← SES-023 — Versioning, Negotiation, and Compatibility · Standard Index · SES-025 — Provider Capability and Fidelity Profiles →
Status: Draft 1.0 — Normative target.
A mature SES MUST distinguish authentication, authorization, delegation, approval, and execution-time revalidation. These concepts MUST NOT be represented by one opaque boolean.
Authority SHOULD be modeled as a structured tuple containing principal, action/capability, resource scope, tenant scope, purpose, classification constraints, temporal validity, environmental constraints, obligations, and delegation lineage.
Delegation MUST be explicit, bounded, attributable, and attenuable. A delegate MUST NOT acquire authority outside the delegator’s authority.
Formally:
Authority(delegate) ⊆ Authority(delegator)
unless a separate trusted authority grants additional rights.
Delegation MAY narrow actions, resources, tenants, time, purpose, or budgets. It MUST NOT widen them.
A system MUST define how revoked or expired authority is detected before execution. Long-lived delegated authority MUST NOT be treated as permanently valid.
Where approval is required, approval MUST bind to a canonical semantic artifact or digest. Approving one operation MUST NOT implicitly approve a materially different operation.
Define authority algebra operators, delegation token format, attenuation rules, approval protocol, revocation protocol, and proof verification.
Adversarial tests MUST attempt privilege widening through delegation, approval substitution, scope substitution, stale tokens, and replay. All widening attempts MUST fail.
← SES-023 — Versioning, Negotiation, and Compatibility · Standard Index · SES-025 — Provider Capability and Fidelity Profiles →