From authority to execution.

A principal grants authority over one action, and that authority travels with the action to the place where it runs. Humsana checks the action at that point. Where the action is still the one that was authorized, it proceeds. Where any part of it has moved, the check refuses it and names the part that moved.

The mechanism in five steps.

StepWhat happens
01 ClaimThe agent says who it is, who it acts for, what it wants to do, and what authority it holds.
02 EstablishHumsana separates what is established from what is claimed and from what stays unknown.
03 ConfirmThe consequence decides whether a person has to approve. Where one does, the approval is signed over the exact action.
04 BindThe approval is tied to the action, its bound values and its expiry. It can be spent once.
05 EnforceThe executor presents the action immediately before it runs. A material change is refused and the changed field is named.

What a refusal says.

CodeWhat failed
EFFECTUATION_DRIFTThe presented action differs from the authorized one in a material field.
GRANT_DOES_NOT_COVER_THIS_ACTIONThe presented action is outside this authorization.
MAY_NOT_CHANGEFixed by the authorization and not alterable at execution.
MAY_NOT_INCREASEMay be reduced, not raised above the authorized value.
MAY_ONLY_SHRINKThe scope may narrow, not widen.
GRANT_ALREADY_USEDThe grant is spent. A grant is spent once.
GRANT_NOT_FOUNDNo grant exists for the identifier presented.
AUTHORIZATION_NOT_GRANTEDThere is no authorization to spend. A record that was refused or asked for verification was never spendable and cannot expire.
CONFIRMATION_NOT_OBTAINEDA human step was required and no bound approval was presented.
RECEIPT_EXPIREDPast the expiry, so it applies only where an authorization existed.
RECEIPT_NOT_FOUNDUnknown identifier, or one belonging to another caller.
OUTSIDE_SCOPEOutside the scope registered for this agent.
PROVIDER_DEADLINE_EXCEEDEDA provider did not answer inside the deadline. The boundary waits twenty seconds and records the expiry, not consent.

Thirteen codes, plus the class and registry checks the deployment enables.