docs(idm): complete delegation lifecycle guidance
This commit is contained in:
@@ -475,7 +475,10 @@ manifest = ModuleManifest(
|
||||
"function and unit are owned by Organizations. Source distinguishes "
|
||||
"direct, delegated, acting-for, directory, governance, and system facts. "
|
||||
"Delegation and acting-for require a valid source assignment and the "
|
||||
"corresponding function permission. Subunit scope broadens the fact's "
|
||||
"corresponding Organizations function permission. A delegate acts as themself; "
|
||||
"acting-for additionally requires Access to select the exact representation "
|
||||
"context before it contributes authority. Source and derived assignments must "
|
||||
"remain current, active, tenant-local, and function-compatible. Subunit scope broadens the fact's "
|
||||
"organizational reach. Deactivation and expiry preserve provenance while "
|
||||
"removing the assignment from effective resolution. Governed request and "
|
||||
"grant decisions retain actor, policy, workflow revision, comments, and "
|
||||
|
||||
Reference in New Issue
Block a user