Skip to content

Authorization, budgets, and side effects

12. Authorization, budgets, and side effects

Section titled “12. Authorization, budgets, and side effects”
MWP-AUT-001MUST

After WorkItem acceptance and all required approvals, the Authorization Service issues a short-lived least-privilege capability token. The token MUST be bound to:

  • the Worker Agent ID and current Session Epoch;
  • WorkItem ID and Ownership Epoch;
  • the current Execution Lease ID;
  • allowed tools, resources, data, and operations;
  • financial, token, call, compute, time, and side-effect limits; and
  • an expiration no later than the applicable Execution Lease.
MWP-AUT-002MAYMUST NOTMUST

The Coordinator MAY request authorization but MUST NOT manufacture, copy, or forward a Worker’s credential. Tokens and secrets MUST NOT appear in Messages, Agent Cards, Context Packages, Artifacts, or Group Events. Expired, revoked, mismatched, or over-budget tokens MUST be rejected.

MWP-AUT-003MUSTMAY

Organization policy MUST be able to place a WorkItem into awaiting_execution_approval before production deployment, payments, external communications, destructive changes, or sensitive-data access. The Authorization Service MUST withhold the capability token until the signed approval gate is satisfied. Low-risk work MAY proceed automatically under policy.

MWP-AUT-004MUST NOT

Mission and WorkItem budgets are mandatory protocol concepts. The MissionOwner sets Mission limits, the Coordinator allocates no more than those limits to WorkItems and child Missions, and the Authorization Service enforces hard limits. Budget exhaustion pauses affected work and requires explicit escalation; Agents MUST NOT silently exceed a limit.

MWP-AUT-005MUST

The Group Authority MUST persist an aggregate six-dimensional budget ledger. A signed ext.missionweaveprotocol.core.resource_usage_record Command records a nonzero delta against one WorkItem, Ownership Epoch, and Execution Lease ID; the corresponding ext.missionweaveprotocol.core.resource_usage_recorded Event carries the delta, cumulative usage, and remaining budget. Consumption MUST update the WorkItem and its complete WorkItem/Mission ancestry in one atomic transition. A one-dimension overflow MUST reject the whole transition as BUDGET_EXCEEDED. Capability-token budgets MUST be capped by both the Work Contract and the authoritative remaining budget.

MWP-AUT-006MUST

Cancellation or emergency termination MUST revoke relevant leases and capability tokens, stop new assignments, and initiate contract-defined cleanup or compensation WorkItems where needed.