Status: Proposed Date: 2026-09-23 Related: Architecture Review §5.1, ADR-A63, ADR-A69 Drafted by: Agent, autonomous session (P0.1.12). Pending human ratification — see phase-0-status.md.
Identity, authorization, and graph visibility need one extended principal shape shared by human users, ingestion services, and LLM-mediated agents, with graph visibility derived server-side rather than accepted from a client.
Principal {
subject, kind: human|service|agent,
organisationId, tenantId,
scope: { projects: [..], environments: [..] }, // explicit, never wildcard
roles: [ scoped role claims ],
graphVisibility: GraphSelector, // derived, never client-supplied
entitlements: [..],
delegation: { onBehalfOf?, chain: [..] }?,
deadline, correlationId
}
Rules:
graphVisibility is derived server-side from roles, activation binding, and dataset binding, once per request. It is the only input to graph scoping. No component re-derives it or accepts it from elsewhere.ingest:route:*, query:projection:*).pty:Delegation.cause.kind = admin in the change feed (ADR-A57).Principal constructed from a client-supplied graphVisibility is rejected (L1 test, P0.7.1).Principal.scope.environments binds to; project scope is authoring-only and does not grant runtime graph visibility.