a party, approve an expenditure, publish information, disclose market data, direct work, or bind a Joint Operating Committee.

Contextual least privilege

Access must be limited by duty, transaction, information classification, organizational construct, Joint Operating Committee, property, agreement, market, working interest, authority, time, device, session assurance, and accountability.

Accountability as a product strength

Accountability, auditability, and evidence are competitive strengths of Synallagi. The module should help restore confidence in oil & gas administration, financial reporting, investor communication, and operating integrity. As is noted earlier in the Industrial Command & Control section of this specification.

Cybersecurity is integral

Cybersecurity is not a separate afterthought. Identity compromise, unauthorized access, malicious administration, data leakage, ransomware, integration abuse, artificial intelligence misuse, and market manipulation all belong within the scope of this module.

Markets and asset participation

Markets are first-class security contexts. Marketplace access, disclosure, offer authority, bid authority, settlement, investment participation, and asset securitization require explicit authorization and evidence.

Blockchain, stablecoins, and crypto-based participation

Where Synallagi supports blockchain records, stablecoin settlement, digital wallets, or crypto-based participation in oil & gas assets, the module must govern identity, wallet control, beneficial ownership, transaction authority, investor reporting, financial statement publication, disclosure, custody, settlement, revocation, and incident response.

Artificial Intelligence under policy

Artificial intelligence systems may advise, prepare, reconcile, classify, monitor, or recommend. They may not infer representation, disclosure rights, or business authority. Any autonomous action requires explicit policy, accountable ownership, audit evidence, and enforceable guardrails.

Required conceptual separations

The module must keep the following concepts separate, even when an implementation platform combines parts of them:

- identity;

- authentication;

- organization;

- organizational relationship;

- represented party;

- Joint Operating Committee membership;

- market participation;

- wallet or payment instrument control;

- business role;

- duty;

- privilege;

- data entitlement;

- authority;

- responsibility;

- accountability;

- delegation;

- transaction state;

- information classification;

- cybersecurity risk;

- audit event; and

- policy decision.

This separation is necessary because a person may be authenticated but not authorized, employed but not assigned, assigned but not empowered, empowered but conflicted, or technically able to act without business authority.

Open design decisions

The following items should not be forced prematurely:

- the detailed role and duty catalogue;

- the detailed market participation model;

- wallet identity and beneficial ownership rules;

- stablecoin settlement and custody requirements;

- blockchain record authority;

- crypto-based asset securitization workflow;

- investor reporting from the Joint Operating Committee level;

- cybersecurity incident classifications;

- artificial intelligence execution boundaries;

- Targeting Framework access rules;

- revocation timing by event type;

- audit participation by accounting firms; and

- exact Oracle implementation mapping.

Only to Start the Ball Rolling for Our User Community

These decisions should be developed through focused pages and later folded into the module.

Tuesday, September 01, 2026

Security & Access Control - Conceptual Model

Conceptual Model

Date: 2026-06-27

1. Design intent

Synallagi operates across organizational boundaries. A person may work for one producer, represent another party under contract, participate in several Joint Operating Committees, perform a specialized duty for a limited period, support a marketplace, and possess different authority in each context.

A conventional statement such as "assign the user a role" is therefore insufficient. Synallagi must determine who the person is, whom they represent, where and in which organizational construct they are acting, what duty they are performing, which information and transaction are involved, the limit of their authority, and whether the current circumstances provide sufficient assurance.

This need for context becomes more important as Synallagi advances hyper-specialization and the division of labor. A geologist may specialize in a formation or geophysical theory. An engineer may specialize in a particular form of hydraulic-fracturing design. An administrative or accounting specialist may manage one narrow process within the Material Balance Report. A single producer or Joint Operating Committee may not generate enough demand to sustain these capabilities within only one producer. Synallagi must enable specialists to work across many producers, Joint Operating Committees, markets, and assignments without receiving broad or permanent access to all of them.

Synallagi is ecosystem-informed, user community-led, service provider-enabled, and technologically supported. Producers participate in this environment, but they are not its exclusive or dominant source of operating knowledge. The relevant community includes service providers, engineers, geologists, accountants, administrators, contractors, service-industry firms, financial participants, technology providers, artificial intelligence specialists, cybersecurity specialists, and other disciplines required to rebuild oil & gas accounting, administration, operations, governance, and marketplaces.

Industrial Command and Control remains the business model through which authority, responsibility, coordination, and accountability are established. Security and Access Control is the policy system that faithfully enforces that model. Its practical objective is to enable the right person, with the right access, to the right information, at the right time, in the right place, on the right device, with the right authority, and through the right method of engagement.

2. Governing principles

1. Explicit representation: every consequential action identifies the organization, market, Joint Operating Committee, or other recognized construct on whose behalf it is performed.

2. No authority by implication: access to a function does not by itself grant authority to commit a party, approve expenditure, disclose information, publish market data, or direct work.

