Signature requirements by operation
Operation	Required components
Read an authorized resource	Authentication
Create an ordinary resource	Authentication
Publish authored material	Authentication + Authorship
Issue a signed credential	Authentication + Authorship
Send an encrypted message	Authentication; encryption occurs using recipient Box public key
Mint a child Key	Authentication + Delegation
Assign child permissions	Authentication + Delegation
Expand child permissions	Authentication + Delegation, possibly Owner approval
Rotate the authentication component	Delegation or Owner
Rotate the authorship component	Authentication + Delegation, or Owner
Rotate the delegation component	Owner approval recommended
Revoke a child	Authentication + Delegation
Revoke a subtree	Authentication + Delegation plus elevated policy or Owner
Owner action	Owner session plus step-up when required