{"file":"docs/seed/Description.txt","start":1,"end":34,"lines":[{"number":1,"text":"Build one stateful authorization monolith with two sharply separated surfaces:"},{"number":2,"text":""},{"number":3,"text":""},{"number":4,"text":""},{"number":5,"text":""},{"number":6,"text":"Owner Control Plane"},{"number":7,"text":"A human-facing web application used only by Owner accounts."},{"number":8,"text":""},{"number":9,"text":"A human-authenticated browser interface used for:"},{"number":10,"text":""},{"number":11,"text":"Account administration."},{"number":12,"text":"Creating Primary Authors."},{"number":13,"text":"Setting initial permission ceilings."},{"number":14,"text":"Viewing lineage."},{"number":15,"text":"Viewing provenance."},{"number":16,"text":"Reviewing activity."},{"number":17,"text":"Receiving alerts."},{"number":18,"text":"Suspending and revoking Keys."},{"number":19,"text":"Rotating components."},{"number":20,"text":"Freezing branches or the tenancy."},{"number":21,"text":""},{"number":22,"text":""},{"number":23,"text":""},{"number":24,"text":"Key Execution Plane"},{"number":25,"text":"A signed-request API used only by Primary Author, Secondary Author, Use, and Keyring credentials."},{"number":26,"text":""},{"number":27,"text":"An API-only surface authenticated by cryptographic signatures."},{"number":28,"text":""},{"number":29,"text":"It must never accept:"},{"number":30,"text":""},{"number":31,"text":"Owner cookies."},{"number":32,"text":"Owner passwords."},{"number":33,"text":"Owner email authentication."},{"number":34,"text":"Bearer use of the Credential ID."}]}