# InfoTechCanon Security Model concept boundary review — 2026-09-20 Authority: INFO-WP-0027-T02, the declaration round that gave this artifact an `owned_concepts` list. Resolutions cite the kernel map concept-owner table where it assigns an owner, and are decided in this review where it does not. No concept is renamed, moved or removed. | Concept | Owner | Resolution | Decided by | | --- | --- | --- | --- | | `Alert` | model/observability | Assigned by the kernel map concept-owner table. | kernel map | | `Exposure` | model/security | Security owns Exposure; it is one of the model purpose entities alongside threat, weakness and vulnerability. Network describes reachability that produces exposure and imports. | this review | | `Investigation` | model/security | Security owns Investigation as part of response. The Observability sense is analysis activity over telemetry and imports. | this review | Concepts this artifact declares are listed in its frontmatter. An overlap recorded here means another artifact defines the same name; where the owner is another artifact, this one imports the definition rather than restating it.