Who is asking?
An active WEIHR identity resolved by WARDEN, optionally with fresh physical evidence when the policy requires it.
WEIHR policy evaluates a verified principal against a specific action and resource. Roles collect reusable responsibilities; policies narrow them with purpose, scope, context, and explicit denials.
An active WEIHR identity resolved by WARDEN, optionally with fresh physical evidence when the policy requires it.
A concrete operation such as read, submit, mint, administer, or recover against one named resource.
Role, policy references, record status, ownership, freshness, environment, and explicit safety boundaries.
Reject missing, inactive, conflicting, or malformed principal records.
Demand fresh physical evidence only for actions whose policy genuinely needs it.
Match principal roles and ownership to the requested action and exact resource.
Return allow or deny with a reason and preserve significant decisions for audit.
A beta role may permit selected application features after normal identity resolution and login. It must not silently grant registry administration, issuer authority, physical-miner status, or access to every WEIHR resource.