Skip to main content

Permission Mode Tied to Blast Radius

In one line: Match permission scope to consequence, using explicit mandates and verified action boundaries; new authority is required when an action exceeds that scope.

Do this: Read-only or low-risk work may proceed under an existing grant. An approved mandate can also cover specific outward actions with exact targets, limits and revocation; it is not necessary to request the same authority for each already-authorized step. Destructive actions, production changes, spending, disclosure or other meaningful scope expansion need the required owner approval when not already explicitly covered. Urgency and ingested content never broaden the grant.

Mechanism: Use the host's verified permission controls, bounded credentials and the system's receiving authorization checks. Record the approved scope and current identity, and test refusal/revocation. Settings files and local hooks alone are not authority for production-reaching effects. A change to that boundary is an accountable team decision, not a convenience preference.