Problem
Security assessments often focus on steady-state sign-in. Real failures occur during transitions: a device is lost, a role changes, a key is replaced or a team returns after compromise.
Hypotheses
H1: Visible pre- and post-states reduce misinterpretation. H2: Targeted revocation causes less operational interruption than global sign-out. H3: A documented abort path reduces insecure workarounds during incomplete transitions.
Scenarios
Four standardised scenarios are tested separately: a lost secondary device, expiry of a temporary role, planned key rotation and recovery after assumed endpoint loss. Production incidents are not simulated.
Measures
Measures include time to safe state, correct decisions, assistance, residual old access, cross-device consistency and perceived certainty. Technical state and user belief are recorded separately.
Security and ethics boundaries
The protocol uses isolated accounts, synthetic data and pre-defined stop criteria. Participants can withdraw without penalty. Security findings follow responsible disclosure before publication.
Expected artefacts
The protocol produces a state diagram, scenario scripts, anonymised timelines, deviation register and replication guide. It promises no positive outcome; disproven hypotheses remain publishable.
