SCOPE 2.0 replaces the unsafe total-order approval hierarchy with
AuthorizationEnvelope capability partial orders. Cross-family scopes are
incomparable. Grant issuance requires a VerifiedDecision from the mandatory
verification service.
- Authorization model:
scope_rank/ total hierarchy comparisons are deprecated for authorization. Useenvelope_contains,envelope_intersection,envelope_is_narrower, andenvelope_difference. - Grant issuance:
GrantEngine.issueaccepts onlyVerifiedDecision. Plain dicts withdecision_signatureare never grant-eligible. - Identifiers: New artifacts use full UUID4 hex IDs (not 6-character fragments). Short IDs remain readable as legacy aliases only.
- Trust root:
scope_trust_root_hashis the digest of the complete authorization trust manifest, not only policy + key registry. - Identity: Missing role claim/group mapping fails closed (no default
domain_scientist). - REST: Spoofable
X-Scope-Tenant-Id/X-Scope-Policy-Dir/X-Scope-Ledger-Path/X-Scope-Caller-Idheaders are not authoritative. Public request fields no longer accept arbitrary server filesystem paths. - Ledger: Prefer SQLite transactional ledger (
SCOPE_LEDGER_BACKEND=sqliteor*.sqlitepath). Local append files areLocalAppendSink, not WORM. - Version: Package version is
2.0.0.
- Legacy scope names still appear on grants as
approved_scopeand map into envelopes viaenvelope_from_legacy_scope. - Development mode may accept unsigned decisions as explicit
VerifiedDecisionwith SAL0; production requires cryptographic verification.
| Layer | Status |
|---|---|
| Artifact schemas (packet/decision/grant) | Stable contract with 2.0 extensions |
| Core library implementation | Beta — expanding toward institutional DoD |
| Production deployment profile | Not claimed ready until Section 14 DoD passes |
Do not market WORM, verified remote ledger, multi-tenant isolation, KMS/SAL4, or institutional authorization as complete until acceptance tests pass.