跳转到内容

ak.identity.accountability_grant

← Event kinds

eventak.identity.accountability_grant· identity· active
wire scope
durable_event
reducer input
yes
payload
Issuer-signed endorsement that a subject DID (typically an agent / service / hosted actor) is accountable to the issuer for a declared scope (employment / contracted_service / agent_operator). Every Actor Profile.accountable_principal_ids[] entry requires a matching active record at profile admission; a missing one deterministically rejects the whole profile Event with accountability_grant_missing. See zh/models/actor.md section 3.3.1. expires_at is optional; absent means non-expiring, governed by grant_status revocation and controller lifecycle cascade. Ordinary issuer grants are admitted only in the issuer PCR with the issuer device method. The sole Service issuer exception is the closed Applet managed-actor creation aggregate: its grant resides in the exact provision Collaboration Realm and both proofs use the exact accepted registration-epoch Service method. No standalone Service grant ingress or cross-Realm search is authorized. Collaboration Realm membership or a Profile association never grants source Event disclosure or replication of this private identity/control fact. Only the kind-specific source scope and registered authority/profile evidence disclosure contract may release authorized material, without underlying control-stream access.

Wire scope

durable_event · Persisted canonical history & reducer input.

Source