22 lines
2.4 KiB
Markdown
22 lines
2.4 KiB
Markdown
|
|
# CARING access governance concept boundary review — 2026-09-20
|
||
|
|
|
||
|
|
Authority: INFO-WP-0027-T07, which declared the concepts CARING defines, T05,
|
||
|
|
which resolved residual R-3, and ADHOC-2026-09-20-T01, which bound the Scope
|
||
|
|
dimension to one definition. No concept is renamed, moved or removed.
|
||
|
|
|
||
|
|
| Concept | Owner | Resolution | Decided by |
|
||
|
|
| --- | --- | --- | --- |
|
||
|
|
| `Effective Access` | standard/caring | CARING's central distinction, with `Declared Access`. Declared here under T07; the Kubernetes RBAC benchmark depends on it. | this review |
|
||
|
|
| `Declared Access` | standard/caring | As above. Access Control owns the authorization mechanisms; CARING owns the declared-against-effective analysis over them. | this review |
|
||
|
|
| `Capability Profile` | standard/caring | The prose spelling of the declared `CaringCapabilityProfile`. Both spellings are declared so that the name a reader meets in the text resolves; one owner, no conflict. | this review |
|
||
|
|
| `Derived Capability` | standard/caring | As above, for `CaringDerivedCapability`. | this review |
|
||
|
|
| `Authority` | model/organization | CARING section 10.7 names a legal, regulatory or institutional body with exceptional access claims — a demanding party, not a right. ITC-ORG section 10.17 owns `Authority` as the right itself. Both sections now carry the disambiguation. | this review (R-3) |
|
||
|
|
| `Scope` | model/identity | ITC-IDENT section 2.10 owns the general boundary. CARING section 21 ranges over its instances and its ladder is a value set, not a second definition. ITC-ACCESS `ResourceScope` refines the same concept. | ADHOC-2026-09-20-T01 |
|
||
|
|
| `Environment` | model/landscape | The kernel map assigns Environment to Landscape. CARING section 21.5 enumerates values for it; SecurityCanon imports it from Landscape. | kernel map |
|
||
|
|
| `Subject` | model/access-control | ITC-ACCESS owns Subject as the access-control view of an actor. CARING analyses subjects and imports. | this review |
|
||
|
|
| `Canonical Role`, `Plane`, `Condition` | standard/caring | CARING's own dimensions. `Operator` the role is not `OPERATE` the SecurityCanon auth mode, and `Condition` is not `Activation`; both pairs are recorded as distinct in the SecurityCanon boundary. | SECURITY-DEC-2026-003 |
|
||
|
|
|
||
|
|
Concepts this artifact declares are listed in its frontmatter. An overlap
|
||
|
|
recorded here means another artifact defines the same name; where the owner is
|
||
|
|
another artifact, this one imports the definition rather than restating it.
|