Distributed Job Scheduler  ·  View 19 of 20  ·  Assurance

Identity and Privilege Flow

Who proves what, to whom, in what order — including the call that is deliberately refused.

Editable source SVG draw.io All views
Tenant engineer Identity provider Management API Authorisation Workload identity Attempt runner Tenant target 1. authenticate 2. OIDC token 3. create trigger 4. role: author? 5. granted 6. verify target ownership 7. extend horizon to 24 h 8. role: policy? 9. denied: separate grant 10. mint for this attempt 11. token, attempt lifetime 12. sign fire record 13. dispatch + signature 14. verify issuer 15. valid, scoped to trigger 16. 202 accepted Identity — Who Proves What, in What Order Authorship and policy change are separate grants. The dispatch credential is minted per attempt and expires with it, so a captured dispatch buys one trigger for one timeout. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • The horizon extension is drawn being denied, because the privilege split is only real if an author who can create a trigger cannot widen its blast radius (ADR-15).
  • The dispatch token is minted by the attempt runner per attempt, so the credential's lifetime and the attempt's lifetime are the same object.
  • The target verifies the issuer rather than a shared secret, so rotating platform keys is not a tenant migration.

Assumptions

  • Tenants can verify an OIDC issuer. Targets that cannot fall back to the signed-payload path, which is weaker and is recorded as such.

Risks

  • A tenant that grants the policy role to everyone who has the author role recreates the problem the split exists to prevent. The audit trail detects it; nothing prevents it.