{
  "agent_tasks": [
    "explain_platform_architecture"
  ],
  "ai_indexable": true,
  "approvers": [
    "Stephen"
  ],
  "audiences": [
    "technical_lead",
    "developer",
    "organization_leader",
    "integration_partner",
    "agent"
  ],
  "authority_domain": "platform_architecture",
  "authorization_scope": "PUBLIC_INFORMATION",
  "availability_state": "NOT_AVAILABLE",
  "canonical_authority": "SRC-ARCHITECTURE-ATLAS-V2-2",
  "canonical_locale": "zh-CN",
  "capability_state": "IN_DEVELOPMENT",
  "chunk_context": {
    "repeat_authorization_state": true,
    "repeat_dates": true,
    "repeat_doc_id": true,
    "repeat_execution_boundary": true,
    "repeat_product": true,
    "repeat_reality_state": true,
    "repeat_region": true,
    "repeat_version": true
  },
  "citation": {
    "canonical_url": "/en/architecture/identity-and-authority",
    "preferred_anchor": "overview"
  },
  "content_applicability": "SHARED_NEUTRAL",
  "content_digest": "cdeb6e74bcf01895e64bb10c823ca6ddd3d09e407788890deb869a99c799f66a",
  "content_maturity": "DRAFTED",
  "doc_id": "MYRILUM-DOC-ARCH-015",
  "document_type": "concept",
  "effective_at": null,
  "evidence_refs": [],
  "expires_at": null,
  "freshness_status": "CURRENT",
  "governance_status": "APPROVED",
  "last_verified_at": "2026-09-23",
  "locale": "en",
  "machine_summary": "Identity, authorization and access decisions (MYRILUM target architecture A15, principles only). Three credentials that never substitute for each other. Every condition must hold at once. Approval is bound to one specific action. Checked every time, revocable at any time. The two regions' identity is kept apart.",
  "nav_order": 145,
  "operational_effect": "NONE",
  "owner": "Web3Capital Documentation Steward",
  "product_id": null,
  "publication_by_region": {
    "CN": "PRIVATE",
    "GLOBAL": "PUBLISHED_GLOBAL"
  },
  "publication_status": "PUBLISHED_GLOBAL",
  "region": "GLOBAL",
  "regions": [
    "GLOBAL",
    "CN"
  ],
  "related_docs": [
    "MYRILUM-DOC-ARCH-000",
    "MYRILUM-DOC-ARCH-003",
    "MYRILUM-DOC-ARCH-016",
    "MYRILUM-DOC-ARCH-026",
    "MYRILUM-DOC-START-002"
  ],
  "requires_human_gate": true,
  "review_due_at": "2026-10-23",
  "safety_class": "INFORMATIONAL",
  "schema_version": "0.1",
  "search_indexable": true,
  "section": "architecture",
  "slug": "architecture/identity-and-authority",
  "source_commit": "6b41cce4496de03c67a501aa94cd41ec6ac0e85a",
  "source_path": "outputs/architecture/myrilum-full-architecture-atlas-v2.2/atlas.json",
  "source_refs": [
    "SRC-ARCHITECTURE-ATLAS-V2-2"
  ],
  "source_repository": "myrilum",
  "summary": "Sign-in identity, task capability and approval for important actions are three different credentials; an action runs only when identity, action, authorization, data, budget and risk conditions all hold at once.",
  "supersedes": null,
  "tags": [
    "architecture",
    "architecture-map:A15"
  ],
  "tasks": [
    "understand_platform_architecture"
  ],
  "title": "Identity, authorization and access decisions",
  "translation_of": "MYRILUM-DOC-ARCH-015@0.1.0:zh-CN",
  "translation_source_sha": "97b503ec9ea65be2d73ba077d645b4bb58fa3204273d0017be24e0c27df61ba7",
  "translation_status": "BLOCKED_PENDING_REGIONAL_REVIEW",
  "version": "0.1.0",
  "visibility": "PUBLIC"
}