3. Contextual least privilege: access is restricted by duty, information, organizational construct, Joint Operating Committee, property, agreement, market, transaction, time, authority, and accountability.

4. Independent revocation: ending one assignment removes only the access derived from that assignment.

5. No permanent trust from network location: identity, policy, and current context determine access.

6. Foundational accountability: every material decision remains attributable to an authorized human or explicitly governed automated authority.

7. Complete evidence: Synallagi records the basis on which material access and authority decisions were made.

8. Safe failure: uncertainty about identity, representation, policy, scope, authority, cybersecurity condition, or accountability results in denial or controlled escalation.

9. Technology-independent requirements: Oracle capabilities implement the model but do not define Synallagi's organizational concepts.

10. Governed change: roles, policies, conflicts, authority templates, market rules, wallet rules, and artificial intelligence guardrails are versioned and reviewed like other critical product configuration.

3. Core objects

3.1 Identity

An identity is the persistent digital representation of a human, service, integration, device, wallet, or automated agent. Its purpose is to give Synallagi one reliable subject to which authentication, organizational relationships, assignments, actions, and accountability can be attached. A human identity normally remains the same while the person's employer, producer representation, Joint Operating Committee memberships, market participation, duties, and authority change around it.

An identity is not an employee record, Joint Operating Committee member, role, wallet, account, or market participant. Those are relationships or assignments attached to the identity.

Identity is broader than federated identity. Federation is one method by which Synallagi may trust another organization's authentication of an identity. It does not create Joint Operating Committee membership, market participation, wallet authority, or business authority.

Each identity consists of a unique identifier, type, status, authoritative source, assurance information, and lifecycle. Non-human identities must have a named human or organizational owner.

3.2 Organization

An organization may be a producer, service company, supplier, regulator, auditor, financial participant, service provider, People, Ideas & Objects, or another recognized legal or commercial party. A market, Joint Operating Committee, user community, role, or wallet community may influence access but is modeled separately because it is not necessarily an organization.

3.3 Organizational relationship

This object establishes why an identity may represent an organization. Examples include employment, directorship, partnership representation, professional engagement, service contract, regulatory appointment, audit engagement, or approved marketplace participation.

The relationship represents an owner, sponsor, effective dates, status, and evidence. Ending it triggers review or revocation of all derived assignments.

3.4 Organizational construct

Synallagi organizational constructs define, support, and constrain what the application, its participants, and its automated processes may do.

The nine organizational constructs currently identified are:

1. Joint Operating Committee.

2. Endogenous Technical Change and sharing of infrastructure.

3. Hyper-specialization and division of labor.

4. Markets.

5. Innovation.

6. Intellectual Property.

7. Information Technology.

8. Trust.

9. Transactions.

An organizational construct is represented in security policy when it creates membership, authority, responsibility, information, process, market, technology, trust, or transaction boundaries. The constructs must not be reduced to technical roles. They are part of the institutional design that determines which relationships and actions Synallagi recognizes.

3.5 Joint Operating Committee

A Joint Operating Committee is the key organizational construct of Synallagi and a governed multi-party operating context. It has members, participating organizations, agreements, properties, decision rules, authority structures, information boundaries, effective dates, and accountability requirements.

The Joint Operating Committee is not merely a data-security segment. It is a domain object from which scoped authority and access may be derived.

3.6 Representation

Representation connects an identity, organization, and operating context. It answers: "For whom is this identity acting here?"

An identity may have more than one representation, including arrangements in which a small producer participates through another producer as a non-novated member. The active representation must be unambiguous when a material action occurs. Where dual representation creates a conflict, policy must prohibit the action or require declared mitigation.

3.7 Business role

A business role describes a recognizable position in an organization, Joint Operating Committee, market, user community, or service-provider process, such as working-interest representative, production engineer, controller, external auditor, formation specialist, transaction designer, wallet administrator, marketplace participant, or Material Balance Report reconciliation specialist.

A role groups duties but does not itself define all information access or authority.

3.8 Duty

A duty is a coherent responsibility such as preparing an Authorization for Expenditure, reviewing a voucher, approving a work order, reconciling production, certifying access, administering security, designing a transaction, qualifying a market participant, or reviewing blockchain settlement evidence.

Duties are the primary units used for least privilege, work rotation, segregation-of-duties analysis, and assignment of accountability.

3.9 Privilege

A privilege permits a system action such as view, create, amend, approve, post, export, administer, settle, tokenize, revoke, or invoke an application programming interface operation.

Privileges enable functions. They do not independently grant information access or business authority.

Synallagi application programming interfaces are private. Direct access is restricted to licensed developers, approved user-community participants, service providers, and authenticated runtime integrations. Public users receive only the compiled or runtime application functions intentionally exposed to them.

Unauthorized release or use of private application programming interfaces is a license, security, and intellectual property concern. The specification should state Synallagi's product policy clearly without relying on legal interpretation inside this module.

