Access, delegation and secret metadata
Account, access role, permission, delegation, access review and key metadata. Credential values are not part of the registry.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
Bundle → Layer → Finding → Questions Missing, in the backlog
Not described yet. This gap is in the card backlog.
Note: Research contour: bundles not designed yet; questions are listed as open questions.
Classifiers Filled
- Family
- Enterprise profiles
- Category
- Enterprise subject
- Entry kind
- subject
- Domain
- EnterpriseRSK
- Industry
- Cross-industry
- Tags
- EM-RSK-03W1subjectDigitalAccountAccessRolePermissionGrantDelegationAccessReview
What it is Filled
Account, access role, permission, delegation, access review and key metadata. Credential values are not part of the registry.
Why it exists Filled
Account, access role, permission, delegation, access review and key metadata. Credential values are not part of the registry.
Distinguishing features Derived, awaiting review
- An IAM role is not a position
- Delegation does not extend the original right
- Only metadata and a protected reference to the secret are stored
What robots and AI may and may not do Derived, awaiting review
Must not
- Negative case: A manager position automatically grants access to all HR data.
Note: Negative case of the research brief, not yet a rule for agents.
Moral aspects Missing, in the backlog
Not described yet. This gap is in the card backlog.
Owners Filled
Steward
Владелец рисков / CISO / внутренний аудит
Master systems
- GRC
- IAM
- SIEM
- сервис-деск
Links to other meta-models Filled
references
- WM-PER-002 - conceptual-candidate
- WM-XCT-002 - conceptual-candidate
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Derived, awaiting review
- DigitalAccount
- AccessRole
- PermissionGrant
- Delegation
- AccessReview
- CredentialMetadata
Direct properties not applicable Not applicable
Not applicable
Enterprise record contour: physical properties belong to referenced world models.
Recognition required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Hazards and failure modes required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Context of use required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Sources Filled
- NIST CSF/AI RMF: governance and risk functions
- ODRL/PROV: authority, grounds and evidence
- GRC/IAM/BCM practice and NIST SP 800-34 for recovery
Open questions
- How to link an account and a Person without equating them?
- How do temporary and delegated rights operate?
- How to attest key revocation without disclosing the key?
- Установить границу и решение reuse/extend/new по действующим спецификациям.
- Подтвердить semantic crosswalk, права и source mastership.
- Выбрать immutable refs; провести проверки fixtures до заявления о публикационной готовности.
Machine files
Provenance
enterprise research programme · published-partial
Built from: enterprise/models/em-rsk-03/brief.json
Still in Russian: suggested owner, blocking decisions, vercy candidates. Translate in research/enterprise/i18n/units.en.json.