102 lines
2.7 KiB
JSON
102 lines
2.7 KiB
JSON
|
|
{
|
||
|
|
"systems": [
|
||
|
|
{
|
||
|
|
"id": "qonto-assistant",
|
||
|
|
"name": "Qonto Governed Assistant",
|
||
|
|
"resource_types": [
|
||
|
|
{
|
||
|
|
"name": "finance-snapshot",
|
||
|
|
"scope_level": "Resource",
|
||
|
|
"planes": [
|
||
|
|
"Data",
|
||
|
|
"Audit"
|
||
|
|
],
|
||
|
|
"metadata": {
|
||
|
|
"description": "Read-only Qonto finance capability surface (org summary, transactions, CostRunRate hints). No spend/transfer/card/write capability is ever registered here -- those are hard-denied inside qonto-assistant's own policy kernel and never reach flex-auth."
|
||
|
|
}
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"actions": [
|
||
|
|
{
|
||
|
|
"name": "finance.qonto.read",
|
||
|
|
"capabilities": [
|
||
|
|
"View",
|
||
|
|
"Audit"
|
||
|
|
],
|
||
|
|
"planes": [
|
||
|
|
"Data",
|
||
|
|
"Audit"
|
||
|
|
],
|
||
|
|
"exposure_modes": [
|
||
|
|
"Masked"
|
||
|
|
],
|
||
|
|
"metadata": {
|
||
|
|
"required_context": [],
|
||
|
|
"description": "Coarse \"may this actor use qonto-assistant's read surface at all\" gate. Tenant capability-role/plan liveness (VEN/CUS, ADR-0014) is a separate check against tenant-engine's live-lookup endpoint, not encoded in this policy."
|
||
|
|
}
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"caring_profiles": [
|
||
|
|
"caring-0.4.0-rc2"
|
||
|
|
],
|
||
|
|
"metadata": {
|
||
|
|
"flex_auth_contract": "protected-system-v0",
|
||
|
|
"boundary_contract": "qonto-assistant/docs/SecurityPractice.md"
|
||
|
|
}
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"resource_manifests": [],
|
||
|
|
"tenants": [
|
||
|
|
{
|
||
|
|
"id": "tenant:friendly:binky",
|
||
|
|
"name": "Binky Hedgehog GmbH"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"subjects": [
|
||
|
|
{
|
||
|
|
"id": "agent-harness-binky",
|
||
|
|
"type": "Agent",
|
||
|
|
"display_name": "agent-harness session (binky tenant)",
|
||
|
|
"organization_relation": "ServiceProvider",
|
||
|
|
"roles": [
|
||
|
|
"Operator"
|
||
|
|
],
|
||
|
|
"groups": [
|
||
|
|
"group:qonto-assistant-readers"
|
||
|
|
],
|
||
|
|
"tenant": "tenant:friendly:binky",
|
||
|
|
"metadata": {
|
||
|
|
"description": "Harness-run agent sessions calling qonto-assistant's finance.qonto.read capability over REST or MCP."
|
||
|
|
}
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "bernd.worsch",
|
||
|
|
"type": "Human",
|
||
|
|
"display_name": "Bernd Worsch (founder)",
|
||
|
|
"organization_relation": "Customer",
|
||
|
|
"roles": [
|
||
|
|
"Operator"
|
||
|
|
],
|
||
|
|
"groups": [
|
||
|
|
"group:qonto-assistant-readers"
|
||
|
|
],
|
||
|
|
"tenant": "tenant:friendly:binky",
|
||
|
|
"metadata": {
|
||
|
|
"description": "Founder operator, human REST/MCP caller."
|
||
|
|
}
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"groups": [
|
||
|
|
{
|
||
|
|
"id": "group:qonto-assistant-readers",
|
||
|
|
"display_name": "qonto-assistant finance.qonto.read callers",
|
||
|
|
"members": [
|
||
|
|
"agent-harness-binky",
|
||
|
|
"bernd.worsch"
|
||
|
|
],
|
||
|
|
"tenant": "tenant:friendly:binky"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"relationships": []
|
||
|
|
}
|