Nothing decides who enforces a numeric limit, or what happens when a connected application loses access #172

Open
opened 2026-10-06 18:11:48 +00:00 by cgalo5758 · 1 comment
Owner

What a person cannot do today

Rely on a limit or on a revocation once an application runs outside the console. A numeric limit is delivered as a number, and nothing says whether the console or the application counts usage against it. Nothing defines what an application does when its connection to the console fails or a person's access ends, or what becomes of what a member made with it.

What they should be able to do

  • Each numeric key declares where it is enforced. A key the console enforces uses acquire, commit and release with leases that expire (five minutes, provisional), and declares what happens when the console cannot be reached, deny by default. A key the application enforces receives its limit by push, and the application reports absolute usage, shown with the time it was reported. A key delivered through more than one connection is enforced by the console.
  • Seven rules govern ending access: authentication fails closed and recovers on the first verified answer; the absence of a record never revokes; removal is explicit and retried until acknowledged; revocation is not deletion; an outage delays revocation visibly, with privileged mappings expiring by default; reconciliation touches only the targets the console manages; and disconnecting an application asks first.
  • What an application keeps and lets a member export is declared, and the plan pages show it before a member buys and before they downgrade. Erasure is a forget request.
  • Two questions are settled here: how a connector learns that a target is no longer managed, so it leaves the group alone, and whether a rule's reduction policy becomes part of the delivered record.

Why it matters

Without these rules, a limit can be exceeded or a revocation lost as soon as an application is out of process, and a member cannot see before paying what happens to their work when a plan ends.

Where

internal/entitlements (usage and leases), the specification from #171, the member plan pages.

Done when

Every numeric key declares its enforcement point and both kinds work end to end; the ending rules are in the specification and the conformance harness checks them; the plan pages show retention and export before purchase and downgrade; a forget request erases what an application holds about a person.

Order

Comes after #171. Related: #165 (the usage counter becomes an absolute count), #164 (what "unlimited" means), #163.

## What a person cannot do today Rely on a limit or on a revocation once an application runs outside the console. A numeric limit is delivered as a number, and nothing says whether the console or the application counts usage against it. Nothing defines what an application does when its connection to the console fails or a person's access ends, or what becomes of what a member made with it. ## What they should be able to do - Each numeric key declares where it is enforced. A key the console enforces uses acquire, commit and release with leases that expire (five minutes, provisional), and declares what happens when the console cannot be reached, deny by default. A key the application enforces receives its limit by push, and the application reports absolute usage, shown with the time it was reported. A key delivered through more than one connection is enforced by the console. - Seven rules govern ending access: authentication fails closed and recovers on the first verified answer; the absence of a record never revokes; removal is explicit and retried until acknowledged; revocation is not deletion; an outage delays revocation visibly, with privileged mappings expiring by default; reconciliation touches only the targets the console manages; and disconnecting an application asks first. - What an application keeps and lets a member export is declared, and the plan pages show it before a member buys and before they downgrade. Erasure is a forget request. - Two questions are settled here: how a connector learns that a target is no longer managed, so it leaves the group alone, and whether a rule's reduction policy becomes part of the delivered record. ## Why it matters Without these rules, a limit can be exceeded or a revocation lost as soon as an application is out of process, and a member cannot see before paying what happens to their work when a plan ends. ## Where `internal/entitlements` (usage and leases), the specification from #171, the member plan pages. ## Done when Every numeric key declares its enforcement point and both kinds work end to end; the ending rules are in the specification and the conformance harness checks them; the plan pages show retention and export before purchase and downgrade; a forget request erases what an application holds about a person. ## Order Comes after #171. Related: #165 (the usage counter becomes an absolute count), #164 (what "unlimited" means), #163.
cgalo5758 added this to the Public launch milestone 2026-10-06 18:11:48 +00:00
Author
Owner

Order: followed by #173, then #174.

Order: followed by #173, then #174.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: wiki-cafe/member-console#172