3.11 Authority

Authority permits a subject to make or approve a business commitment. It may be constrained by monetary value, ownership interest, voting threshold, technical discipline, geographic area, property, transaction type, market, wallet, settlement instrument, or emergency condition.

Authority is granted by an accountable body and must have an effective period and evidence for accountability and auditability. The system must make the origin, exercise, result, and subsequent review of authority visible.

3.12 Responsibility and accountability

Responsibility identifies the party expected to perform or supervise work. Accountability identifies the party answerable for the outcome. Neither should be inferred solely from technical access.

Accountability must persist from the assignment of authority through the transaction, resulting records, financial statements, investor communication, performance evaluation, and audit evidence.

3.13 Delegation

A delegation temporarily transfers specified duties or authority. It identifies delegator, delegate, scope, reason, dates, approval, conflicts, and revocation state.

Delegation cannot create powers the delegator does not possess, evade segregation-of-duties policy, or silently transfer accountability. Synallagi should support innovative delegation patterns developed through our user community where they are needed to preserve organizational continuity.

3.14 Policy

A policy expresses the conditions under which a request is permitted, denied, or escalated. Policies may be global, organizational, Joint Operating Committee-specific, resource-specific, transaction-specific, market-specific, wallet-specific, or method-specific.

3.15 Audit event

An audit event records who or what acted, represented party, context, action, resource, before and after state, evaluated policy, decision, authority basis, time, assurance, result, accountability, and correlation identifiers.

Synallagi shall restore audit controls to a central operational role and demonstrate their value across distributed workforces, artificial intelligence-assisted processes, Joint Operating Committees, markets, service-provider activities, blockchain-supported transactions, and crypto-based asset participation.

In addition to audit controls, People, Ideas & Objects invites accounting firms to establish their own user-community members to actively participate in software development. The objective is to integrate higher levels of accountability, assist audit needs, and reduce the overall costs of annual audits and statutory reporting for the oil & gas industry.

4. Access-decision model

Every protected operation is evaluated as:

Subject plus representation plus operating context plus duty plus action plus resource plus information scope plus transaction state plus authority plus time plus session assurance plus cybersecurity condition plus applicable constraints plus accountability assignment.

The decision process should answer:

1. Is the identity active and sufficiently authenticated?

2. Is its authoritative relationship still valid?

3. Which organization is it representing?

4. Is that representation valid for this producer, Joint Operating Committee, agency, employment assignment, market, wallet, or other recognized context?

5. Does the identity hold the required role and duty?

6. Does the duty provide the required system privilege?

7. Does the data entitlement include this exact resource?

8. Is the transaction in a state where this action is permitted?

9. Does the identity possess sufficient business authority?

10. Would the action create a segregation-of-duties or representation conflict?

11. Are time, session, device, location, identity assurance, and cybersecurity conditions acceptable?

12. Is additional approval, step-up authentication, or independent certification required?

13. Is the accountable party identified?

The decision and its material inputs are retained as evidence for consequential actions.

5. Trust boundaries

Boundary A — home organization to Synallagi

The home organization may authenticate its people and assert selected attributes. Synallagi determines which issuers, authentication assurances, attributes, and lifecycle signals it accepts.

Boundary B — organization to Joint Operating Committee

Employment or authentication does not automatically confer Joint Operating Committee membership. A valid Joint Operating Committee representation and assignment are separately required.

Boundary C — Joint Operating Committee to producer-private information

Participation in a Joint Operating Committee grants no implicit access to a producer's strategy, reserves analysis, internal correspondence, unrelated properties, or other private information.

This boundary does not restrict information that is public by law or regulation. Production volumes, well configurations, drilling records, hydraulic-fracturing information, and other prescribed records may need to be disclosed in considerable detail.

Boundary D — Joint Operating Committee to marketplace

Information and authority used in a Joint Operating Committee are not automatically publishable or usable in a marketplace. Disclosure and commitment require separate privileges and authority, except where a defined public-disclosure obligation applies.

Boundary E — human to automated agent

An artificial intelligence system or automated service receives only explicitly delegated information and actions. The system records whether output is advisory, prepared for approval, or executed under governed automated authority.

People, Ideas & Objects' intellectual property and Targeting Framework are intended to define the objectives, permissions, constraints, and boundaries within which agents operate. These guardrails must be implemented as enforceable policy and monitored behaviour, not only as instructions to the model.

Boundary F — application to integration

Every application programming interface client and integration has its own identity, owner, credential lifecycle, permissions, information scope, and monitoring. Shared technical accounts are prohibited except under an approved transitional exception.

Boundary G — market to asset ownership

Market participation, wallet control, stablecoin payment capability, or blockchain address control does not automatically establish beneficial ownership, authority to sell, authority to pledge, authority to vote, or authority to receive Joint Operating Committee-level financial statements. Those rights must be separately represented, evidenced, and governed.

