Commission a source connection, never merely a key.
source + principal + authority + grant + credential custody + connector + evidence
For operational systems the same unit becomes system + identity + authority + entitlement + custody + enforcement path + evidence. Desired and actual state remain separate. “Should have” never silently becomes “has,” and “vendor says granted” never silently becomes “verified working.”
Scope
The first proving perimeter is the existing eleven rooms: BigQuery, CJ, impact.com, Omnisend, Ahrefs, RichAds, Mysterium business API, GoProxies, Grafana/VictoriaMetrics, ClickUp and the Slack public-channel export. The eventual estate includes every MN system that holds consequential information or grants consequential access.
Non-goals
- No universal master password and no store of raw credential values.
- No forced warehouse or uncontrolled copy of every source.
- No automatic truth engine: readable data can still be incomplete, incomparable or wrong.
- No AI with unbounded administrator rights.
- No green access state without a live acceptance fixture.
- No bypass of vendor controls, contracts, consent, privacy or organizational authority.
The information contract is part of the room.
The governed perimeter
Purpose, class, grant holders, sensitivity, control mechanism, fixture, revocation path and enforcement capability.
The usable meaning
Definitions, grain, identifiers, history, freshness, lineage, permitted uses, supported decisions and known conflicts—versioned with the room.
The same authorized read path exposes both. A steward approves legend changes but is never the runtime source of meaning. Removing that person from the workflow must not prevent an authorized human or AI from interpreting the current accepted contract.
Other core objects
| Object | Purpose | Critical boundary |
|---|---|---|
| Identity | Human, contractor, service, agent or emergency identity with sponsor and lifecycle. | A service credential never hides inside a human account. |
| Cross-source relationship | Versioned identifiers, time/grain boundary, transformation and permitted join. | Candidate relationships never silently become accepted joins. |
| Role pack | Versioned desired-access template with exact inclusions, exclusions and expiry. | A novel exception is not standard onboarding. |
| Entitlement | Smallest capability: scope, method, object, history, environment, expiry. | Read, write, delete, spend and user-management remain separate. |
| Authority rule | The human decision rule that allows an entitlement to exist. | AI may execute authority; it may not manufacture it. |
| Evidence | Timestamped proof of desired state, actual state, acceptance, denial and drift. | No secrets or raw customer data in the control-plane record. |
State model
NOT_AUTHORIZED → REQUESTED → GRANTED → AUTHENTICATED → USEFUL_READ → COMMISSIONED → DURABLE
Independent qualifiers remain visible: OVERPRIVILEGED, PERSON_BOUND, EXPIRING, STALE, UNVERIFIED, SCOPE_PARTIAL, MAPPING_PARTIAL, MUTATION_POWER_PRESENT, REVOCATION_UNPROVED and OFFBOARDING_SLA_UNSUPPORTED.
One graph; separated powers.
The control plane stores contracts, desired and actual state, policy and evidence. It does not store the estate. Connectors are capability-specific and visible; an export, a vendor admin action, an SSO grant and a read-only API are never presented as equivalent.
Fifteen-minute standard onboarding.
T0: an authorized sponsor selects a pre-approved role pack for a verified identity. T1: every required room reaches its pack-specific accepted state and its live fixture passes. Objective: T1 − T0 ≤ 15 minutes.
A role pack that still requires ad hoc approval or vendor-menu archaeology is not eligible for the standard-onboarding objective.
Thirty-second controlled-path offboarding.
T0: the signed suspension or offboarding event is accepted by the policy engine. T1: the identity is denied at every MN-controlled enforcement point. Production objective: T1 − T0 ≤ 30 seconds at a percentile and geographic boundary still to be certified.
A signed identity-kill event propagates deny-first. Controlled enforcement points invalidate the identity immediately. Downstream workers then revoke vendor sessions, remove memberships, transfer ownership, rotate affected shared credentials and collect denial evidence. Cleanup failure never restores access.
OFFBOARDING_SLA_UNSUPPORTED until the path is controlled or removed.The 30-millisecond limit test
Stretch benchmark: ≤ 30 ms for locally controlled enforcement points where cached edge denial makes the experiment meaningful. It is an engineering provocation, not a customer promise and not a production-readiness gate.
Five views of one entitlement graph.
| View | Question answered |
|---|---|
| Person | What should this identity have, what does it actually have, and what happens next? |
| Room | Who and what can enter this room, including stale accounts, contractors and inherited roles? |
| Information | What does the room contain, what does it mean, what can it support, and where does it conflict? |
| Role pack | What is the full capability bundle, its exclusions, authority version and automation coverage? |
| Event | What changed during join, move, promote, demote, suspend or leave—and what evidence remains? |
The control plane must know the whole graph. Its interface must not reveal the whole graph to everyone. Personal, manager, room-steward, Key Holder and sealed visibility classes remain separate.
Prove the model before automating power.
Bind all eleven rooms to one registry, attach their legends, render desired versus actual state and refuse false green.
Implement three packs, automate highest-control connectors and prove one standard identity within 15 minutes.
Choose the identity root and enforcement perimeter, propagate signed denial and prove controlled access ends within 30 seconds.
Expand to code, cloud, finance, communications, support and HR only through versioned contracts and fixtures.
The system is not ready until it proves these.
- Registry and evidence bundle contain the same complete room set.
- Every room exposes a versioned legend with definitions, grain, identifiers, measured history, freshness, uses, supported decisions and relationship state.
- Removing the steward from runtime does not prevent an authorized reader from interpreting the current accepted meaning.
- A known contradiction remains visible with both provenances; the system cannot silently merge it.
- A role-pack change names every affected entitlement before execution.
- Standard onboarding reaches verified readiness within fifteen minutes.
- Offboarding denies the identity within 30 seconds at the certified perimeter.
- Vendor cleanup failure does not restore access.
- A direct personal token is flagged outside the 30-second guarantee.
- No identity approves its own exception.
- One Key Holder cannot perform a Tier 2 action alone.
- AI cannot widen a role pack while executing it.
- A stale or empty fixture cannot produce green.
- Sensitive membership remains hidden from unauthorized dashboard users.
- Every grant and revoke has a durable authority and execution receipt.
Implementation choices still requiring evidence.
- Named Key Holders and backups.
- Sensitive and sealed-room taxonomy.
- Authoritative identity provider and enforcement technology.
- Certified percentile and geographic boundary for the 30-second objective.
- Exact perimeter for the 30-ms stretch benchmark.
- Systems that can be mediated without a new single point of failure.
- Exact first role-pack entitlements and cross-source contracts.
A small contract for agents.
The document’s claims, status and links are repeated below as a machine-readable record. The prose remains authoritative where this short record omits detail.
{
"surface": "key-maker-technical-architecture",
"status": "proposed-future-state",
"version": "0.1",
"as_of": "2026-08-27",
"initial_perimeter_rooms": 11,
"onboarding_objective_minutes": 15,
"offboarding_objective_seconds": 30,
"offboarding_stretch_benchmark_ms": 30,
"stretch_is_customer_promise": false,
"press_release": "/key-maker/",
"mammoth_gate": "no-signed-opportunity-schedule-no-material-pursuit"
}