[
  {
    "anchor": "overview",
    "approvers": [
      "Stephen"
    ],
    "authorization_scope": "PUBLIC_INFORMATION",
    "availability_state": "NOT_AVAILABLE",
    "canonical_authority": "SRC-ARCHITECTURE-ATLAS-V2-2",
    "canonical_url": "/en/architecture/identity-and-authority",
    "capability_state": "IN_DEVELOPMENT",
    "chunk_id": "MYRILUM-DOC-ARCH-015@0.1.0:en:GLOBAL:overview",
    "citation_id": "MYRILUM-DOC-ARCH-015@0.1.0:en#overview",
    "command_authority": "NONE",
    "content_applicability": "SHARED_NEUTRAL",
    "content_digest": "cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a",
    "content_maturity": "DRAFTED",
    "doc_id": "MYRILUM-DOC-ARCH-015",
    "effective_at": null,
    "expires_at": null,
    "freshness_status": "CURRENT",
    "governance_status": "APPROVED",
    "last_verified_at": "2026-09-23",
    "limitations": "Read-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.",
    "locale": "en",
    "operational_effect": "NONE",
    "owner": "Web3Capital Documentation Steward",
    "product_id": null,
    "publication_status": "PUBLISHED_GLOBAL",
    "region": "GLOBAL",
    "requires_human_gate": true,
    "review_due_at": "2026-10-23",
    "safety_class": "INFORMATIONAL",
    "section_title": "What this page covers",
    "source_commit": "6b41cce4496de03c67a501aa94cd41ec6ac0e85a",
    "source_refs": [
      "SRC-ARCHITECTURE-ATLAS-V2-2"
    ],
    "text": "Document: Identity, authorization and access decisions (MYRILUM-DOC-ARCH-015, version 0.1.0).\nCanonical URL: /en/architecture/identity-and-authority#overview. Product: NOT_APPLICABLE.\nRegion: GLOBAL; locale: en; visibility: PUBLIC; publication: PUBLISHED_GLOBAL.\nContent: DRAFTED; governance: APPROVED; freshness: CURRENT.\nReality: IN_DEVELOPMENT; availability: NOT_AVAILABLE; authorization: PUBLIC_INFORMATION.\nAuthority: SRC-ARCHITECTURE-ATLAS-V2-2; source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a; content digest: cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a.\nEffective: NOT_SET; expires: NOT_SET; verified: 2026-09-23; review due: 2026-10-23.\nSafety: INFORMATIONAL; human gate: true; operational_effect=NONE; command_authority=NONE.\nDocument governance assignment: owner=Web3Capital Documentation Steward; assigned approvers (not approval evidence)=Stephen.\nRead-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.\nWhat this page covers: This is MYRILUM's target architecture. It does not mean everything on the map is live; whether a capability can be used today is stated in “Current availability”.\nCentral identity, resource-level permissions, task delegation and approval of high-impact actions are four different layers of control. This page states principles only; implementation details are not published.",
    "title": "Identity, authorization and access decisions",
    "version": "0.1.0",
    "visibility": "PUBLIC"
  },
  {
    "anchor": "three-credentials",
    "approvers": [
      "Stephen"
    ],
    "authorization_scope": "PUBLIC_INFORMATION",
    "availability_state": "NOT_AVAILABLE",
    "canonical_authority": "SRC-ARCHITECTURE-ATLAS-V2-2",
    "canonical_url": "/en/architecture/identity-and-authority",
    "capability_state": "IN_DEVELOPMENT",
    "chunk_id": "MYRILUM-DOC-ARCH-015@0.1.0:en:GLOBAL:three-credentials",
    "citation_id": "MYRILUM-DOC-ARCH-015@0.1.0:en#three-credentials",
    "command_authority": "NONE",
    "content_applicability": "SHARED_NEUTRAL",
    "content_digest": "cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a",
    "content_maturity": "DRAFTED",
    "doc_id": "MYRILUM-DOC-ARCH-015",
    "effective_at": null,
    "expires_at": null,
    "freshness_status": "CURRENT",
    "governance_status": "APPROVED",
    "last_verified_at": "2026-09-23",
    "limitations": "Read-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.",
    "locale": "en",
    "operational_effect": "NONE",
    "owner": "Web3Capital Documentation Steward",
    "product_id": null,