6. Assignment lifecycle

Join

1. Establish or federate identity.

2. Verify organizational relationship and sponsor.

3. Admit the organization and representative to the applicable context.

4. Assign governed roles and duties.

5. Define information scope and authority.

6. Evaluate conflicts.

7. Obtain required approvals.

8. Provision and verify access.

9. Record evidence and notify relevant owners.

Recurring transaction designs should be expressed as governed templates. A template defines the persistent, generic elements of a transaction type: roles, duties, workflow, information requirements, controls, authority patterns, and audit evidence. Each assignment supplies the people, organizations, Joint Operating Committees, properties, values, dates, and other context unique to that transaction.

Move

Changes in employer, contract, represented organization, Joint Operating Committee, property, duty, authority, ownership, pooling assignment, market status, wallet authority, or transaction template trigger reevaluation. New access is not simply added to old access. Obsolete derived access is removed.

Leave

Termination, contract expiry, Joint Operating Committee withdrawal, assignment, novation, farmout, farmin, subsequent joint venture, working-interest disposition, suspension, loss of qualification, market removal, wallet compromise, or termination of a pooling assignment causes prompt reevaluation or revocation.

Review

Access is certified periodically and after material events. Reviewers assess not only the assigned roles but Joint Operating Committee membership, information scope, authority, delegation, privileged access, market access, wallet authority, artificial intelligence access, and unresolved exceptions.

7. Segregation-of-duties model

Conflicts should be defined at three levels:

1. Assignment conflict: incompatible duties are held concurrently.

2. Transaction conflict: one person attempts incompatible actions on the same transaction.

3. Representation conflict: one person represents parties with conflicting interests in the same decision.

A conflict may be prohibited, require a different actor, or proceed only with an approved mitigating control.

8. Illustrative decision scenarios

Authorization for Expenditure approval

A partner representative may approve an Authorization for Expenditure only for the represented partner and applicable Joint Operating Committee, within a valid assignment and monetary authority, after required authentication, provided the representative did not perform a prohibited conflicting duty.

8.a. Voucher review

A working-interest participant may view joint-account voucher information and supporting evidence to the extent established by the governing agreement and pooled Joint Operating Committee structure. Producer-private analysis, unrelated properties, and another participant's private annotations remain outside that entitlement.

Implementation within Synallagi is defined in the Accounting Voucher module. What is an accounting voucher is unique with particular characteristics for North American oil & gas and use of the Joint Operating Committee. A point of discussion is the Accounting Voucher can be saved as a template, added to as time passes and reused. When a template is deployed and is active within the accounting month it is then called a Synallagi. The Greek word for transaction, deal, business or exchange.

Marketplace participation

A market participant may offer services, bid, negotiate, or accept an assignment only within an approved market role, qualification, representation, disclosure policy, and authority limit. Marketplace participation does not create access to unrelated producer-private or Joint Operating Committee-confidential information.

Crypto-based asset participation

A holder of a crypto-based oil & gas asset may receive financial statements or other disclosures only when identity, wallet control, beneficial ownership, asset rights, disclosure entitlement, and regulatory obligations have been established. Control of a wallet alone is not sufficient to establish every right in Synallagi.

Hyperspecialized Material Balance Report work

One service provider may capture industry-level balancing adjustments as controlled transactions. Another may analyze, verify, and reconcile the adjustments. Further specialists may support individual producers or Joint Operating Committees in validating their resulting records. Each specialist receives only the process, information partition, and evidence required for their duty.

Artificial intelligence preparation of a recommendation

An artificial intelligence agent may read approved information and prepare a recommendation under its own workload identity. It may not represent a partner or approve the decision unless a future policy explicitly establishes governed automated authority.

9. Oracle mapping principle

Oracle Cloud Enterprise Resource Planning can implement substantial portions of function and data security. Oracle security administration and risk-management capabilities can support role administration, analysis, access requests, segregation-of-duties controls, access certification, and audit reporting.

Synallagi should inherit and configure Oracle-delivered security where it meets the requirement, then use supported extension points to add Synallagi-specific capabilities while maintaining a consistent user experience.

Synallagi must own the domain objects and policy semantics unique to the product: Joint Operating Committee membership, representation, pooling relationships, agreement scope, working interest, transaction authority, delegation, marketplace participation, hyperspecialized service-provider work, wallet participation, crypto-based asset rights, cybersecurity policy, and cross-organizational conflicts.

10. Remaining decisions

The following matters remain open and should be developed with our user community and service providers:

1. A complete catalogue of standardized and hyperspecialized roles and duties.

2. The precise relationship among working-interest voting, monetary authority, technical authority, pooled capability assignments, market authority, and wallet authority.

3. The detailed information-classification rules for each Joint Operating Committee artifact and public disclosure obligation.

4. Actions requiring dual control, step-up authentication, independent technical certification, or Compliance and Governance review.

