PM-AUT-0030
Derivations attach to an Authorization, not to an Operation
A Derivation MUST be enforced through an Authorization. The set of Derivations applied to a transition MUST therefore be a function of the Authorization under which the Event was raised, and MUST NOT be a function of the Operation alone.
Non-normative, and this is the assertion on this page that changes an implementation.
The obvious design is Derivation-per-Operation: creating an Artefact always stamps
createdDate. The method says otherwise. Two Agents invoking the same Operation under different Authorizations get different Derivations, so the same Operation on the same data can write different data depending on who asked. The Derivation table'sEnforced Oncolumn bears this out: both of its rows name an Authorization, not an Operation (IMG:derivation-garantees-states#r3c6).This is more expressive than the obvious design and considerably more dangerous. It means
PO-0001— that a Derivation entails its target State's Restriction — has to be discharged per Authorization, not per Operation, or a model can be correct for one Agent and broken for another. It also means an Authorization is not purely a permission check and cannot be implemented as one.
SRC-PATENT MUST · draft · area AUT · since 0.1.1
Verbatim quote
defines which Derivation should be enforced on the Authorization
Source
frozen 2026-09-08T095618Z · sha256 2d6b61ee55a4688d… · live