Post 1 diagnosed ontology scar tissue as an accountability problem. Post 2 tested three modern remedies against that diagnosis and found a fourth, less-marketed pattern that actually closes it.
This post asks the more precise question underneath both: accountability for what, specifically. A schema can be perfectly owned and still leave an enterprise exposed, if ownership only covers part of what agentic AI actually needs governed.
The four surfaces
SACS is Luminity’s provenance framework, introduced in Series 13, for evaluating whether an architecture governs not only what information exists but how it is acted upon. Luminity refers to the architectural locations where alignment-grade provenance has to live as SACS: Source (where a claim or data point originated), Action (what operation was taken on it, and by what authority), Context (the shared meaning it carries into a decision), and Scope (whether the identity acting is actually bound to the action taken). A system can be strong on one surface and structurally silent on another, and the four scars from Post 1 are what silence looks like from the outside.
Applying SACS to every pattern this series has examined produces one finding that doesn’t show up when you evaluate each pattern on its own: nothing examined here covers all four surfaces except the one built specifically, expensively, and continuously to do so.
| Pattern | Source | Action | Context | Scope |
|---|---|---|---|---|
| Palantir Ontology / FDE | Strong | Strong | Strong | Strong |
| Stanford Protégé | Strong | Absent | Strong | Absent |
| Data mesh, governed | Conditional | Absent | Conditional | Conditional |
| GraphRAG | Partial | Absent | Partial, unowned | Absent |
| Automated lineage tooling | Strong | Absent | Weak | Absent |
| Ontology-as-code (dbt) | Moderate | Strong | Moderate | Strong |
Read across the rows and the pattern from Posts 1 and 2 sharpens into something more specific. Palantir’s specimen earns full coverage the hard way: an FDE sitting in the business is a human closing all four surfaces manually, continuously, at cost. Stanford’s Protégé proves the same structural point from the opposite direction — a rigorous, decades-old academic ontology-authoring tool still leaves Action and Scope empty, because authoring a shared conceptualization was never the same problem as governing what a system does with it. Data mesh’s Context and Source columns are conditional on the same thing Post 2 already flagged: federated governance has to actually get built, not just named.
Why no remedy adds up to a whole one by stacking
Read down the columns instead of across, and a second finding appears. Action is empty for every pattern except two: Palantir’s continuously-staffed FDE model, and dbt’s build-time contract enforcement. Every other remedy in this series — the academic tooling, the decentralized ontology, the LLM-derived graph, the lineage catalog — never touches what happens when an agent actually acts on the data it describes. That is not a coincidence of which tools got popular. It is what happens when “ontology” gets used to mean “a better description of the data” rather than “a governed constraint on what a system is authorized to do with it.” Post 1’s four scars are what the first definition produces at scale; SACS is why the second definition is the one that closes them.
This is also why combining remedies doesn’t reliably fix the gap. An enterprise running data mesh alongside a lineage catalog has real Source coverage and partial Context — and still has no Action or Scope surface at all, because neither tool was built to have one. Stacking two Action-absent patterns produces zero Action coverage, not partial. The gap has to be checked explicitly, surface by surface, or it survives underneath a stack of tools that each look like progress.
The schema was never the problem this series has been describing. A perfectly designed, perfectly owned schema still leaves an enterprise exposed if it only covers Source and Context while Action and Scope stay silent — which is what happens by default with every remedy examined here except the two built to close them on purpose. Ontology scar tissue isn’t cured by a better graph, a more decentralized org chart, or a faster catalog. It’s cured by an explicit check, against all four surfaces, of what a given architecture actually governs versus what it only describes.
This closes the series. The diagnosis in Post 1, the remedy audit in Post 2, and the SACS reading here are the same argument at three different distances: an ontology is an asset only when someone is structurally accountable for what it describes and what it authorizes, on all four surfaces, continuously. Everything else is a more expensive way of writing the description down.