    "publication_status": "PUBLISHED_GLOBAL",
    "region": "GLOBAL",
    "requires_human_gate": true,
    "review_due_at": "2026-10-23",
    "safety_class": "INFORMATIONAL",
    "section_title": "Three credentials that never substitute for each other",
    "source_commit": "6b41cce4496de03c67a501aa94cd41ec6ac0e85a",
    "source_refs": [
      "SRC-ARCHITECTURE-ATLAS-V2-2"
    ],
    "text": "Document: Identity, authorization and access decisions (MYRILUM-DOC-ARCH-015, version 0.1.0).\nCanonical URL: /en/architecture/identity-and-authority#three-credentials. Product: NOT_APPLICABLE.\nRegion: GLOBAL; locale: en; visibility: PUBLIC; publication: PUBLISHED_GLOBAL.\nContent: DRAFTED; governance: APPROVED; freshness: CURRENT.\nReality: IN_DEVELOPMENT; availability: NOT_AVAILABLE; authorization: PUBLIC_INFORMATION.\nAuthority: SRC-ARCHITECTURE-ATLAS-V2-2; source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a; content digest: cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a.\nEffective: NOT_SET; expires: NOT_SET; verified: 2026-09-23; review due: 2026-10-23.\nSafety: INFORMATIONAL; human gate: true; operational_effect=NONE; command_authority=NONE.\nDocument governance assignment: owner=Web3Capital Documentation Steward; assigned approvers (not approval evidence)=Stephen.\nRead-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.\nThree credentials that never substitute for each other: Sign-in identity proves who you are; task capability states what a task may do; approval for an important action covers this one time and this one object. Each is issued and checked on its own, and none can stand in for another.",
    "title": "Identity, authorization and access decisions",
    "version": "0.1.0",
    "visibility": "PUBLIC"
  },
  {
    "anchor": "all-conditions",
    "approvers": [
      "Stephen"
    ],
    "authorization_scope": "PUBLIC_INFORMATION",
    "availability_state": "NOT_AVAILABLE",
    "canonical_authority": "SRC-ARCHITECTURE-ATLAS-V2-2",
    "canonical_url": "/en/architecture/identity-and-authority",
    "capability_state": "IN_DEVELOPMENT",
    "chunk_id": "MYRILUM-DOC-ARCH-015@0.1.0:en:GLOBAL:all-conditions",
    "citation_id": "MYRILUM-DOC-ARCH-015@0.1.0:en#all-conditions",
    "command_authority": "NONE",
    "content_applicability": "SHARED_NEUTRAL",
    "content_digest": "cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a",
    "content_maturity": "DRAFTED",
    "doc_id": "MYRILUM-DOC-ARCH-015",
    "effective_at": null,
    "expires_at": null,
    "freshness_status": "CURRENT",
    "governance_status": "APPROVED",
    "last_verified_at": "2026-09-23",
    "limitations": "Read-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.",
    "locale": "en",
    "operational_effect": "NONE",
    "owner": "Web3Capital Documentation Steward",
    "product_id": null,
    "publication_status": "PUBLISHED_GLOBAL",
    "region": "GLOBAL",
    "requires_human_gate": true,
    "review_due_at": "2026-10-23",
    "safety_class": "INFORMATIONAL",
    "section_title": "Every condition must hold at once",
    "source_commit": "6b41cce4496de03c67a501aa94cd41ec6ac0e85a",
    "source_refs": [
      "SRC-ARCHITECTURE-ATLAS-V2-2"
    ],
    "text": "Document: Identity, authorization and access decisions (MYRILUM-DOC-ARCH-015, version 0.1.0).\nCanonical URL: /en/architecture/identity-and-authority#all-conditions. Product: NOT_APPLICABLE.\nRegion: GLOBAL; locale: en; visibility: PUBLIC; publication: PUBLISHED_GLOBAL.\nContent: DRAFTED; governance: APPROVED; freshness: CURRENT.\nReality: IN_DEVELOPMENT; availability: NOT_AVAILABLE; authorization: PUBLIC_INFORMATION.\nAuthority: SRC-ARCHITECTURE-ATLAS-V2-2; source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a; content digest: cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a.\nEffective: NOT_SET; expires: NOT_SET; verified: 2026-09-23; review due: 2026-10-23.\nSafety: INFORMATIONAL; human gate: true; operational_effect=NONE; command_authority=NONE.\nDocument governance assignment: owner=Web3Capital Documentation Steward; assigned approvers (not approval evidence)=Stephen.\nRead-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.\nEvery condition must hold at once: Allowed to run = valid identity ∧ lawful action ∧ matching authorization ∧ data allowed ∧ budget available ∧ risk cleared. Anything not explicitly allowed is treated as not allowed. Being able to use a product feature is not the same as permission over its data or its actions.",
