EM-RSK-03 · Subject model · W1
Access, delegation and secret metadata
Account, access role, permission, delegation, access review and key metadata. Credential values are not part of the registry.
Queued for research
Claude: not-started; Grok: not-started.
Research note, in Russian: Entire research brief pending
Subject boundary and candidate types
- DigitalAccount
- AccessRole
- PermissionGrant
- Delegation
- AccessReview
- CredentialMetadata
Deep research questions
- How to link an account and a Person without equating them?
- How do temporary and delegated rights operate?
- How to attest key revocation without disclosing the key?
Verifiable invariants
- An IAM role is not a position
- Delegation does not extend the original right
- Only metadata and a protected reference to the secret are stored
End-to-end acceptance scenario
An assignment change revokes the conditioned rights, keeps separately justified grants and does not disclose secrets in projections.
Negative case
A manager position automatically grants access to all HR data.
Approaches to compare
- NIST CSF/AI RMF: governance and risk functions
- ODRL/PROV: authority, grounds and evidence
- GRC/IAM/BCM practice and NIST SP 800-34 for recovery
Candidates in the live catalogue
- WM-PER-002 · Digital Identity / Account · 0.2.0-legacy · not installed automatically
Semantic fit requires boundary research; a published model does not by itself complete this card. - WM-XCT-002 · Access Contract / Consent · 0.3.0-research.1 · installable
Semantic fit requires boundary research; a published model does not by itself complete this card.
Result requirements
Every card is executed together with the full research contract: definitions, fields and cardinalities, lifecycle, sources, data mastership, rights, the five object facets, at least eight invariants, positive and negative examples, dependencies, migration and applicability limits.