01 / Source and scope
Who acts, and what changes?
Agent or workload requesting a protected resource. Organization policy administrator and task issuer.
Invoke an API that changes resource state.
02 / Action-time control
Make the requested effect testable.
SP 800-207 is architectural guidance; network location and valid identity alone do not authorize a specific effect. Locate policy decision and enforcement near the resource; re-evaluate subject, action and context.
03 / Evidence and responsibility
Permission, execution, and outcome are separate.
Policy version, decision, enforcement event and resource result.
ProofGrid can help express and record authority decisions; the organization owns its zero-trust architecture and enforcement coverage.
Primary source