Generalise the CARING section 32 role set (R-2, INFO-DEC-2026-001)
The role set — Principal, effective actor, Delegator, tool or agent, policy ceiling, execution context, audit identity — now applies wherever a subject's access is exercised through another party, rather than to non-human subjects only. The gap this closes is not about agents. A support operator impersonating a customer involves no non-human subject anywhere in the path, yet without the decomposition that operator's audit identity and policy ceiling collapse into the customer's, which is the outcome CARING's exposure analysis exists to prevent. CARING already names customer impersonation as an exposure mode and ImpersonationBlocked as a control; the vocabulary for analysing it was gated to subjects the case does not involve. Section 33 was already subject-agnostic, so the canon applied the execution paths to any subject while restricting the roles along those paths to non-human ones — an artifact of the section heading, not a considered position. Accepted narrowly. Section 32.1 stays agent-stated, with a note on reading the capability ceiling for a human effective actor. No role is removed, renamed or added, and section 33 is untouched. Option C, a twelfth dimension, is rejected as duplicating sections 32 and 33 while touching a dimension set the Kubernetes RBAC benchmark depends on. Canon version moves to 0.4.0-RC2-itc2; source version stays 0.4.0-RC2, since this revises the InfoTechCanon-aligned standard and claims nothing about upstream CARING. The change is additive: an implementation that applied the set only to non-human subjects stays conformant for those subjects. Review record in history/; the SecurityCanon boundary file and placement record are updated to show R-2 resolved. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 3588@bnt-lap001 Assistant-Session: 24b80f66-e5a7-4e61-99fe-2d422e6d17da
This commit is contained in:
parent
473c1aeca8
commit
30cf417a18
3 changed files with 106 additions and 5 deletions
|
|
@ -64,9 +64,12 @@ Limits of this acceptance:
|
|||
- Scoped to SecurityCanon draft 0.2.0. No stable promotion is asserted.
|
||||
- Acceptance covers the semantic boundary and import declarations. It records no
|
||||
consumer adoption, no runtime claim, and no conformance statement.
|
||||
- A proposal to generalise CARING section 32 beyond non-human subjects is
|
||||
referenced by SecurityCanon but is **not** accepted here. It would be an
|
||||
InfoTechCanon change requiring its own review.
|
||||
- A proposal to generalise CARING section 32 beyond non-human subjects was
|
||||
referenced by SecurityCanon and not accepted at the time of this review. It
|
||||
was reviewed separately on 2026-09-20 and **accepted** as INFO-DEC-2026-001;
|
||||
see `history/2026-09-20_235357+0200-caring-32-generalisation.md`. CARING moves
|
||||
to canon version 0.4.0-RC2-itc2. The change is additive and affects no
|
||||
SecurityCanon declaration.
|
||||
- The G7 validator in `prj-canon-federation` pins card paths for
|
||||
info-tech-canon, commerce-canon and the-custodian. Registering the
|
||||
security-canon card is that project's change; this review does not make it.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue