The Authorization Model specifies the decision at the center of the framework: how a proposed action becomes — or fails to become — an authorized governed effect. The other normative sections specify the parts the decision composes. The Mechanistic Boundary (ZTG-1) specifies the structural separation the decision sits inside; Identity Integrity (ZTG-0d) specifies whose authority the decision recognizes; Irreversibility of Harm (ZTG-5) specifies the consequence dimension the decision is graded against; the structural prerequisites specify the recorded, reproducible, temporally-anchored, consistent substrate the decision runs over. §3 specifies the decision that binds them into a single verdict.
Operational Questions #
§3 is the section mapped to admissibility — was this action actually authorized under valid, human-governed conditions? It owns the general form of that question; ZTG-5 owns the consequence-specific portion of it (harm class, ceiling, gate). §3 is also where the convergence test is situated as the discipline that keeps an admissibility determination checkable rather than asserted, with its full method deferred to §22. The authorization model conditions every other operational question, because each of them — evidence coupling, fail-closed semantics, replayability, governance continuity, override visibility, execution-boundary enforcement — is a property of, or a precondition for, the authorization decision this section defines.
Normative #
An authorization is the explicit, recorded determination that a specific proposed action is admissible: permitted, under valid human-governed conditions, at a definite instant, by an attributable authority, within bounded consequence. The architecture's default disposition toward any proposed action is refusal; an authorization is the positive grant that converts that default into permission for one action. Authority is never assumed, inherited, or inferred from the absence of denial.
The Authorization Request #
The unit of decision is the authorization request: the object the boundary evaluates. A request comprises the proposed action and its validated parameters (ZTG-1 / §18), the authorizing identity asserted for it (ZTG-0d), the registered surface it would route through (ZTG-3), and the decision-time temporal context against which it is evaluated (ZTG-0c). A request is evaluated as a whole and against a single coherent snapshot of governance state (ZTG-0e); an architecture that decides parts of one request against different states or different instants has not produced one authorization.
The reasoning system originates the proposal — the candidate action and its parameters — and nothing else in the request. It does not supply the authorizing identity, the harm classification, the time, or the policy. The governed subject proposes; it does not author the inputs against which its proposal is judged.
The Verdict Space #
Every evaluation of a request produces exactly one of three verdicts:
authorize— the request is admissible; the action is granted permission to become a governed effect through its routed surface.refuse— the request is not admissible; no effect follows. Refusal is the default and the most common verdict, and it is recorded with the same fidelity as a grant (ZTG-0a).escalate— admissibility cannot be determined by the architecture alone, or policy designates the decision for human judgment; the request is routed to the authority policy specifies, and the escalation, its trigger, and its routing are recorded.
escalate is a first-class verdict, not a deferred refuse. It is how the model
routes the decisions a policy reserves for human authority — high-consequence actions,
edge cases, situations requiring institutional judgment — without either granting them
mechanically or refusing them as if they were inadmissible.
Admissibility #
A request is admissible only if every one of the following holds at decision-time. Each condition is owned by the section named; §3 is where they compose into a single determination. Admissibility is a conjunction: the failure of any one condition makes the request inadmissible, and the absence of a positive determination on any condition is a failure, not a pass.
- Attributable authority. A valid authorizing identity, traced through its delegation chain to a ratifying principal, bound by non-repudiable, revocable credentials, and valid as of decision-time (ZTG-0d).
- Coherent temporal context. A single decision-time from a trusted source and a coherent point-in-time snapshot of governance state; no stale, future, or temporally inconsistent inputs (ZTG-0c).
- Consistent governance. A single governance view, agreed across enforcement points and applied atomically (ZTG-0e).
- Policy permission. The proposed action is permitted by the policy in effect in the governance bundle for that snapshot.
- Closed-surface routing. The action routes to a registered surface or sub-surface (ZTG-3), selected by governed routing over validated features, carrying that channel's declared harm class.
- Bounded consequence. The action is within its policy-assigned liability ceiling and is routed to the harm-class-appropriate gate (ZTG-5).
- Recordable and coupled. The decision is recorded with integrity (ZTG-0a) and is replayable (ZTG-0b); where it authorizes an effect, that effect will be coupled to its evidence (ZTG-4).
When all conditions hold, the verdict is authorize. When a condition fails, the
verdict is refuse. When a condition cannot be determined, or policy reserves the
decision, the verdict is escalate. There is no admissible action outside this
conjunction, and there is no path to a grant that does not establish every condition
in it.
Authorization Provenance #
Every authorization MUST trace to human-attested authority. The authority under which a grant is made is either direct human attestation — a ratifying principal authorizing the action — or derivation from human-attested policy — a policy, itself ratified by a principal under ZTG-0e, that permits the action. No authorization derives from any other source. The model admits no self-bootstrapped authority: the system does not originate the authority under which it acts, and there is no representable grant whose authority terminates at the system rather than at a human or institutional principal.
This is the property on which the framework's liability argument rests. Because every authorized effect traces to either a principal's direct attestation or a principal's ratified policy, every authorized effect has an accountable human author — the party whose attested acceptance of responsibility the authorization carries (§1.0). An architecture in which some authorizations could not be traced to attested human authority would be one in which some consequential actions had no responsible author, which is the condition the model exists to make unrepresentable.
