Identity & Access¶
Every action should resolve to a principal, a delegated authority, a policy decision, and auditable evidence.
Design principles¶
Prefer short-lived credentials, explicit delegation, least privilege, strong workload identity, and server-side authorization.