5. Required revocation and reevaluation timing for each lifecycle event.

6. The actions artificial intelligence systems may prepare, recommend, execute, or never perform.

7. The security consequences of the nine organizational constructs.

8. The detailed blockchain, stablecoin, and crypto-asset participation model.

9. The cybersecurity control model appropriate to Synallagi's cross-industry role.

10. The access rules for the Targeting Framework.

Monday, August 31, 2026

Security & Access Control — Business and Technical Specifications. Part I

Note to Our User Community

This specification represents the beginning of the development process rather than its conclusion. It establishes the purposes, operating concepts, essential capabilities, responsibilities, controls, and architectural boundaries presently understood to be necessary for Synallagi. It does not contain every requirement that developers will eventually need, nor should it be interpreted as prescribing every design decision that will be made.

As custody of the specification passes from its originator to the Synallagi user community, responsibility for its continued development passes with it. Members of the community will be expected to test its assumptions against their experience, identify missing requirements, resolve ambiguities, and develop the operational detail needed to transform its concepts into a working product.

This transfer is not intended to constrain the community to the ideas presently documented. Members should feel free to propose new capabilities within the community, challenge existing assumptions, and pursue better ways of satisfying the purposes of Synallagi. They should build collaborative support for their ideas and support material proposals with detailed analysis of the business need, affected users, alternatives, benefits, costs, risks, dependencies, authorities, controls, and consequences involved.

Ideas should be welcomed while they are still forming. However, an idea should become a development requirement only after it’s been examined sufficiently to demonstrate that it addresses a genuine need, fits the wider product, and is supported by those whose work or responsibilities it will affect directly.

The community must avoid adding products, technologies, processes, controls, or complexity merely because they are available. Technical sophistication is not a benefit by itself. Every material addition should correspond to a defined business, operational, security, regulatory, or architectural requirement. The objective is to satisfy the needs of Synallagi completely and responsibly without burdening its users, developers, operators, or producers with unnecessary complexity and cost.

Under the Synallagi user community license, a qualified member may receive exclusive rights and corresponding responsibilities for a defined process domain that the member undertakes to manage on behalf of the oil & gas industry. These rights establish accountable stewardship. They are not merely permission to influence the product or control a body of functionality.

The Synallagi user community license establishes the following foundational principles of accountable stewardship and independent governance. These rights ensure that the community remains the primary driver of the product:

  • Exclusive authority to modify, develop, or create derivative works from the underlying intellectual property of Synallagi is reserved solely for licensed community members.
  • People, Ideas & Objects developers maintain an exclusive focus on community-led requirements, remaining unresponsive to external influences that have not been reconciled through our user community.
  • Members operate as independent business participants with autonomous budgetary control, ensuring their contributions represent genuine industry needs rather than the interests of external funding sources.

The license provides for the service-provider organization that the member will own and operate to implement, operate, maintain, support, and continue developing the processes within that domain. The member must therefore consider the complete life of the process, including:

  • Maintaining its business and technical specifications.
  • Building informed and representative support for proposed requirements.
  • Defining the information, actions, authority, events, controls, and evidence required.
  • Reconciling competing user needs and documenting material decisions.
  • Coordinating requirements that affect other Synallagi process domains.
  • Working with architects and developers to produce compatible solutions.
  • Establishing testing, acceptance, security, service, operational, and maintenance requirements.
  • Providing the documentation, training, support, governance, and continuity necessary for dependable industry use.
  • Managing future changes without losing the purpose, integrity, compatibility, or accumulated knowledge of the process domain.

Exclusive stewardship does not create unlimited authority to expand a process domain, introduce unnecessary complexity, or make decisions affecting other domains without consultation. Every material addition must remain traceable to a demonstrated industry requirement. Changes crossing process-domain boundaries must be collaboratively developed and reconciled within the wider Synallagi specification.

The proficiency demonstrated by Elon Musk in executing scientific endeavors of immense scale and intricacy remains unrivaled. Central to his methodology is an "algorithm"—a set of principles he asserts are fundamental to his success. Within Synallagi, this framework serves as a vital conceptual cornerstone, guiding our user community in the meticulous development and delivery of their products. As detailed in Walter Isaacson's Elon Musk, this algorithm consists of five essential components. (Isaacson, 2023, pp. 282, 284–285)

1. Question every requirement.

All requirements should be attached to the name of the person who made it. Always question the requirements, no matter who made it, and then try to improve them. p. 284

People, Ideas & Objects will require each of our user community members and developers to digitally sign their contributions. This process offers two key benefits: it ensures accountability by identifying the responsible individual, and it helps allocate service provider organizations to specific processes within Synallagi. The allocation will be determined by an AI algorithm developed by our user community, with digital signatures assisting in the guiding of appropriate assignments.

