SECURITY MODEL
Failure removes executable authority. It does not manufacture certainty.
MCPaios is fail-closed at the execution boundary and conservative in its proof language. Missing current state produces DENY. Compromised trust ends current eligibility. Historical records remain available without being promoted into stronger claims than their evidence supports.
SECURITY / FAIL-CLOSED / CURRENT-TRUSTDEFAULT POSTURE
Unknown is not ALLOW.
The authority fence accepts only an exact, current, receipted decision. Availability pressure does not convert ambiguity into permission.
if authority.state ∉ CURRENT:DENYif request.scope ≠ grant.scope:DENYif decision.receipt ≠ DURABLE:DENYFAIL-CLOSED MATRIX
Seven ordinary ways authority stops.
DENYThe fence cannot confirm current state.
DENYPast authority is not current authority.
DENYHistorical validity cannot cross the present boundary.
DENYNeighboring action or target is outside the grant.
DENYThe request is not bound to the ratified constraints.
DENYA previously evaluated request cannot be reused.
DENYExecution does not begin without recorded evidence.
TRUST BOUNDARIES
Five separations that prevent authority inflation.
The security model keeps identity, authorization, execution, and evidence from certifying themselves.
Machines propose. Authenticated humans ratify or deny exact scope.
prevents self-authorizationMCPaios evaluates authority. The target retains execution credentials.
prevents credential centralizationThe decision is committed before execution; completion is recorded afterward.
prevents outcome substitutionRevocation changes present eligibility without erasing prior records.
prevents history rewritingInternal integrity and independent external time evidence remain distinct claims.
prevents proof overstatementLEAST-PRIVILEGE MACHINE IDENTITIES
Operator, fence, and auditor are separate principals.
The operator submits and operationalizes already-ratified work. The fence verifies an exact request. The auditor reads evidence. No one machine role may propose, authorize, execute, revoke, and certify its own activity.
proposal + bounded grantverify + completereceipt + reconstructionratify + revokeOPTIONAL EVIDENCE PROFILES · HISTORICAL QUALIFICATION
End current trust. Preserve history.
The preserved optional-profile proof corpus includes root-epoch handling. Within that profile, when an authority root is marked compromised, grants rooted in that epoch lose current eligibility. A successor root can become active without deleting the earlier authority records, receipts, or evidence needed for later investigation.
OPTIONAL-PROFILE EVIDENCE BOUNDARIES
Stronger evidence claims require their declared profiles.
The live product declares MCP2-CORE. Witness quorum, provider freshness, and root-epoch evidence below describe optional profiles and preserved qualification; they are not automatically enabled by core access.
Stale distributed authority ≠ executable authority. A cached or replicated view cannot override current canonical state.
One witness ≠ proven authority history. A single external observer cannot satisfy a threshold provenance claim.
One witness failure ≠ authority freeze. Threshold availability allows one provider to fail without collapsing the evidence plane.
Previously valid witness ≠ perpetually current witness. Freshness must be demonstrated, not assumed from prior success.
MAC validity under a compromised root ≠ proof of when evidence existed. Mathematical validity and trusted time provenance remain separate questions.
OPERATE THE BOUNDARY
Security policy becomes operational only when the fence enforces it.
Use the Control Plane to inspect current authority, revoke grants, review evidence, and reconstruct the exact decision path.