Skip to content
MCPaiosMachine Authority
Explore
MCPaios/How Machine Authority Works

MACHINE AUTHORITY LIFECYCLE

A governed path from proposal to reconstructible consequence.

MCPaios prevents a request, approval, grant, authority decision, execution result, and revocation from collapsing into one ambiguous event. Eight stages preserve who did what, under which authority, and when that authority stopped.

LIFECYCLE / 08-STAGE / REQUEST → REVOCATION
01

STAGE 01

Machine proposal

An authenticated operator identity submits an exact request without claiming that the request is already authorized.

BOUND RECORDactoractiontargetpurpose
02

STAGE 02

Human decision

An authenticated owner, authority administrator, or approver reviews the exact proposal and records a reasoned decision.

BOUND RECORDhuman identitytenant roledecisionreason
03

STAGE 03

Bounded grant

Only the ratified scope becomes authority. Actor, action, target, policy, purpose, and validity remain bound.

BOUND RECORDratificationpolicy digestvalidity windowrevocation handle
04

STAGE 04

Fence verification

The target-side fence resolves current state immediately before the protected credential can be used.

BOUND RECORDcurrent statusscope matchexpirynonce
05

STAGE 05

Local execution

Only a durable, receipted ALLOW crosses the boundary. The protected target executes with its own credential.

BOUND RECORDno hosted executetarget custodyexact requestlocal side effect
06

STAGE 06

Receipt

The ALLOW or DENY decision remains distinct from the later completion result reported by the target.

BOUND RECORDdecision receiptauthority snapshotcompletion statusresult digest
07

STAGE 07

Reconstruction

The proposal, human decision, grant, fence result, completion, identities, and policy binding are reproduced together.

BOUND RECORDordered evidencechain integrityservice attributionprotocol pin
08

STAGE 08

Revocation

Human authority can end eligibility before a later protected action. Revocation does not undo completed actions or guarantee interruption of an action already running.

BOUND RECORDrevoker identityreasonrevoked statehistory retained

WHY THE ORDER MATTERS

The receipt must precede execution. Revocation must survive reconstruction.

A fence cannot execute first and create a convenient ALLOW afterward. A revocation cannot erase the successful activity that occurred while authority was current. Ordering is part of the security property.

t₀ proposalt₁ human ratificationt₂ bounded grantt₃ durable ALLOWt₄ local executiont₅ completiont₆ revocation → later DENY

OPERATE THE BOUNDARY

Follow the lifecycle inside the working authority plane.

Authenticated operators can review decisions, inspect grants, revoke authority, read evidence, and reconstruct the complete path.

Open the Control Plane