Skip to harness content
Open technical reference map

Production domain 04

Identity, Authorization & Tenant Isolation

3 capabilities and 3 controls define the canonical obligation set for this domain.

Domain 04Dependencies: Security & Data Protection
Canonical pathcontrols/production-layers.v2.jsonRevision69bab1cInspect source

Applicability and claim boundary

This domain defines obligations. It does not prove that a specific repository or run satisfies them.

Applicability
Assess this domain when the authorized workload can affect its capabilities. Resolve every control as required, potentially affected, or not applicable before completion.
Proof level
The accepted formats below identify possible evidence inputs. A format alone does not establish semantic or authoritative assurance; provenance and the commissioned proof contract set the supported level.
Claim boundary
Static controls are requirements, not execution evidence, provider attestation, or proof of production readiness.

Capabilities

authorization-enforcement

Authorization Enforcement

Enforce authorization at every protected server-side boundary.

tenant-isolation

Tenant Isolation

Prevent cross-tenant reads, writes, and side-channel disclosure.

identity-lifecycle

Identity Lifecycle

Govern sessions, credentials, identities, and deprovisioning end to end.

Controls

AUTH-AUTHZ-001Authorization Enforcement

Every protected operation enforces server-side authorization.

Accepted evidence format: Command output
AUTH-TENANT-001Tenant Isolation

Cross-tenant read and write attempts fail at every relevant boundary.

Accepted evidence format: Command output
AUTH-LIFECYCLE-001Identity Lifecycle

Sessions, identities, keys, and deprovisioning have tested lifecycles.

Accepted evidence format: Command output