REFERENCE SCENARIO · IMPLEMENTATION-GRADERS-10 — Mandate / delegation lifecycle and scoped authority
This scenario connects a user action to state, authority, policy, evidence and integration boundaries. It is a reference model; legal or regulatory decisions remain with the authoritative party for each data domain.
Actors / systemsPrincipal organisation/person; delegate/representative; Admin or Owner experience; identity/policy/mandate services.PreconditionsPrincipal has authority to delegate the intended scope and both identities can be verified to required assurance.TriggerPrincipal creates, changes, suspends or revokes a mandate/delegation.
End-to-end flowAuthenticate principal → validate delegable scope → identify delegate → define purpose/resources/actions/time limits → approve/accept where required → issue mandate → evaluate it at privileged actions → suspend/revoke/expire → preserve evidence and version history.State modelDraft → Active → Suspended/Expired/Revoked. Mandate state is separate from the underlying object lifecycle and relationship claims.Authority boundaryThe principal remains source of delegated authority within the permitted domain; Trusted ThingID evaluates and evidences the mandate but does not invent authority.
Policy / disclosureDelegability, least privilege, purpose, resource/action scope, time bounds, assurance, separation of duties and revocation.EvidenceMandate creation/acceptance, scope snapshot, identity references, policy version, suspension/revocation/expiry and audit.API / event / connectorMandate API; claims/identity reads; policy decision service; evidence API; mandate lifecycle events.
Failure / retry / reconciliation
Over-broad scope → reject; expired mandate → deny; revoked mandate replay → reject using current status; unavailable authority source → fail closed for privileged write unless explicit policy says otherwise.
Architecture
P02 · P03 · P06
Actor → Experience → Action → Business Object → Authority → Policy → State → Evidence → API/Connector → Architecture → Standard.
Standards / profiles
Identity/credential and authorisation profiles applicable to deployment; evidence/audit requirements.
REFERENCE ARCHITECTURE
Product UI statusUI/UX BASELINE — *_final.png is embedded only when the approved source binary and provenance are available; no screenshot is fabricated to fill a missing source.