# InfoTechCanon Access Control Model concept boundary review — 2026-09-20 Authority: INFO-WP-0027-T02, the declaration round that gave this artifact an `owned_concepts` list. Resolutions cite the kernel map concept-owner table where it assigns an owner, and are decided in this review where it does not. No concept is renamed, moved or removed. | Concept | Owner | Resolution | Decided by | | --- | --- | --- | --- | | `Action` | model/task | Assigned by the kernel map concept-owner table. | kernel map | | `Attribute` | model/data | Data owns Attribute. Access Control uses it for attribute-based decisions and imports; its AttributeValueType catalog already depends on the data definition. | this review | | `Subject` | model/access-control | ITC-ACCESS owns Subject as the access-control view of an actor. CARING analyses subjects and imports; SecurityCanon imports it under SECURITY-DEC-2026-003 and uses AuthorityContext for its own dimension. | this review | Concepts this artifact declares are listed in its frontmatter. An overlap recorded here means another artifact defines the same name; where the owner is another artifact, this one imports the definition rather than restating it.