Overview
Create communication clients, operation grants, transport permissions, resource-sensitive authorization, and outbound delegation policies.
Problem
Installed applications need explicit authority boundaries instead of implicit trust.
Solution
Use AccessGuard authorization records to define who can call which operation over which transport and whether AccessGuard may represent that source application downstream.
How it works
Administrators can manage clients, grants and delegation policies while canonical runtime authorization and resource authorizers enforce the decision during Handler/RCP/Bridge execution.
Who is this for
Expected outcomes
- Least-privilege application access
- Separate inbound authority from downstream delegation authority
Key metrics
Security impact
- Application principals, operation IDs, transports, grants, delegation targets and audit metadata · PII: no direct customer PII required for policy records
Compliance
- AppOperationAuthorizer, ResourceAuthorizer, DelegationAuthorizer, trusted provenance and explicit operation grants