2. Delete any part or process you can.

You may have to add them back later. In fact, if you do not end up adding back at least 10% of them, then you didn’t delete enough. p. 284

Given the oil & gas industry's high rate of data distribution and duplication, this step challenges us to consider whether a single data source could eliminate redundancy. For further insight, refer to E.F. Codd’s Relational Theory in the bibliography. Where sharing the same data to different users who perceive the data differently.

A key lesson from software development is that while adding features is simple, it often leads to feature bloat; true innovation lies in simplifying the interface by removing unnecessary elements—even if that removal faces resistance.

3. Simplify and optimize.

This should come after step two. A common mistake is to simplify and optimize a part or a process that should not exist. p. 284

Although straightforward, this step underscores the time constraints often imposed by quarterly requirements, which frequently force organizations to bypass this global perspective. In many ERP implementations, budgets dictate the elimination of the user committee is the first element skipped, making our prioritization of our user community a distinct competitive advantage, resulting in improved software quality.

4. Accelerate cycle time.

Every process can be speeded up. But only do this after you have followed the first three steps. In the Tesla factory, I mistakenly spent a lot of time accelerating processes that I later realized should have been deleted. p. 284

5. Automate.

That comes last. The big mistake in Nevada and at Fremont was that I began by trying to automate every step. We should have waited until all the requirements had been questioned, parts and processes deleted, and the bugs were shaken out. p. 285

“If conventional thinking makes your mission impossible,” Musk told him, “then unconventional thinking is necessary.” p. 282

Synallagi divides automation into two distinct areas. The first area encompasses the automation integrated with Oracle Cloud ERP, included upon discovery. The second area involves automating the processes within Synallagi itself, which has been deferred to the third phase of development. For further details, please refer to our 2/10/2025 paper. Innovative Organization Excellence: How Elon Musk and Visionary Leaders Build High-Performance Enterprises.

Licensed members must preserve reasonable opportunities for affected users and producers, Joint Operating Committees and markets to contribute knowledge, question assumptions, propose alternatives, and participate in validation. Exclusive rights establish responsibility and accountability; they must not prevent the collaboration from which the quality and legitimacy of Synallagi will be derived.

The original specification provides the foundation. Our user community will transform that foundation into complete and testable requirements. Licensed process-domain stewards will establish and operate the service-provider organizations through which those requirements can be implemented, maintained, supported, and improved over time.

The quality of Synallagi ERP software will ultimately depend upon the quality of our user community and their stewardship.

Introduction

Joint Operating Committees are the key organizational construct of a dynamic, innovative, accountable and profitable oil & gas company. It is the interactions of many producers, service providers and suppliers who are involved in the day to day commercial and strategic concerns of that Joint Operating Committee that we need to concern ourselves with. The Security & Access Control module's focus is to ensure the right people have the right access to the right information with the right authority. This is at the right time at the right place and through the right device.

Throughout Synallagi we discuss two of the most pressing operational issues in the oil & gas industry. Those being the demand for earth science & engineering effort is increasing with each barrel produced. This is best represented by the steep escalation of oil & gas exploration and production costs. At the same time, critical earth science & engineering resources are fixed and difficult to expand. And with the anticipated retirement of this brain trust in the next twenty years, the problem becomes critical. The second issue regards the manner in which the administrative and accounting resources are organized within the industry. With Synallagi the need for each producer to develop their own administrative and accounting capabilities internally is replaced by an overall industry capability. Then each producer can access those resources on a variable cost basis with direct charges to the Joint Operating Committee. This provides operational flexibility in how a producer approaches its strategic and tactical needs to their distinct competitive advantages.

Business Specifications

Two Types of Data

When we talk about the various people within the producer firms affiliated with a Joint Operating Committee. And the number of Joint Operating Committees that a firm may have an interest in. And the number of people a firm employs. Access control becomes challenging. It becomes a challenge when we consider that people certainly should have the access required, but the level of trust they may have with respect to other partner organizations is probably not as strong. That is to say, does using the Joint Operating Committee as the key organizational construct of a dynamic, innovative, accountable and profitable oil & gas producer, open the producer firm to data loss? This is how People, Ideas & Objects deal with the access and trust issue in the Security & Access Control module.

3.10 Data entitlement

A data entitlement identifies the resources and records to which a privilege applies. Relevant scopes may include organization, business unit, ledger, Joint Operating Committee, property, well, agreement, partner, marketplace, wallet, blockchain address, work order, Authorization for Expenditure, voucher, settlement, or transaction.

Oracle AI Database 26ai or a later approved release is the intended principal data platform. Synallagi should therefore be treated in significant part as database-centred development, while access remains governed consistently through the application, policy, integration, and database layers.

When we concern ourselves with the data and information of the producer firm. We concern ourselves with the information cleared by the various Joint Operating Committees that the oil & gas producer’s interest is in. We can all agree that this information is proprietary and subject to each producer firm's internal policies. (Information such as reserves data, accounting information, internal reports and correspondence, strategy documents.) What we're concerned about is the information and data held in the Accounting Voucher module and the associated data common to the joint account. (well file, agreements, production data, capital and operating costs, revenue and royalties.)

