Engine · Job routing
Policy management
Check who may request work, which profile it may use, and why permission is granted or refused.
Workflow
- Register a fixed profileRegister a fictional profile whose source, destination, database, queue, cache and credential folders are fixed. Reject symlinks, layout changes and ownership mismatches. The root is captured so later object changes cannot retarget a grant.
- Request an operationThe caller supplies a typed request for one registered app and owner. A permission decision is not a job and does not itself perform the requested work.
- Issue a scoped grantIssue a unique, revocable grant for the request scope. Grant identity, profile, operation family and policy revision are checked again when the grant is used.
- Check request and grantAuthorization revalidates the envelope, rejects stale or revoked grants, and compares the request against the grant scope. A change in policy revision needs a matching grant. This scope check does not bind the exact operation or selected items, impose an expiry time, or revalidate profile directories.
- REFUSED · no work admittedA named refusal explains the rejected request. Invalid profile registration or grant issue also stops before authorization; do not fall through to a job or broaden the scope.
- AUTHORIZED · fixed scopeReturn AuthorizedOperation with the validated request, grant identity and revision, and the captured profile root. It is evidence of admission, not proof a job ran or succeeded.
- Revoke future useRevocation stops later use of that grant. It does not automatically cancel work already in flight; cancellation belongs to the job workflow.
Failure boundaries
- Revoked grantAuthorization refused: No work admitted
- Wrong owner or operationScope check refuses: No broadened access
- Invalid layout at registrationRegistration refuses: No profile registered
- Actual-data profile requestedProvisioning refused here: No production access granted
engine.job.policy