Protocol primitive 2/5
AUTHORITY
AUTHORITY determines who may act, for what purpose, within what scope and under what revocation/expiry conditions.
Rules
Authority must be explicit, scoped and attributable to an authoritative source. An application, agent, device or node receives authority; it does not manufacture authority by being installed, online or in possession of data.
Evaluation
- Identify the actor Entity/application/device.
- Verify the delegation or authorization record.
- Confirm scope, purpose, time and object/domain restrictions.
- Check revocation/supersession.
- Reject scope escalation.
BTDU example
BTDU mutation requires a signed authorization receipt whose scope is BTDU_WRITE. The runtime verifies that receipt before accepting mutation.
Provider boundary
Cloud administrators, storage providers, routers, discovery services and DNS operators do not gain protocol authority merely because they control infrastructure.