Close analysis of these two types of data and information held within the firm and the Joint Operating Committee falls within the proprietary and partnership domains. In Canada at least, most data and information regarding well operations can be freely obtained through various regulatory agencies. Nonetheless, the majority of the data is shared through the partnership who have an interest in the data and information. Which is not the case with the producer firm's data. Most of the information is kept close at hand and reported through filtered reserve report summaries and annual reports. Therefore keeping a handle on proprietary data, while operating the Joint Operating Committee as the key organizational construct of the innovative oil & gas producer, as proposed by People, Ideas & Objects, does not present any data leakage.

Access control can therefore be limited by restricting any company personnel from viewing other companies' files. Which is a given. While in People, Ideas & Objects access control is restricted to the firm's Joint Operating Committees and the firm's files only. To extend this further, we would limit access to the appropriate roles within the firm. Then it is up to our user community to define a standard set of generic roles in which access is required to certain data types. This would apply to the types of operations handled by that role, for example, read, insert, update, delete. These generic roles could then be assigned to each individual within the organization based on their needs. Assigning multiple roles for more complex access. Access to proprietary data would be restricted to company personnel only.

Industrial Command & Control (ICC)

Throughout Synallagi we've discussed our solution to one of the premier issues the oil & gas industry faces. That is the demand for earth science & engineering effort per barrel of oil increases with each barrel produced. This is best represented by the steep escalation of oil & gas exploration and production costs over time. At the same time, critical earth science & engineering resources are fixed and difficult to expand in the short or medium term. Add to that the anticipated retirement over the next twenty years of the current brain trust of the industry and the problem becomes a critical concern.

What is proposed through the People, Ideas & Objects software application modules ICC is that the producer's operational strategy avoids the “operator” concept. Instead, it pools these technical resources through each of their partnerships represented in their Joint Operating Committees. That way the inefficiencies that would have been present in the industry can be made available and used through industry wide, producer focused, advanced and advancing specialization and division of labor. Where many of the lower end processes are offloaded to service providers who specialize in that basic skill on behalf of many producers. This is done in a geographical area or other specialization. And each individual producer focuses on a specialized element of science as it develops and innovates upon that.

People, Ideas & Objects believe producers will soon be unable to commercially support the full scale of engineering & earth science disciplines tasks and responsibilities as they have in house. This will be due to the shortages of resources, the cost escalation of these resources in the market due to their shortages, the expansion of demand from higher production volumes to achieve energy independence, the demands for more science in each incremental barrel of oil produced, the anticipated, substantial expansion of the sciences and the need to innovate upon that expanding science. For producers to maintain a broadened division of labor to deal with these issues and “operatorship” capabilities, it will extend them beyond any producer's commercial capacity.

What these concepts demand is what the Security & Access Control module is designed to provide through the ICC. The People, Ideas & Objects system must provide access to the right person at the right time and at the right place. This is with the right authority and the right information. With the ICC there will be a manner in which the technical and all the resources pooled from the producers, interact with the appropriate governance, compliance and industry standard chain of command.

Before the hierarch, a commercial development of the 20th century, only the military structure existed to organize large populations of individuals. The main difference between the two is subtle but significant. Military structures are broader and flatter than hierarchy. That is one of the ideals we are seeking, but the more significant feature is the ability for the chain of command to span multiple internal and external organizational structures and to move resources from different areas of the military through standardization.

The nature of people working through the industry-standard chain of command layered over the Joint Operating Committee will include all oil & gas disciplines. The contributions of staff, financial and technical resources will include all those employed by the industry today. I could foresee many office buildings being refurbished to accommodate the staff of a single Joint Operating Committee of a large property. There, staff from the different producers may be seconded to provide support for the Joint Operating Committee. They may work for a single Joint Operating Committee, not for any particular producer firm.

As background we should recall that each individual would have different access levels and authorizations to access to People, Ideas & Objects Synallagi. Assuming different roles and responsibilities, they would impose different access levels to data, information, processes and functionality. People, Ideas & Objects application modules rely on the Security & Access Control module to implement Industrial Command & Control. This structure, particularly in a Joint Operating Committee, would weave multiple producer firms under one industry standard chain of command. The interface ensures that all processes are monitored for compliance, governance, and overall completeness.

A principle of Synallagi is that North American oil & gas producers will earn the investment community’s support through competitive performance in capital markets—and through exceptional accountability, compliance, and governance.

Based on People, Ideas & Objects’ long-term observation and analysis of producer performance, the industry’s accountability, compliance and governance appear to operate at approximately one-quarter of the standard expected of a genuinely competitive industry. This is an informed analytical assessment rather than the result of a formal quantitative study.

For decades, the sector consumed capital while failing to deliver the fiduciary discipline investors should expect. It took the extraordinary endowment of shale—and destroyed it rather than creating any value.