The Convergence Test #
An admissibility determination is admissible evidence only if it is checkable. The convergence test is the discipline that holds it to that standard: an independent re-evaluation of a request, over the recorded substrate, MUST converge on the same determination, and a determination that cannot be independently reproduced is not yet admissible. This is why the model's inputs are recorded (ZTG-0a), its evaluation is deterministic and replayable (ZTG-0b), and its consequence assessment is banded (ZTG-5): each is what lets a second party regenerate the determination rather than take it on trust. The full method of the convergence test — the independent-assessment procedure and the criteria for convergence — is larger than this section and is specified in §22.
Composition #
The authorization model is not a separate mechanism from the boundary; it is the decision the boundary runs. ZTG-1 guarantees that every proposed action reaches the model and that no action becomes an effect except through its verdict; §3 specifies what that verdict is and how it is reached. ZTG-3 guarantees the verdict has a closed set of channels to authorize into; ZTG-5 grades the verdict by consequence; the prerequisites guarantee the substrate the verdict is computed over and recorded into. The binding force §1.0 asks for — authority exercised at the point of execution rather than advisorily — is realized here: the model is the point at which an accountable human's authority is exercised against a specific action, mediated by ZTG-1 and attributed by ZTG-0d.
Conformance Criteria #
A conforming implementation can: represent every authorization decision as a request evaluated as a whole against one coherent snapshot; produce exactly one of the three verdicts for every request and record refusals and escalations with grant-level fidelity; demonstrate that a grant is issued only when every admissibility condition is established, and that absence of a condition produces refusal or escalation rather than a grant; trace every authorization to direct human attestation or to human-attested policy, and demonstrate that no grant terminates its authority at the system; demonstrate that escalation routes to the authority policy specifies; and demonstrate that its authorization determinations are independently reproducible from the recorded substrate (convergence test, §22).
Further Considerations #
The reference-monitor grounding. Security engineering arrived, half a century ago, at the conditions a component must meet to be trusted to mediate access: it must be invoked on every access (complete mediation), it must be tamperproof, and it must be small and simple enough to be verified. The authorization model is the reference monitor for a governed autonomous system's effects on the world. Complete mediation is ZTG-1; tamperproofing is the boundary's isolation from the reasoning it gates; verifiability is replay (ZTG-0b) and the convergence test. The discipline is the same one the reference-monitor concept established — a mediator you cannot bypass, cannot tamper with, and can independently check — applied to authorization rather than to file access. The older idea sets the bar; §3 is what clears it for this domain.
Admissibility is not correctness. The model guarantees that an authorized action was permitted under valid human-governed conditions. It does not guarantee that the action was wise, optimal, or good. A correctly-authorized action can still be a mistake — the policy that permitted it may have been ill-judged, the principal who attested it may have erred. The framework is precise about which of these it provides: it makes consequential action governed and attributable, so that a mistake has a responsible author and a reconstructable basis, not that mistakes do not occur. Conflating admissibility with correctness would overclaim; the model's value is that it makes the governance of an action a checkable fact, which is the precondition for holding anyone to account for the action's merits.
Refusal is the common case, and that is the design. Because the default disposition is refusal and admissibility is a conjunction of conditions every one of which must hold, most evaluations end in refusal, and the refusals carry most of the diagnostic information about how the boundary behaves under pressure (ZTG-0a). A model that authorized by default and refused by exception would invert the burden of proof the framework places on action: under ZTG, action bears the burden of establishing its admissibility, not the architecture the burden of establishing a reason to refuse.
Escalation as the third path. Much of the value of the model is in not collapsing the verdict space to grant-or-refuse. A two-valued model forces every decision policy wishes to reserve for human judgment into either a mechanical grant or a refusal that reads as inadmissibility. The third verdict is what lets the architecture route a decision to human authority as a positive act — the human engaging the decision the policy chose to reserve for them — rather than as a failure of the machine to decide.
How We Do It #
Constable implements the authorization model as the decision function of its execution gate: a reference monitor between the agent runtime and the effect surface that every proposed action must traverse and that emits exactly one verdict per request.
The request and the gate. Constable assembles each authorization request from the
agent's proposed action and validated parameters (post-Airlock), the asserted
authorizing identity, the candidate surface route, and the pinned decision-time
snapshot. The gate evaluates the request as a whole with OPA/Rego and returns one of
authorize, refuse, or escalate, bound to the action, policy version, identity,
and decision-time, and recorded under ZTG-0a (AUTHORIZATION_REQUESTED,
BOUNDARY_EVALUATED, and the matching verdict event).
Admissibility as policy. The seven admissibility conditions are evaluated against the pinned governance bundle: identity validity (ZTG-0d), temporal coherence (ZTG-0c), bundle consistency (ZTG-0e), policy permission, surface routing (ZTG-3), ceiling and gate (ZTG-5), and recordability. A request that fails any condition refuses; a request whose determination is indeterminate, or which policy reserves, escalates through HumanSeal.
Provenance retention. Each grant records the authority it was made under — the attesting principal, or the ratified policy and the principal who ratified it — so the authority of any authorized effect traces to a human author. Constable holds no path by which a grant can be issued under authority that does not resolve to attested human responsibility.
Escalation through HumanSeal. Escalated requests are surfaced to the authority policy designates, with the consequence context (harm class, ceiling, composite assessment) presented, and the human's engagement recorded as the act that resolves the escalation.
Convergence and conformance. Constable's replay harness (ZTG-0b) regenerates a recorded determination from its substrate; the convergence test builds on this to check that independent assessment converges. The full conformance protocol is documented in the conformance verification specification referenced in §22.