Command & assurance / 02
Access / Mission-scoped
Authentication establishes identity. Authorization establishes what that identity may do for a specific mission, environment, platform, action, and time window.
Roles describe decision ownership, not status inside an organization.
Machine identity must be specific enough to revoke without disrupting unrelated missions.
Create distinct identities for each runtime, agent role, adapter, platform, and environment.
Use short-lived credentials bound to audience, purpose, mission, and permitted operation.
Rotate automatically and deny reuse across production, rehearsal, and development boundaries.
Record identity, credential version, policy decision, and target with every external action.
A valid session is never sufficient proof for a mission command.
Revocation is an operational procedure with a platform-state consequence.
Revoke the narrowest affected identity, token, role assignment, or mission authority.
Stop new actions and reconcile in-flight commands using their operation identities.
Transfer human ownership explicitly; never leave an active mission without an authority owner.
Preserve the revocation event, reason, decision owner, affected actions, and recovery outcome.