Passport
Passport is the authority and identity layer of CAELOMERE. It verifies who or what is asking, what authority it holds, what systems and actions it is permitted to use, and whether that authority is still valid. Passport is not simply login or authentication — it is the standing record of who or what is entitled to act.
Not access. Authority.
Authentication answers a narrow question: is this user who they claim to be? Passport answers a much more consequential one: does this user or system hold the authority to perform this specific action, in this specific context, at this specific moment?
Authority in Passport is scoped, specific and revocable. It is not a general permission to act — it is a standing record of what is permitted, why, and for how long.
- Identifies the actor — human, service or autonomous system
- Binds the actor to a scoped, time-bound authority
- Verifies the authority is current and not revoked
- Presents the authority to Guardian for the control decision
What Passport does.
Passport is the platform's bridge between identity and authority — the point at which a request becomes a claim that can be checked.
Establishes the actor
Determines whether the request originates from a human, a service, or an autonomous system — and what class of actor it belongs to.
Attaches authority
Binds the actor to a specific authority: what it may do, over which systems, under which conditions, for how long.
Checks validity
Confirms the authority is current — not expired, not suspended, not revoked — before the request is presented to Guardian.
Limits the permitted action
Authority is never general. It is scoped to the specific action requested, in the specific context the request names.
Hands off to Guardian
Passes the verified authority to Guardian, which decides whether the action may proceed, and under what limits.
Preserves the record
Every authority check is itself part of the durable record — who asked, under what authority, and when it was checked.
Why this is not login.
Ordinary authentication answers whether a user is who they say they are. Passport answers whether that user or system is entitled to do this, here, now.
| Question | Ordinary authentication | Passport |
|---|---|---|
| Who is acting? | Username and credentials | Actor identity plus actor class — human, service, autonomous system |
| What may they do? | Role or group membership | Scoped, specific authority bound to the requested action |
| In what context? | Usually not considered | Authority is contextual — the same actor may hold authority in one context and not another |
| Is it still valid? | Session-based, time-limited by token | Standing authority, independently revocable, verified on every consequential request |
| What happens next? | Access granted or denied to the resource | Authority presented to Guardian for the control decision |
Passport sits between FORGE and Guardian.
After FORGE structures the problem, Passport establishes who or what is entitled to act before any policy decision is made.
See authority in the governed route.
One platform journey, from problem to proven outcome, using synthetic data only. See Passport check authority before anything consequential is allowed to proceed.