    "title": "Identity, authorization and access decisions",
    "version": "0.1.0",
    "visibility": "PUBLIC"
  },
  {
    "anchor": "bound-approval",
    "approvers": [
      "Stephen"
    ],
    "authorization_scope": "PUBLIC_INFORMATION",
    "availability_state": "NOT_AVAILABLE",
    "canonical_authority": "SRC-ARCHITECTURE-ATLAS-V2-2",
    "canonical_url": "/en/architecture/identity-and-authority",
    "capability_state": "IN_DEVELOPMENT",
    "chunk_id": "MYRILUM-DOC-ARCH-015@0.1.0:en:GLOBAL:bound-approval",
    "citation_id": "MYRILUM-DOC-ARCH-015@0.1.0:en#bound-approval",
    "command_authority": "NONE",
    "content_applicability": "SHARED_NEUTRAL",
    "content_digest": "cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a",
    "content_maturity": "DRAFTED",
    "doc_id": "MYRILUM-DOC-ARCH-015",
    "effective_at": null,
    "expires_at": null,
    "freshness_status": "CURRENT",
    "governance_status": "APPROVED",
    "last_verified_at": "2026-09-23",
    "limitations": "Read-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.",
    "locale": "en",
    "operational_effect": "NONE",
    "owner": "Web3Capital Documentation Steward",
    "product_id": null,
    "publication_status": "PUBLISHED_GLOBAL",
    "region": "GLOBAL",
    "requires_human_gate": true,
    "review_due_at": "2026-10-23",
    "safety_class": "INFORMATIONAL",
    "section_title": "Approval is bound to one specific action",
    "source_commit": "6b41cce4496de03c67a501aa94cd41ec6ac0e85a",
    "source_refs": [
      "SRC-ARCHITECTURE-ATLAS-V2-2"
    ],
    "text": "Document: Identity, authorization and access decisions (MYRILUM-DOC-ARCH-015, version 0.1.0).\nCanonical URL: /en/architecture/identity-and-authority#bound-approval. Product: NOT_APPLICABLE.\nRegion: GLOBAL; locale: en; visibility: PUBLIC; publication: PUBLISHED_GLOBAL.\nContent: DRAFTED; governance: APPROVED; freshness: CURRENT.\nReality: IN_DEVELOPMENT; availability: NOT_AVAILABLE; authorization: PUBLIC_INFORMATION.\nAuthority: SRC-ARCHITECTURE-ATLAS-V2-2; source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a; content digest: cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a.\nEffective: NOT_SET; expires: NOT_SET; verified: 2026-09-23; review due: 2026-10-23.\nSafety: INFORMATIONAL; human gate: true; operational_effect=NONE; command_authority=NONE.\nDocument governance assignment: owner=Web3Capital Documentation Steward; assigned approvers (not approval evidence)=Stephen.\nRead-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.\nApproval is bound to one specific action: An important action is approved by an authorized person on the basis of evidence, and the approval holds only for that plan version, recipient, environment, key data flows and budget; if any of them changes, the approval no longer applies. A model can never issue an approval on a person's behalf.",
    "title": "Identity, authorization and access decisions",
    "version": "0.1.0",
    "visibility": "PUBLIC"
  },
  {
    "anchor": "recheck-and-revoke",
    "approvers": [
      "Stephen"
    ],
    "authorization_scope": "PUBLIC_INFORMATION",
    "availability_state": "NOT_AVAILABLE",
    "canonical_authority": "SRC-ARCHITECTURE-ATLAS-V2-2",
    "canonical_url": "/en/architecture/identity-and-authority",
    "capability_state": "IN_DEVELOPMENT",
    "chunk_id": "MYRILUM-DOC-ARCH-015@0.1.0:en:GLOBAL:recheck-and-revoke",
    "citation_id": "MYRILUM-DOC-ARCH-015@0.1.0:en#recheck-and-revoke",
    "command_authority": "NONE",
