The authority layer

Not access. Authority.

Authentication answers a narrow question: is this user who they claim to be? Passport answers a much more consequential one: does this user or system hold the authority to perform this specific action, in this specific context, at this specific moment?

Authority in Passport is scoped, specific and revocable. It is not a general permission to act — it is a standing record of what is permitted, why, and for how long.

  • Identifies the actor — human, service or autonomous system
  • Binds the actor to a scoped, time-bound authority
  • Verifies the authority is current and not revoked
  • Presents the authority to Guardian for the control decision
Function

What Passport does.

Passport is the platform's bridge between identity and authority — the point at which a request becomes a claim that can be checked.

01 — Identify

Establishes the actor

Determines whether the request originates from a human, a service, or an autonomous system — and what class of actor it belongs to.

02 — Bind

Attaches authority

Binds the actor to a specific authority: what it may do, over which systems, under which conditions, for how long.

03 — Verify

Checks validity

Confirms the authority is current — not expired, not suspended, not revoked — before the request is presented to Guardian.

04 — Scope

Limits the permitted action

Authority is never general. It is scoped to the specific action requested, in the specific context the request names.

05 — Present

Hands off to Guardian

Passes the verified authority to Guardian, which decides whether the action may proceed, and under what limits.

06 — Record

Preserves the record

Every authority check is itself part of the durable record — who asked, under what authority, and when it was checked.

Distinction

Why this is not login.

Ordinary authentication answers whether a user is who they say they are. Passport answers whether that user or system is entitled to do this, here, now.

Question Ordinary authentication Passport
Who is acting? Username and credentials Actor identity plus actor class — human, service, autonomous system
What may they do? Role or group membership Scoped, specific authority bound to the requested action
In what context? Usually not considered Authority is contextual — the same actor may hold authority in one context and not another
Is it still valid? Session-based, time-limited by token Standing authority, independently revocable, verified on every consequential request
What happens next? Access granted or denied to the resource Authority presented to Guardian for the control decision
Role in the platform

Passport sits between FORGE and Guardian.

After FORGE structures the problem, Passport establishes who or what is entitled to act before any policy decision is made.

See authority in the governed route.

One platform journey, from problem to proven outcome, using synthetic data only. See Passport check authority before anything consequential is allowed to proceed.