Engine · Job routing

Policy management

Check who may request work, which profile it may use, and why permission is granted or refused.

Workflow

  1. Register a fixed profileRegister a fictional profile whose source, destination, database, queue, cache and credential folders are fixed. Reject symlinks, layout changes and ownership mismatches. The root is captured so later object changes cannot retarget a grant.
  2. Request an operationThe caller supplies a typed request for one registered app and owner. A permission decision is not a job and does not itself perform the requested work.
  3. Issue a scoped grantIssue a unique, revocable grant for the request scope. Grant identity, profile, operation family and policy revision are checked again when the grant is used.
  4. Check request and grantAuthorization revalidates the envelope, rejects stale or revoked grants, and compares the request against the grant scope. A change in policy revision needs a matching grant. This scope check does not bind the exact operation or selected items, impose an expiry time, or revalidate profile directories.
  5. REFUSED · no work admittedA named refusal explains the rejected request. Invalid profile registration or grant issue also stops before authorization; do not fall through to a job or broaden the scope.
  6. AUTHORIZED · fixed scopeReturn AuthorizedOperation with the validated request, grant identity and revision, and the captured profile root. It is evidence of admission, not proof a job ran or succeeded.
  7. Revoke future useRevocation stops later use of that grant. It does not automatically cancel work already in flight; cancellation belongs to the job workflow.

Failure boundaries

  • Revoked grantAuthorization refused: No work admitted
  • Wrong owner or operationScope check refuses: No broadened access
  • Invalid layout at registrationRegistration refuses: No profile registered
  • Actual-data profile requestedProvisioning refused here: No production access granted

engine.job.policy