platform · AVC

Authority is a runtime property.

Permission, risk, approval and ownership are visible before consequential work executes.

Authority reference

Permission, limits and prohibition remain separate.

These reference states communicate the governing boundary before any consequential control is presented.

ObserveRead-only evidence collection
PrepareDraft without external effect
ForbiddenCannot be self-granted
Authorization path

Permission is earned gate by gate.

A confident model response cannot skip any of these controls.

  1. Identity and capability

    The subject holds a purpose-, scope- and environment-bound grant.

    passed
  2. Risk classification

    The requested action fits the grant risk ceiling.

    passed
  3. Budget and policy

    Spend and constitutional policy both permit the action.

    active
  4. Independent approval

    Consequential work waits for the required owner or approver evidence.

    pending
  5. Outcome verification

    Execution is not complete until evidence satisfies the success criterion.

    pending
Root control

The Constitution is above ordinary execution.

Ownership, root credentials, protected constraints and privileged production authority remain non-delegable.

Separation of duties

Request, execution and approval remain distinct roles.

Higher-risk actions require independent approval. An agent cannot request, approve and verify its own consequential action as one convenient bundle.

Fail closed

Missing capability or evidence means denial, not improvisation.

Authorization is deterministic and deny-by-default across capability, risk, budget and policy checks.