17
DraftS05-CON-010v0.1Source imported
Section 21 of 102
20. Agent Permission and Authority Model
Stable section ID: S05-CON-010-SECTION-21 · 27 content blocks
The Agent Permission and Authority Model determines what an agent may access, recommend, modify, approve, initiate, or execute.
Permissions shall be:
- Explicit.
- Role-based or attribute-based.
- Limited to the required scope.
- Time-bounded where appropriate.
- Context-sensitive.
- Revocable.
- Auditable.
- Denied by default when not granted.
Authority shall be defined separately for information access and physical action. An agent may be permitted to read structural data without being permitted to alter it, or to recommend an operational change without executing it.
Permission evaluation may consider:
- Agent identity.
- User identity.
- Building or project ownership.
- Agent role.
- Current lifecycle phase.
- Building operational state.
- Location.
- Time.
- Risk level.
- Occupancy condition.
- Active emergency state.
- Required human approval.
- Available evidence.
- Certification and qualification status.
Agents shall not delegate their permissions to another agent unless such delegation is explicitly authorized, limited, traceable, and revocable.