Search and contents

Identity, authorization and access decisions

Sign-in identity, task capability and approval for important actions are three different credentials; an action runs only when identity, action, authorization, data, budget and risk conditions all hold at once.

In developmentNot availableVerified

What this page covers

This is MYRILUM's target architecture. It does not mean everything on the map is live; whether a capability can be used today is stated in “Current availability”.

Central identity, resource-level permissions, task delegation and approval of high-impact actions are four different layers of control. This page states principles only; implementation details are not published.

Three credentials that never substitute for each other

Sign-in identity proves who you are; task capability states what a task may do; approval for an important action covers this one time and this one object. Each is issued and checked on its own, and none can stand in for another.

Every condition must hold at once

Allowed to run = valid identity ∧ lawful action ∧ matching authorization ∧ data allowed ∧ budget available ∧ risk cleared. Anything not explicitly allowed is treated as not allowed. Being able to use a product feature is not the same as permission over its data or its actions.

Approval is bound to one specific action

An important action is approved by an authorized person on the basis of evidence, and the approval holds only for that plan version, recipient, environment, key data flows and budget; if any of them changes, the approval no longer applies. A model can never issue an approval on a person's behalf.

Checked every time, revocable at any time

Permission is not checked only once when a task is created; it is checked again before every important action. After revocation or freezing, new actions stop at once; actions already accepted externally are queried or compensated. Every time leaves a record of who acted, on what basis, on which object and when.

The two regions' identity is kept apart

Identity authentication for the China region and the global region runs in separate environments. Data, permissions and forbidden actions are hard boundaries and are never relaxed because a model is cheaper or delivery would be faster.

Source

This page follows A15 of the MYRILUM architecture map v2.2. Under the public boundary it publishes principles only and carries no diagram. Related: “Business domains and fact authority”; “Agent runtime and failure recovery”; “Deployment and trust boundaries”.

Was this page helpful?

Sources and maintenance
Region
Global
Version
0.1.0
Publication
Published globally
Document status
Approved · Drafted
Authorization
Public information
Command authority
None
Type
Concept
Audience
Technical leads, Developers, Organization leaders, Integration partners, Agents
Safety class
Informational
Agent tasks
understand_platform_architecture
Owner
Web3Capital Documentation Steward
Last verified
2026-09-23
Review due
2026-10-23
Source commit
6b41cce4496d
Canonical authority
SRC-ARCHITECTURE-ATLAS-V2-2
Content digest
cdeb6e74bcf01895
Stable citation
MYRILUM-DOC-ARCH-015@0.1.0:en#overview

Machine-readableMarkdownMetadataJSON-LDChunks

This documentation grants no execution, release, or production authority.

Sources and maintenance

Region
Global
Version
0.1.0
Publication
Published globally
Document status
Approved · Drafted
Authorization
Public information
Command authority
None
Type
Concept
Audience
Technical leads, Developers, Organization leaders, Integration partners, Agents
Safety class
Informational
Agent tasks
understand_platform_architecture
Owner
Web3Capital Documentation Steward
Last verified
2026-09-23
Review due
2026-10-23
Source commit
6b41cce4496d
Canonical authority
SRC-ARCHITECTURE-ATLAS-V2-2
Content digest
cdeb6e74bcf01895
Stable citation
MYRILUM-DOC-ARCH-015@0.1.0:en#overview

This documentation grants no execution, release, or production authority.