Skip to content
MCPaiosMachine Authority
Explore
MCPaios/Knowledge Base

KNOWLEDGE / TIPS / POINTS / LINKS

Understand the authority decision in front of you.

The same topic registry powers these articles and the ? buttons in MCPaios. Product information is public; tenant records and authority operations require sign-in.

MCPAIOS / KNOWLEDGE BASE
Knowledge

Control Plane

The human work surface for seeing current machine authority, pending human decisions, machine identities, receipts, and reconstruction evidence.

Tips

Start here when you are unsure what needs attention next.

Points

The Control Plane governs authority state. It does not perform the protected machine action itself.

Knowledge

Ratify

Record a human decision that an exact proposed authority scope may become a grant.

Tips

Read actor, actions, targets, validity window, intent, and policy binding before ratifying.

Points

Ratification authorizes the proposal to become authority; it does not execute the requested action.

Knowledge

Grant

The canonical bounded authority record that states what a machine actor may do, against which targets, under which policy, and for what time window.

Tips

Open a grant whenever scope, ancestry, expiry, or revocation status is unclear.

Points

A credential can authenticate a caller, but the credential is not the grant.

Knowledge

Machine Actor

The exact machine identity named by the grant and request.

Tips

Treat actor identity as an exact binding, not a descriptive label.

Points

A request from a different actor must not inherit authority merely because it can reach the same service.

Knowledge

Principal

The human or governed principal under whose authority the machine grant exists.

Tips

Use the principal to understand who the machine authority ultimately belongs to.

Points

Delegated grants preserve the principal boundary required by the pinned MCP2 protocol.

Knowledge

Policy Digest

A cryptographic digest binding the grant and verification request to the exact governing policy material.

Tips

A changed policy should produce a changed digest rather than silently changing old authority.

Points

A policy label alone is not sufficient. The digest is the integrity binding used by authority verification.

Knowledge

Fence

The last-responsible-moment authority boundary immediately before a protected action can execute.

Tips

Keep target credentials and execution capability behind the fence.

Points

Only an exact current receipted ALLOW may cross the protected execution boundary. Timeout, malformed authority, or required-state failure fails closed.

Knowledge

Operator

A machine identity role that may submit bounded proposals and materialize only authority already ratified by a human.

Tips

Keep operator and fence credentials separate.

Points

An operator does not gain human ratification authority.

Knowledge

Auditor

A read-oriented machine identity role for receipts, reports, authority events, and reconstruction.

Tips

Use an auditor credential for evidence review instead of reusing an operator or fence credential.

Points

Audit access does not imply execution authority.

Knowledge

Decision Receipt

Durable evidence of an authority verification decision, including protocol and request/grant bindings.

Tips

Use the receipt ID as the starting point when investigating a past ALLOW or DENY.

Points

A receipt is evidence of the decision; reconstruction may also require the applicable canonical records and profile evidence.

Knowledge

Reconstruct

Rebuild the historical authority context for a receipt so an auditor can understand why the decision was made and what happened afterward.

Tips

Start with the receipt ID rather than trying to infer history from current grant state.

Points

Historical validity and current eligibility are different questions. Reconstruction preserves that distinction.

Knowledge

Revoke

Prospectively invalidate machine authority so future protected execution cannot rely on the revoked grant.

Tips

Record a clear revocation reason; it becomes part of the authority evidence.

Points

Revocation does not erase historical receipts or pretend a previously valid execution never happened.

Knowledge

Machine Credential

One-time bearer material used to authenticate a machine identity to MCPaios.

Tips

Store plaintext only in the calling service secret manager. MCPaios stores the hash, not the reusable plaintext.

Points

Credentials authenticate. They do not create or expand machine authority.

Knowledge

Receipt ID

The unique identifier for one durable MCPaios authority decision receipt.

Tips

Copy the receipt ID from Evidence when you need to reconstruct or audit a decision.

Points

The ID locates the evidence record; it is not itself the proof material.

Knowledge

Action

The exact operation the machine is asking to perform. Authority is evaluated against this exact action, not a broad description of what the machine can do.

Tips

Keep action names narrow and stable so a grant says exactly what is permitted.

Points

A grant for one action does not authorize a different action merely because both use the same service.

Knowledge

Target

The exact protected resource, service, record, tool, or endpoint against which the action would occur.

Tips

Use the narrowest target identifier that still describes the intended protected resource.

Points

Authority for one target does not automatically extend to neighboring resources or another environment.

Knowledge

Validity Window

The period during which a grant may be considered for execution-time authority verification.

Tips

Keep the window no longer than the work actually requires.

Points

Verifier time controls current eligibility. A request timestamp does not extend expired authority.

Knowledge

Delegation

A bounded child grant derived from existing authority without exceeding the parent grant’s principal, policy, actions, targets, or validity window.

Tips

Inspect the parent chain whenever delegated authority behaves differently than expected.

Points

Delegation can narrow authority; it cannot silently broaden it.

Knowledge

Authority Ledger

The append-only sequence of governed authority events used to preserve how the current machine-authority state came to exist.

Tips

Use the revision, sequence, and ledger head when comparing two snapshots of authority state.

Points

The ledger preserves history; changing current authority does not rewrite earlier events.

Knowledge

Credential Custody

The rule that reusable plaintext machine credentials stay with the calling service, while MCPaios retains only the hash needed to authenticate them.

Tips

Copy a newly issued bearer token directly into the caller’s secret manager before leaving the one-time view.

Points

Do not place bearer credentials in source code, chat, screenshots, tickets, or logs.

Knowledge

Service Role

The fixed machine identity role—operator, fence, or auditor—that determines which MCPaios API operations a credential may call.

Tips

Create separate identities for separate duties instead of sharing one credential across roles.

Points

A role controls access to MCPaios operations; grants still determine what a machine actor may actually do.

Knowledge

Protocol Pin

The exact MCP2 Candidate version and public commit that this MCPaios deployment is qualified to implement.

Tips

Use the protocol endpoint when auditing which MCP2 semantics a receipt or deployment is using.

Points

MCPaios implements the pinned MCP2 protocol; it does not redefine MCP2.

Knowledge

Completion Evidence

The result record bound to a receipted ALLOW after the protected target has attempted execution.

Tips

Treat missing completion evidence after ALLOW as a condition to investigate rather than assuming success.

Points

Authority to execute and evidence that execution completed are distinct facts.

Knowledge

Nonce / Replay Protection

A single-use request value used with tenant and grant context so an accepted protected request cannot simply be replayed.

Tips

Generate a fresh nonce for each new protected execution attempt.

Points

Replay protection is part of the execution boundary; reusing a consumed nonce must fail closed.

Knowledge

Human Membership

An identity-bound role in the MCPaios human authority organization, such as owner, authority administrator, approver, or auditor.

Tips

Grant only the human role required for the person’s actual governance responsibility.

Points

Human membership governs authority decisions. It is separate from machine service credentials.

Knowledge

Human Invitation

A non-authoritative invitation that allows a specific verified person to claim an offered human role.

Tips

Check the email, role, and expiry before sending an invitation.

Points

An invitation grants no authority by itself. Membership exists only after authenticated claim.

Knowledge

Execution Boundary

The target-owned boundary where a protected action is allowed to proceed only after a current durable MCPaios ALLOW.

Tips

Keep target credentials and the execution callback on the target side of the fence.

Points

MCPaios deliberately has no generic /execute route.