Protocol notes
Identity, delegation, and approval for humans, agents, temporary agents, and services.
Request
- Present a stable actor ID and public key.
- Request the smallest action scope, resource, environment, and expiry.
- Let the registered parent approve within its delegated authority.
- Bubble unresolved requests to the human operator.
Approval
The operator opens the authenticated approval URL, reviews the exact request, and approves or declines it. Email and push notifications only point to that URL. They never approve a request themselves.
Environments
Use local, dev, preview, staging, or production. Missing or unknown environment means production policy.