FAMILY HOMEEXPLORE AFAEXPLORE AVPEXPLORE EABARUN AUTHORITY JOURNEYINSPECT FROZEN CHALLENGE
ADMISSIBLE FEDERATION ARCHITECTURE
REGISTRY · TA-14-AIGR-000042STATUS · REGISTERED RC1 / NOT YET FROZENSTEWARD · TA-14 AUTHORITY · GREGGORY DON BUTLERAUTHORITY OBJECT · AVP V1.0.2FOUNDING PROFILE · AFA-IP-001

AUTHORITY CONTEXT
MAY CROSS.
EXECUTION AUTHORITY
MUST BE ESTABLISHED LOCALLY.

AFA governs the seam between independently governed domains. It permits bounded authority context to travel while preserving a hard architectural barrier before local consequence.

OPEN CANONICAL RC1 · DOI 10.5281/zenodo.22846133 ↗OPEN PERMANENT REGISTRY RECORD →FEDERATION & AUTHORITY →
THE CONNECTION SANDBOX

LINKED ✓ → CONNECTED ✓ → EXECUTE ?

Same building object. Governed connection. One proposed consequence. The Connection Profile gets the request to the boundary. From there, the public question is simply TA-14.

LINKEDBUILDING OBJECT ✓
CONNECTION PROFILECONNECTED ✓
TA-14READY
CONSEQUENCE?
PROPOSED ACTIONChange building setpoint to 72°F.
LINKING IS NOT CONNECTING. CONNECTING IS NOT AUTHORITY TO EXECUTE.
CONTINUE THE STORY ↓
YOU JUST RAN THE SANDBOX

What do you want to understand next?

You already know the main idea. A connection can be completely legitimate and the proposed action can still be stopped. Pick how deep you want to go.

UNDERSTAND · 60 SECONDSWhy does TA-14 come after the connection?See the simple handoff: Connection Profile → TA-14 → Consequence.TEST IT · 2 MINUTESWhat if something changes?Break a condition and watch why a prior answer cannot simply keep running.GO DEEPER · TECHNICALShow me the machinery.Inspect federation, receiving decisions, Passport behavior, failure modes, composition, and evidence.

PLAY FIRST. UNDERSTAND SECOND. INSPECT THE ARCHITECTURE THIRD.

AFA · GUIDED SHOWROOM

Understand federation before you move the Passport.

AFA is about crossing between independently governed domains without pretending that context, trust, identity, or acceptance automatically becomes local permission to act.

INTERACTIVE FEDERATION SEAM

Move the Passport. Watch where authority stops.

ORIGIN

Domain A possesses bounded authority context. Nothing here grants Domain B permission to act.

STOP CONDITION · NO LOCAL LEASE · NO LOCAL CAPSULE · NO COMMIT · NO EXECUTION · NO EFFECT
DECISION CONSOLE

The receiver keeps the right to refuse.

ACCEPT_NARROWED

Receiver accepts only a provably narrower authority context.

EXECUTION AUTHORITY: NOT ESTABLISHED BY FEDERATION
LIVE RECEIVING-DOMAIN LAB

Change the authority context. Watch the receiving decision change.

Start with a valid crossing. Break one condition at a time. AFA does not silently repair the Passport, inherit permission, or convert successful transport into execution authority.

RECEIVING DETERMINATIONACCEPT_NARROWED

The bounded authority context may enter local assessment. Execution authority is still not established.

EXECUTION AUTHORITY · NOT ESTABLISHED BY FEDERATION
NEGATIVE SPACE REVEAL

These objects cannot ride the Passport.

Successful transport, identity, trust, compatibility, receipt or acceptance never imply the receiving domain's protected consequence authority.

FAILURE LAB

Attack the seam, not just the happy path.

GOVERNED RESULT
SUSPEND

Cryptographic validity does not establish present-tense freshness.

COMPOSITION LAB · A → B → C

Federation does not compound authority.

DOMAIN A
A→B BOUNDARY
DOMAIN B
B→C BOUNDARY
DOMAIN C

If B accepts narrowed authority from A, B may re-present only a provably preserved or narrower descendant to C. C must make its own ReceivingDetermination. B's receipt is not proof that B possessed execution authority, and neither acceptance grants C permission to act.

LOOK UNDER THE HOOD

Four ways to see what TA-14 is actually doing.

You do not need to know the acronyms to understand the architecture. Think of TA-14 like a careful gatekeeper: it needs rules, a specific handoff, tests for what can go wrong, and an honest record of what has actually been proven.

01 · THE RULEBOOKWhat are the rules?Read the registered release candidate — the written rules for what may cross between independently governed domains and what must stop before local execution.READ THE RULEBOOK ↗02 · THE HANDOFFWhat gets passed over?See the Connection Profile exercise. It asks what information may cross the connection without pretending that the connection itself gives permission to act.INSPECT THE HANDOFF ↓03 · TRY TO BREAK ITWhat happens when something goes wrong?Run the failure tests. Make the context stale, broaden the scope, change a condition, or tamper with the record and watch the architecture refuse to quietly continue.RUN THE FAILURE LAB ↓04 · WHAT IS PROVEN?Is this real or just a diagram?See exactly what this showroom demonstrates today, what is implemented, and what still needs external runtime and CI evidence. No pretending.CHECK THE STATUS ↓
RUNTIME STATUS · THE HONEST SCOREBOARD

What can we honestly say works today?

This showroom demonstrates the boundary logic, receiving decisions, changed-condition behavior, failure cases, and receipts. A harness has been implemented. It does not claim completed external CNS/CP registry publication, proven live interoperability with an outside system, TA14_RECOGNIZED implementation, transfer of execution authority, or completed Node/CI runtime evidence.

SHOWROOM LOGICDEMONSTRABLE ✓
FAILURE CASESINTERACTIVE ✓
BOUNDARY RECEIPTSDEMONSTRABLE ✓
EXTERNAL RUNTIME / CIEVIDENCE PENDING

WHY THIS MATTERS: A governance architecture should not claim more evidence than it has. The status card is part of the architecture, not fine print.

THE HANDOFF

The connection got the request here.
Now what?

The Connection Profile tells us the connection is legitimate and what may cross it. TA-14 does not redo that work. TA-14 asks the next question: may this exact consequence become reality now?

CONNECTION PROFILEThe governed relationship and crossing rules are established.
TA-14The proposed consequence is tested against what is true now.
CONSEQUENCEALLOW · HOLD · DENY · ESCALATE

The Connection Profile governs the relationship. TA-14 governs the consequence.

ONE REQUEST · THREE QUESTIONS
1CONNECTION PROFILEAre these parties connected, and what are they allowed to send across?
2TA-14Does this exact proposed consequence have enough evidence, authority, and standing right now?
3CONSEQUENCEALLOW · HOLD · DENY · ESCALATE

A good connection can still lead to HOLD. That does not mean the connection failed. It means TA-14 found that something required for this consequence is not established now.

MONDAY LIVE

“You told me the Connection Profile was the seam. I built the seam.”

Then we separated the seam from the architecture, made AFA protocol-neutral, and defined exactly why authority context can cross while execution authority must still be established locally. AFA-IP-001 v0.3 is now the bounded examination object for that proposition.