    "content_applicability": "SHARED_NEUTRAL",
    "content_digest": "cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a",
    "content_maturity": "DRAFTED",
    "doc_id": "MYRILUM-DOC-ARCH-015",
    "effective_at": null,
    "expires_at": null,
    "freshness_status": "CURRENT",
    "governance_status": "APPROVED",
    "last_verified_at": "2026-09-23",
    "limitations": "Read-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.",
    "locale": "en",
    "operational_effect": "NONE",
    "owner": "Web3Capital Documentation Steward",
    "product_id": null,
    "publication_status": "PUBLISHED_GLOBAL",
    "region": "GLOBAL",
    "requires_human_gate": true,
    "review_due_at": "2026-10-23",
    "safety_class": "INFORMATIONAL",
    "section_title": "Checked every time, revocable at any time",
    "source_commit": "6b41cce4496de03c67a501aa94cd41ec6ac0e85a",
    "source_refs": [
      "SRC-ARCHITECTURE-ATLAS-V2-2"
    ],
    "text": "Document: Identity, authorization and access decisions (MYRILUM-DOC-ARCH-015, version 0.1.0).\nCanonical URL: /en/architecture/identity-and-authority#recheck-and-revoke. Product: NOT_APPLICABLE.\nRegion: GLOBAL; locale: en; visibility: PUBLIC; publication: PUBLISHED_GLOBAL.\nContent: DRAFTED; governance: APPROVED; freshness: CURRENT.\nReality: IN_DEVELOPMENT; availability: NOT_AVAILABLE; authorization: PUBLIC_INFORMATION.\nAuthority: SRC-ARCHITECTURE-ATLAS-V2-2; source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a; content digest: cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a.\nEffective: NOT_SET; expires: NOT_SET; verified: 2026-09-23; review due: 2026-10-23.\nSafety: INFORMATIONAL; human gate: true; operational_effect=NONE; command_authority=NONE.\nDocument governance assignment: owner=Web3Capital Documentation Steward; assigned approvers (not approval evidence)=Stephen.\nRead-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.\nChecked every time, revocable at any time: Permission is not checked only once when a task is created; it is checked again before every important action. After revocation or freezing, new actions stop at once; actions already accepted externally are queried or compensated. Every time leaves a record of who acted, on what basis, on which object and when.",
    "title": "Identity, authorization and access decisions",
    "version": "0.1.0",
    "visibility": "PUBLIC"
  },
  {
    "anchor": "regions",
    "approvers": [
      "Stephen"
    ],
    "authorization_scope": "PUBLIC_INFORMATION",
    "availability_state": "NOT_AVAILABLE",
    "canonical_authority": "SRC-ARCHITECTURE-ATLAS-V2-2",
    "canonical_url": "/en/architecture/identity-and-authority",
    "capability_state": "IN_DEVELOPMENT",
    "chunk_id": "MYRILUM-DOC-ARCH-015@0.1.0:en:GLOBAL:regions",
    "citation_id": "MYRILUM-DOC-ARCH-015@0.1.0:en#regions",
    "command_authority": "NONE",
    "content_applicability": "SHARED_NEUTRAL",
    "content_digest": "cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a",
    "content_maturity": "DRAFTED",
    "doc_id": "MYRILUM-DOC-ARCH-015",
    "effective_at": null,
    "expires_at": null,
    "freshness_status": "CURRENT",
    "governance_status": "APPROVED",
    "last_verified_at": "2026-09-23",
    "limitations": "Read-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.",
    "locale": "en",
    "operational_effect": "NONE",
    "owner": "Web3Capital Documentation Steward",
    "product_id": null,
    "publication_status": "PUBLISHED_GLOBAL",
    "region": "GLOBAL",
    "requires_human_gate": true,
    "review_due_at": "2026-10-23",
    "safety_class": "INFORMATIONAL",
    "section_title": "The two regions' identity is kept apart",
    "source_commit": "6b41cce4496de03c67a501aa94cd41ec6ac0e85a",
    "source_refs": [
      "SRC-ARCHITECTURE-ATLAS-V2-2"
    ],
