WEIHR policy · authorization

Knowing who acts is only the beginning of deciding what may happen.

WEIHR policy evaluates a verified principal against a specific action and resource. Roles collect reusable responsibilities; policies narrow them with purpose, scope, context, and explicit denials.

Principal

Who is asking?

An active WEIHR identity resolved by WARDEN, optionally with fresh physical evidence when the policy requires it.

Action + resource

What is being attempted?

A concrete operation such as read, submit, mint, administer, or recover against one named resource.

Context

Under which constraints?

Role, policy references, record status, ownership, freshness, environment, and explicit safety boundaries.

Decision order

Resolve

Reject missing, inactive, conflicting, or malformed principal records.

Verify if required

Demand fresh physical evidence only for actions whose policy genuinely needs it.

Evaluate

Match principal roles and ownership to the requested action and exact resource.

Record

Return allow or deny with a reason and preserve significant decisions for audit.

Default deny. A valid password, ONS handle, wallet, identity, role, or resonance reading is not a universal capability. Each contributes one fact to a resource-specific decision.

Beta-account expectation

A beta role may permit selected application features after normal identity resolution and login. It must not silently grant registry administration, issuer authority, physical-miner status, or access to every WEIHR resource.