V0.1

Resolve One Subordinate

Request meaning

IP-RES-01 — One target. A resolve request concerns exactly one Subordinate Identity selected from a trusted consumer-side binding. It uses identity.resolve, Use, exact target scope, and Routine class for this operation only. [ADR 8C, 8G; canonical resolver contract, Exact read capability and scope.]

IP-RES-02 — Trusted context. The consumer instance, Principal, separately mapped Account, target, and opaque consumer reference come from trusted server-side context. An untrusted browser-supplied Passport ID or caller-selected assurance is not authority. Missing, mismatched, inactive, or unspecified association denies. [ADRs 8B, 8G, 8S-A; resolver contract, Contract.]

Result and resolution point

IP-RES-03 — Opaque result. Success returns only the exact ConsumerIdentityRef; it does not serialize Passport IDs, Root IDs, Subordinate IDs, grant data, version vectors, or reusable authorization claims. [ADRs 7P, 8D, 8G; resolver contract, Contract.]

IP-RES-04 — Current coherent view. Authorization evaluates a coherent view of target membership, grants/provenance, restrictions, lifecycle/continuity, association, security generation, and authoritative time. [ADRs 8G–8H, 8J-A, 8L-A–8M-A, 8S-A–8U-A.]

IP-RES-05 — Linearized result. A concurrent relevant mutation is either reflected in the decision or ordered after the resolution point. The point is the authoritative-time sample only when Passport validation commits successfully and the consumer’s local mapping/session snapshots bracketing it agree. [ADR 8H; resolver contract, Cross-database resolution protocol and linearization point.]

IP-RES-06 — Uncertain commit fails closed. Failed, aborted, or uncertain validation commit establishes no successful resolution point and returns no success. Stale state restarts the complete attempt within a bounded internally configured retry limit. Exhaustion returns generic IdentityUnavailable. [ADRs 8H, 8K-A, 8L-A.]

IP-RES-07 — Local bracketing. The consumer re-reads its Account/Principal mapping, target binding, consumer context, and session/security generation after Passport validation. A changed version or inactive mapping discards the result and restarts within bounded retry. The two databases are not one transaction. [ADRs 8H, 9F-A; resolver contract, Cross-database resolution protocol.]

IP-RES-08 — No stale cache. A cached result may be used only with equivalent proof of current local mapping and Passport state and a fresh authorization evaluation; the initial reference slice does not cache resolve outcomes. [ADR 8G; resolver contract, cache rule.]

Observable failures

IP-RES-09 — Failure privacy. For authenticated consumers, unknown/unbound/revoked references, denied authority, stale state, database/adapter failure, overload after admission, and retry exhaustion share one transport-safe generic failure shape. Do not expose target-specific detail. Unauthenticated requests may receive the ordinary authentication-required response before lookup. Immediate admission rejection occurs before target lookup and uses a generic response; a scheduler cannot promise exact packet arrival time. [Resolver contract, Denial and failure privacy / Bounded asynchronous scheduling.] [ADR 8G; resolver contract, Denial and failure privacy and Bounded asynchronous scheduling.]

The exact public status code, response schema, timing profile, transport, and operation versioning remain open questions. See OPEN-01, OPEN-05, and OPEN-07.