# Railiance Platform credential-grant action vocabulary flex-auth uses one protected-system action for the credential broker: | Action | Resource type | Meaning | | --- | --- | --- | | `issue` | `credential-grant` | Authorize issuance of one bounded credential lease from a registered grant. | The request subject is the requesting actor. `context.bound_subject` is the identity to which the resulting credential is bound. Grant id, credential type, issuer, audience, TTL ceiling, permitted actor classes, purposes, and delivery modes are registry-owned resource attributes, not caller assertions. `context.requested_ttl_seconds` is numeric seconds. Parsing the broker's source duration string happens once in the selected wire translator; the policy rejects strings to prevent unit ambiguity.