    "text": "Document: Identity, authorization and access decisions (MYRILUM-DOC-ARCH-015, version 0.1.0).\nCanonical URL: /en/architecture/identity-and-authority#regions. Product: NOT_APPLICABLE.\nRegion: GLOBAL; locale: en; visibility: PUBLIC; publication: PUBLISHED_GLOBAL.\nContent: DRAFTED; governance: APPROVED; freshness: CURRENT.\nReality: IN_DEVELOPMENT; availability: NOT_AVAILABLE; authorization: PUBLIC_INFORMATION.\nAuthority: SRC-ARCHITECTURE-ATLAS-V2-2; source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a; content digest: cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a.\nEffective: NOT_SET; expires: NOT_SET; verified: 2026-09-23; review due: 2026-10-23.\nSafety: INFORMATIONAL; human gate: true; operational_effect=NONE; command_authority=NONE.\nDocument governance assignment: owner=Web3Capital Documentation Steward; assigned approvers (not approval evidence)=Stephen.\nRead-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.\nThe two regions' identity is kept apart: Identity authentication for the China region and the global region runs in separate environments. Data, permissions and forbidden actions are hard boundaries and are never relaxed because a model is cheaper or delivery would be faster.",
    "title": "Identity, authorization and access decisions",
    "version": "0.1.0",
    "visibility": "PUBLIC"
  },
  {
    "anchor": "source",
    "approvers": [
      "Stephen"
    ],
    "authorization_scope": "PUBLIC_INFORMATION",
    "availability_state": "NOT_AVAILABLE",
    "canonical_authority": "SRC-ARCHITECTURE-ATLAS-V2-2",
    "canonical_url": "/en/architecture/identity-and-authority",
    "capability_state": "IN_DEVELOPMENT",
    "chunk_id": "MYRILUM-DOC-ARCH-015@0.1.0:en:GLOBAL:source",
    "citation_id": "MYRILUM-DOC-ARCH-015@0.1.0:en#source",
    "command_authority": "NONE",
    "content_applicability": "SHARED_NEUTRAL",
    "content_digest": "cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a",
    "content_maturity": "DRAFTED",
    "doc_id": "MYRILUM-DOC-ARCH-015",
    "effective_at": null,
    "expires_at": null,
    "freshness_status": "CURRENT",
    "governance_status": "APPROVED",
    "last_verified_at": "2026-09-23",
    "limitations": "Read-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.",
    "locale": "en",
    "operational_effect": "NONE",
    "owner": "Web3Capital Documentation Steward",
    "product_id": null,
    "publication_status": "PUBLISHED_GLOBAL",
    "region": "GLOBAL",
    "requires_human_gate": true,
    "review_due_at": "2026-10-23",
    "safety_class": "INFORMATIONAL",
    "section_title": "Source",
    "source_commit": "6b41cce4496de03c67a501aa94cd41ec6ac0e85a",
    "source_refs": [
      "SRC-ARCHITECTURE-ATLAS-V2-2"
    ],
    "text": "Document: Identity, authorization and access decisions (MYRILUM-DOC-ARCH-015, version 0.1.0).\nCanonical URL: /en/architecture/identity-and-authority#source. Product: NOT_APPLICABLE.\nRegion: GLOBAL; locale: en; visibility: PUBLIC; publication: PUBLISHED_GLOBAL.\nContent: DRAFTED; governance: APPROVED; freshness: CURRENT.\nReality: IN_DEVELOPMENT; availability: NOT_AVAILABLE; authorization: PUBLIC_INFORMATION.\nAuthority: SRC-ARCHITECTURE-ATLAS-V2-2; source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a; content digest: cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a.\nEffective: NOT_SET; expires: NOT_SET; verified: 2026-09-23; review due: 2026-10-23.\nSafety: INFORMATIONAL; human gate: true; operational_effect=NONE; command_authority=NONE.\nDocument governance assignment: owner=Web3Capital Documentation Steward; assigned approvers (not approval evidence)=Stephen.\nRead-only documentation projection. It grants no command authority and cannot authorize or perform any real-world action.\nSource: This page follows A15 of the MYRILUM architecture map v2.2. Under the public boundary it publishes principles only and carries no diagram. Related: “Business domains and fact authority”; “Agent runtime and failure recovery”; “Deployment and trust boundaries”.",
    "title": "Identity, authorization and access decisions",
    "version": "0.1.0",
    "visibility": "PUBLIC"
  }
]
