01 / Source and scope
Who acts, and what changes?
Principal and authority origin
Payment agent or supporting service identity. Merchant or service-provider control owner.
Consequential action
Access cardholder data or alter a payment operation.
02 / Action-time control
Make the requested effect testable.
PCI DSS applies according to system scope; agent usage does not create an exemption. Constrain service access, authenticate actors, approve high-impact changes and monitor access within the CDE.
OriginMerchant or service-provider control owner
RequestAccess cardholder data or alter a payment operation
DecisionEvaluate and enforce before effect
03 / Evidence and responsibility
Permission, execution, and outcome are separate.
Scope inventory, access log, change approval and control test.
ProofGrid can add action decisions and audit context; a qualified assessment and all PCI controls remain customer obligations.
Primary source