| Agent / principal | The actor proposing an action. Has an id and a type (agent, service, human, system) |
| Effect | A typed, canonical description of a proposed side effect: who, what, on which resource, with which parameters, at what risk |
| Canonicalize | Validate an effect, freeze a copy, and compute its digest. Nothing is inferred |
| Digest | sha256 over the material fields of an effect. Approvals bind to it |
| Policy | Deterministic rules deciding which effects can ever happen. Deny beats approval beats allow |
| Authority | Evidence that a principal currently holds permission, with an expiry and a grantor |
| Approval | Independent human sign-off for one exact effect |
| Provider | A pluggable component that answers a question: policy, authority, approval, identity, context, risk |
| Risk | LOW, MEDIUM, HIGH or CRITICAL. Providers can raise it, never lower it |
| Final gate | The last checks right before the action: authority re-check, expiry, single-use |
| Receipt | A record of a decision and what happened. Hashed for tamper-evidence, not signed |
| Fail closed | When governance cannot be established, the action does not happen |
| TOCTOU | Time-of-check to time-of-use: the gap between checking permission and acting. The final gate narrows it |