C8Human Guide

Source-qualified discovery inventory

Authorization policies delegation

Grant structure, policy layers, inheritance constraints, evaluation rules, and versioning.

Open raw data editor06-authorization-policies-delegation.json

Document context

How to read this page

Every value below mirrors the JSON document. Friendly labels and explanations add context without replacing the exact field name or recorded value. Follow any “raw record” link to inspect or edit the same data.

Schema versionschema_version

Version of the discovery-inventory document shape.

0.1.0
Catalogue statuscatalogue_status

Maturity of this catalogue data, not implementation status.

discovery_inventory
Authorityauthority

How this document may be used and what it must not be mistaken for.

Evidence-derived inventory; not a final implementation-governing SSOT. Preserve source modality and consult conflicts.json.
Categorycategory

Stable subject area used to organize the inventory.

authorization_policies_delegation
Descriptiondescription

Human-language explanation preserved by the inventory.

Grant structure, policy layers, inheritance constraints, evaluation rules, and versioning.

Structured collection

Items

4 top-level entries. Nested values are expanded inside each entry.

Open this raw section →

Authorization component

Structured permission grant

Open editable raw record →

Permission is not merely a boolean; each grant carries effect, scope, delegation, temporal, audience, limits, approvals, signatures, and conditions.

What this represents

This entry is recorded as Authorization component in the Items section.

Statement status: Firm statement

The source states this firmly, rather than as a suggestion.

IdidStable catalogue identity. Ordinary edits should preserve it.
auth.grant
NamenameRecorded inventory field; its exact name and structure are preserved.
Structured permission grant
KindkindStructural role of this entry within the catalogue.
authorization_component
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Permission is not merely a boolean; each grant carries effect, scope, delegation, temporal, audience, limits, approvals, signatures, and conditions.
ModalitymodalityStrength or status of the source statement.
firm_statement
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Cascading_Permissions_Model.txtlines 1-21 · open exact evidence
FieldsfieldsRecorded inventory field; its exact name and structure are preserved.
  1. action
  2. effect
  3. resource_scope
  4. use_allowed
  5. delegate_allowed
  6. delegate_to_key_types
  7. maximum_delegation_depth
  8. not_before
  9. expires_at
  10. audiences
  11. rate_limit
  12. total_use_limit
  13. approval_requirement
  14. required_signatures
  15. conditions

Policy model

Seven-layer Primary Author policy

Open editable raw record →

Owner-set policy combines self authority/scope, minting, child and propagation ceilings, operational constraints, and security responses.

What this represents

This entry is recorded as Policy model in the Items section.

Statement status: Source description

This records how the historical source describes the system.

IdidStable catalogue identity. Ordinary edits should preserve it.
auth.primary_policy
NamenameRecorded inventory field; its exact name and structure are preserved.
Seven-layer Primary Author policy
KindkindStructural role of this entry within the catalogue.
policy_model
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Owner-set policy combines self authority/scope, minting, child and propagation ceilings, operational constraints, and security responses.
ModalitymodalityStrength or status of the source statement.
source_description
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Cascading_Permissions_Model.txtlines 22-69 · open exact evidence
LayerslayersRecorded inventory field; its exact name and structure are preserved.
  1. Self permissions
  2. Self resource scope
  3. Child-type minting
  4. Child permission ceilings
  5. Child propagation ceilings
  6. Operational constraints
  7. Security responses

Authorization rules

Authorization invariants

Open editable raw record →

Source explicitly labels these hard-coded invariants rather than configurable preferences.

What this represents

This entry is recorded as Authorization rules in the Items section.

Statement status: Explicit immutable

The source explicitly presents this as immutable or non-configurable.

IdidStable catalogue identity. Ordinary edits should preserve it.
auth.invariants
NamenameRecorded inventory field; its exact name and structure are preserved.
Authorization invariants
KindkindStructural role of this entry within the catalogue.
authorization_rules
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Source explicitly labels these hard-coded invariants rather than configurable preferences.
ModalitymodalityStrength or status of the source statement.
explicit_immutable
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Authorization_Invariants.txtlines 1-24 · open exact evidence
RulesrulesRecorded inventory field; its exact name and structure are preserved.
  1. Deny by default
  2. Explicit deny overrides allow
  3. Child self permissions subset of parent child ceiling
  4. Child delegation permissions subset of parent propagation ceiling
  5. Child resource scope no broader than parent
  6. Child expiry bounded by parent expiry/child TTL ceiling
  7. Child cannot increase delegation depth
  8. Child cannot remove inherited approval
  9. Child cannot weaken signature strength
  10. Revoked ancestor invalidates descendants
  11. Suspended ancestor temporarily suspends descendants
  12. Rotation preserves historical verification
  13. Revocation blocks new actions without rewriting provenance
  14. API Keys cannot modify Owner password/email/sessions/billing/recovery
  15. Provisioning source never affects authorization
  16. Credential ID/public key possession grants no permission
  17. Keyring membership grants no contained-Key authority
  18. Key cannot grant what it cannot delegate
  19. Expansion creates new policy version and event
  20. Events/signatures cannot be edited in place

Persistence rule

Immutable policy versions

Open editable raw record →

Policy changes create new immutable versions with hashes and events.

What this represents

This entry is recorded as Persistence rule in the Items section.

Statement status: Explicit immutable

The source explicitly presents this as immutable or non-configurable.

IdidStable catalogue identity. Ordinary edits should preserve it.
auth.policy_versions
NamenameRecorded inventory field; its exact name and structure are preserved.
Immutable policy versions
KindkindStructural role of this entry within the catalogue.
persistence_rule
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Policy changes create new immutable versions with hashes and events.
ModalitymodalityStrength or status of the source statement.
explicit_immutable