docs(idm): complete delegation lifecycle guidance

This commit is contained in:
2026-08-19 22:16:18 +02:00
parent 2c6ee041b9
commit dc99a40384
3 changed files with 73 additions and 1 deletions
+4 -1
View File
@@ -475,7 +475,10 @@ manifest = ModuleManifest(
"function and unit are owned by Organizations. Source distinguishes "
"direct, delegated, acting-for, directory, governance, and system facts. "
"Delegation and acting-for require a valid source assignment and the "
"corresponding function permission. Subunit scope broadens the fact's "
"corresponding Organizations function permission. A delegate acts as themself; "
"acting-for additionally requires Access to select the exact representation "
"context before it contributes authority. Source and derived assignments must "
"remain current, active, tenant-local, and function-compatible. Subunit scope broadens the fact's "
"organizational reach. Deactivation and expiry preserve provenance while "
"removing the assignment from effective resolution. Governed request and "
"grant decisions retain actor, policy, workflow revision, comments, and "