Your service is a system of systems.
Availability can depend on providers, identities, networks, software updates and legal permissions you do not directly control.
Operational Sovereignty Assessment Framework
OSAF helps organizations assess whether critical services remain controllable, recoverable and adaptable when an external dependency changes, fails or stops cooperating.
The problem
Organizations use cloud, SaaS, identity and AI services every day. The harder question is what remains possible when one of those dependencies changes.
Availability can depend on providers, identities, networks, software updates and legal permissions you do not directly control.
Rights matter, but operational control requires a path that people can actually exercise under pressure.
OSAF distinguishes what is claimed, documented, implemented, monitored, tested and independently assured.
Intuition test
A service can be locally hosted and still depend on remote identity, foreign-controlled keys, proprietary software or an inaccessible control plane.
What OSAF does
The method connects the business consequence to the capabilities, dependencies and evidence that determine what the organization should do next.
Set a boundary narrow enough to assess.
Define why control matters.
Ask what must remain possible.
Trace controls across domains.
Separate claims from demonstration.
Close the consequential gap.
Framework relationship
Select a layer to see how OSAF changes the lens while keeping the same critical service at the centre.
An outcome connects to every capability materially required to achieve it. OSAF does not assume fixed one-to-one mappings.
OSAF posture ladder
The levels are cumulative. The first unsatisfied critical requirement caps the achieved posture.
Recovery and continuity mechanisms are implemented and tested, although important activities may still depend on the provider.
Evidence strength
Choose a stage to see how assurance strengthens as a control moves from assertion to exercised evidence.
The control has been exercised against a defined scenario and acceptance criteria.
Stories
Verified events show how technical, legal, identity and supplier dependencies can alter what an organization is able to do.
A faulty CrowdStrike update became a common-mode operational dependency across organizations and sectors.
A legal action outside the operator's direct control restricted ZTE's access to critical technology supply.
A government directive changed who could use selected advanced Anthropic models.
Start with one service
Start with one bounded service. Examine what must remain possible. Require evidence. Identify the gap.