R-3 is resolved by disambiguation without a rename. CARING section 10.7 now says its Authority exposure mode names a demanding party rather than a right, links to ITC-ORG section 10.17, and notes that such an Authority holds no organizational authority over the system it compels. ITC-ORG carries the reciprocal sentence and records that SecurityCanon's AuthMode qualifies the exercise of the right rather than redefining it. The seventeen concepts no artifact declared are now declared: eleven to the Organization Model, four to CARING and two to the Capability Model. Capacity in the Organization Model and Capacity behaviour in the Capability Model are two concepts, not one, and neither moves. Two of CARING's four turned out not to be new concepts at all but the prose spellings of CaringCapabilityProfile and CaringDerivedCapability; both spellings are declared to the same owner so the name a reader meets resolves. Effective Access and Declared Access were genuinely undeclared. Three boundary reviews are added for organization, caring and capability, bringing the count to fourteen. The concept_defined_without_owner warning is at zero, and the test that asserted it fires now proves it on a modified corpus instead of on the live one. make check passes with 54 tests, clean validation, no warnings, no stale assets. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 3588@bnt-lap001 Assistant-Session: 24b80f66-e5a7-4e61-99fe-2d422e6d17da
61 lines
1.8 KiB
Markdown
61 lines
1.8 KiB
Markdown
---
|
|
id: agent-brief/standard-caring
|
|
artifact_id: standard/caring
|
|
source_path: standards/caring/InfoTechCanonCaringAccessGovernanceStandard.md
|
|
source_kind: standard
|
|
generated: true
|
|
---
|
|
|
|
<!-- GENERATED by info_tech_canon; do not edit by hand. -->
|
|
|
|
# Agent Brief: InfoTechCanon CARING Access Governance Standard
|
|
|
|
- Artifact ID: `standard/caring`
|
|
- Kind: `standard`
|
|
- Canonical path: `standards/caring/InfoTechCanonCaringAccessGovernanceStandard.md`
|
|
- Full source: `standards/caring/InfoTechCanonCaringAccessGovernanceStandard.md`
|
|
- Summary: Cross-cutting canon standard: InfoTechCanon CARING Access Governance Standard.
|
|
|
|
## Retrieval Hints
|
|
|
|
Imports and anchors:
|
|
- `kernel/itc-core`
|
|
- `model/access-control`
|
|
- `model/data`
|
|
- `model/devsecops`
|
|
- `model/evidence`
|
|
- `model/governance`
|
|
- `model/network`
|
|
- `model/observability`
|
|
- `model/organization`
|
|
- `model/security`
|
|
- `model/task`
|
|
- `standard/tagging`
|
|
|
|
## Owned Concepts
|
|
|
|
- `CARINGAccessDescriptor`
|
|
- `CARINGAnalysisFitnessTest`
|
|
- `CARINGAnalysisProcedure`
|
|
- `CARINGCanonicalRole`
|
|
- `CARINGCapabilityProfile`
|
|
- `CARINGDeclaredAccessMap`
|
|
- `CARINGDerivedCapability`
|
|
- `CARINGEffectiveAccessMap`
|
|
- `CARINGExposureEvent`
|
|
- `CARINGExposureMode`
|
|
- `CARINGInducedAccess`
|
|
- `CARINGOrganizationRelation`
|
|
- `CARINGPlane`
|
|
- `CARINGRedesignProcedure`
|
|
- `CARINGRestrictionPrecedence`
|
|
- `Capability Profile`
|
|
- `Declared Access`
|
|
- `Derived Capability`
|
|
- `Effective Access`
|
|
- `InfoTechCanon CARING Access Governance Standard`
|
|
|
|
## Related Distinctions
|
|
|
|
- **Actor vs Subject vs Principal**: Use actor for the acting entity in a context, subject for the entity a policy evaluates, and principal for the authenticated identity bound to access decisions.
|
|
- **Organization Role vs AccessRole vs CARING role**: Organization roles describe responsibility or position; access roles describe permissions; CARING roles classify access-governance needs and analysis.
|