Capability Issuance, Expiry, and Revocation Lifecycle¶
Lifecycle¶
- Policy and approval produce eligible capability scope.
- Capability token/object is issued with expiry and constraints.
- Runtime validates scope before each operation.
- Continuous verification checks trust drift.
- Capability is revoked on expiry, policy change, anomaly, or incident action.
- Revocation event is recorded in evidence.
Capability Attributes¶
- Subject identity binding
- Allowed actions
- Target binding
- Constraints
- Not-before and expires-at UTC timestamps
- Revocation status and reason
Fail-Closed Principle¶
If capability validity cannot be verified, execution does not continue.
Related: