ENTITY Documentation Portal
Protocol primitive 2/5

AUTHORITY

AUTHORITY determines who may act, for what purpose, within what scope and under what revocation/expiry conditions.

Rules

Authority must be explicit, scoped and attributable to an authoritative source. An application, agent, device or node receives authority; it does not manufacture authority by being installed, online or in possession of data.

Evaluation

  1. Identify the actor Entity/application/device.
  2. Verify the delegation or authorization record.
  3. Confirm scope, purpose, time and object/domain restrictions.
  4. Check revocation/supersession.
  5. Reject scope escalation.

BTDU example

BTDU mutation requires a signed authorization receipt whose scope is BTDU_WRITE. The runtime verifies that receipt before accepting mutation.

Provider boundary

Cloud administrators, storage providers, routers, discovery services and DNS operators do not gain protocol authority merely because they control infrastructure.