REFAuthority

Bound authority

Permission that can be explained, constrained and revoked.

This documentation describes the Antecant operating model. The website demonstrates it locally; it does not connect to an autonomous runtime.

Scopes are explicit

Describe the resource, action, environment and expiration for every grant. “Repository read” is different from “repository write”; staging deployment is different from production deployment. Treat unspecified access as denied.

Approval is not enforcement

A visible approval badge cannot secure a tool. The executing system must check current authority at the point of action. The browser demo illustrates this decision but is not a security boundary for external systems.

Revocation is checked at use

New invocations must check current authorization. Revoking a grant should block future use; it does not retroactively undo an action already executed. Consequential work needs cancellation and recovery rules.

Plan for escalation

Escalation should name the requested action, reason, potential consequence and approving role. A request for additional authority is a new decision, not an automatic continuation of the existing run.

SEE THE MODEL IN PRACTICEOpen the interactive walkthrough
FIND YOUR WAY THROUGH THE SYSTEM

· ESC TO CLOSE · TAB TO NAVIGATE