After eleven years of raising these issues, their investors have seen little to no evidence of meaningful remediation. Investor trust must be earned through performance, accountability, and governance—not presumed. This begins with the Security & Access Control module.

Access, Roles and Responsibilities

This topic discusses the way authorizations, roles and responsibilities are handled in the Security & Access Control module of Synallagi. We should discuss the topic of delegating authority and responsibility during absences, which can come up from time to time.

As background we should recall that each individual would have different access levels and authorizations in terms of access to the People, Ideas & Objects systems. Assuming various roles and responsibilities, they would impose different access levels to data, information, processes and functionality. In addition, Security & Access Control is the key module for implementing Industrial Command & Control across People, Ideas & Objects. This structure, particularly in a Joint Operating Committee, would weave multiple producer firms under one chain of command. To ensure compliance, governance, and overall process completeness, it will need to provide an interface to ensure all processes are monitored.

Throughout Synallagi there is the perception of a heightened role for technology in enabling authorization to conduct operations. Thus, the ability to do things and get things done depends on collaborating with partners and authorizing actions through processes managed by the systems. This participation dictates that the designation of the roles in the Security & Access Control module “means” more than just data access; it imposes authority and responsibility to undertake actions on behalf of Joint Operating Committees and / or producer firms.

It is necessary to assign this authority within the Security & Access Control module during any absence. If someone with authority and responsibility is away for whatever reason, they should be able to assign their authority to another person. This will enable them to fill that role while away. This will ensure that the process isn’t held up during their absence. Delegations of authority have been used for years in large firms and with a system that imposes authorizations and responsibilities on specific roles, the ability to temporarily move them down, across or up the chain of command is a necessity to keep the organization functioning.

Lastly we should talk about the interface that helps to identify missing elements in a process. It would simply show the command structure of the people assigned to a Joint Operating Committee or a process. It would show their related role, authorizations and responsibilities. If someone is away, it would indicate who took over their role. It would help to identify how they could impose a chain of command to fill any vacancies. This would be particularly helpful if the role or process needed to be documented for compliance purposes.

Business Specification Conclusion

It is important to remember that here in the Security & Access Control module of Synallagi. That the role and identity-based Industrial Command & Control (ICC) as conceived here has not been implemented, developed or conceived anywhere else before. We are taking role and identity-based management to the next level with the ICC. This is done through the usage of the Joint Operating Committee, through pooling and taking advantage of specialization and the division of labor in the oil & gas industry.

Why are we bothering with the ICC and the Joint Operating Committee pooling of resources? The issue we are resolving is the finite number of earth science & engineering resources available to the industry. With the anticipated retirement levels in the next 20 years. With the time requirements to bring on increased levels of resources. And most importantly with the demands for more energy, and the demands for more earth science & engineering in each barrel of oil equivalent produced. We face long-term shortages of critical resources. The need to organize the industry, exploit specialization and division of labor, and Professor Paul Romer's theory of non-rival costs is necessary to increase the output from the same number of resources. Doing this without pooling the resources in the Joint Operating Committee will cause the producer firm to broaden the scale of their earth science & engineering capabilities beyond what would be a commercially viable concern. Synallagi notes that we have contributions from earth scientists and engineers from multiple producers working together to meet the objectives of the Joint Operating Committee. Therefore we need a means to organize themselves and that is the Industrial Command & Control of the Security & Access Control module.

How the ICC will be implemented will be determined by our user community. However, I can speculate that the Joint Operating Committee will have standard roles and identities used throughout the industry. Standardization provides many benefits and will be necessary in this instance to make technology work. One of the key benefits of standardization is enhanced innovation. The need to have the various areas "covered" regarding compliance and other requirements will require a standard template used by everyone. Everyone will know that that position is responsible for that role and responsibility. When Joint Operating Committees are small and have only a few people assigned, multiple roles can be assigned to one individual.

There are security and access control issues associated with the service industry and particularly service providers accessing People, Ideas & Objects systems and data. Removing administrative and accounting resources from the producer firms and organizing them in their own service providers provides significant operational flexibility to the innovative and profitable oil & gas producer. The Security & Access Control module ties these disparate organizations into highly organized replacements for the current bureaucracy. Contributing substantially to People, Ideas & Objects' overall tangible portion of our value proposition.

With the natural division in the types of information held within a producer and Joint Operating Committee. Producers will know that Synallagi can deliver the right information to the right people at the right time. Leakage of proprietary information can be mitigated by isolating company data. This is due to its unique nature and Oracle Label Securities' ability to restrict access to database fields.

Oracle’s products provide a strong layer of mission critical capabilities in the Security & Access Control module. Oracle provides comprehensive coverage of security, access control, audit, back up, recovery and roll management to name just a few of the highlights provided. Although this comes with additional costs, I am certain that no one will argue with the quality and peace of mind that these products bring.