V0.1
Authority and non-inference
Complete paths
IP-AUTH-01 — One complete path. A protected operation is authorized only when one complete current authority path covers the exact actor, capability, target, and scope. The path includes required provenance, constraints, status, lifetime, lifecycle, security controls, and applicable restrictions. [ADRs 7D–7G, 8F–8G, 8S-A, 8T-A.]
IP-AUTH-02 — No pooled partial grants. An implementation must not combine separately incomplete grants, sibling scopes, or unrelated constraints to synthesize authority. Independent complete paths remain independently eligible. [ADRs 8F–8G.]
IP-AUTH-03 — Scope does not promote. A Subordinate-scoped grant does not expand to a sibling, Root, or Passport scope. A Passport-wide grant may cover a Subordinate only when current authoritative membership confirms it. [ADRs 7D, 8C, 8G.]
IP-AUTH-04 — Capabilities are distinct. Use, Issue, and Delegate are separate; grants are non-delegable by default, and delegated authority cannot exceed the issuer’s valid delegable path. [ADR 8F.]
IP-AUTH-05 — Safeguards do not create authority. Authentication strength, security class, identifier possession, consumer role, recovery, administration, or reconciliation status cannot replace a complete capability path. [ADRs 7E–7G, 8F, 8G, 8S-A–8V-A.]
This operation’s authority
Resolve One Subordinate uses the reference capability IdentityResolve (identity.resolve), grant mode Use, exact SubordinateIdentity(target) scope, and the Routine floor for this lookup only. Routine requires an authenticated assurance; Unspecified is denied. The consumer cannot select or lower this floor. This rule does not set floors for binding or lifecycle operations. [Canonical resolver contract, Exact read capability and scope; ADRs 8S-A, 8W-A.]
Current state, not a lease
IP-AUTH-06 — No lease. Resolution is evidence of authority at its resolution point only. A binding, assertion receipt, or successful response does not authorize a later operation. Every later protected operation independently checks its own current request and state. [ADRs 8G–8H, 8L-A–8M-A.]
IP-AUTH-07 — Revalidate mutations. Sensitive mutations use transaction-bound final checks of commit-relevant authority, lifecycle, membership, proof, continuity, and versions. [ADRs 8H, 8L-A, 8M-A.]
IP-AUTH-08 — Authority and lifecycle are separate. An authorization decision does not itself change lifecycle state; lifecycle validity does not itself establish authority. [ADR 8L-A; workflow matrix, Composition rule.]