Signature requirements by operation Operation Required components Read an authorized resource Authentication Create an ordinary resource Authentication Publish authored material Authentication + Authorship Issue a signed credential Authentication + Authorship Send an encrypted message Authentication; encryption occurs using recipient Box public key Mint a child Key Authentication + Delegation Assign child permissions Authentication + Delegation Expand child permissions Authentication + Delegation, possibly Owner approval Rotate the authentication component Delegation or Owner Rotate the authorship component Authentication + Delegation, or Owner Rotate the delegation component Owner approval recommended Revoke a child Authentication + Delegation Revoke a subtree Authentication + Delegation plus elevated policy or Owner Owner action Owner session plus step-up when required