flowchart LR
subgraph Roles["Human and service roles"]
E["Executive"]
O["Business owner"]
R["Reviewer"]
P["Policy engineer"]
A["Platform administrator"]
U["Auditor"]
W["Agent workload"]
X["Executor workload"]
V["Verifier workload"]
end
subgraph Permissions["Target permissions"]
READ["Read portfolio and assurance"]
RISK["Accept risk / suspend scope"]
DECIDE["Approve or deny exact claim"]
POLICY["Draft and test policy"]
PROMOTE["Review and promote version"]
ADMIN["Register integrations and operate runtime"]
AUDIT["Read evidence and export review pack"]
PROPOSE["Propose Action Claim"]
EXECUTE["Consume bound capability"]
VERIFY["Read authoritative state and attest outcome"]
end
E --> READ
E --> RISK
O --> READ
O --> RISK
R --> DECIDE
P --> POLICY
O --> PROMOTE
A --> ADMIN
U --> AUDIT
W --> PROPOSE
X --> EXECUTE
V --> VERIFY
CURRENT["CURRENT: one shared bearer token
coarsely spans human and service operations"]
REQUIRED["REQUIRED: OIDC + workload identity + tenant RBAC
separation of duties + scoped service credentials"]
CURRENT -.-> Permissions
REQUIRED -.-> Permissions