A principal grants authority over one action, and that authority travels with the action to the place where it runs. Humsana checks the action at that point. Where the action is still the one that was authorized, it proceeds. Where any part of it has moved, the check refuses it and names the part that moved.
| Step | What happens |
|---|---|
| 01 Claim | The agent says who it is, who it acts for, what it wants to do, and what authority it holds. |
| 02 Establish | Humsana separates what is established from what is claimed and from what stays unknown. |
| 03 Confirm | The consequence decides whether a person has to approve. Where one does, the approval is signed over the exact action. |
| 04 Bind | The approval is tied to the action, its bound values and its expiry. It can be spent once. |
| 05 Enforce | The executor presents the action immediately before it runs. A material change is refused and the changed field is named. |
| Code | What failed |
|---|---|
| EFFECTUATION_DRIFT | The presented action differs from the authorized one in a material field. |
| GRANT_DOES_NOT_COVER_THIS_ACTION | The presented action is outside this authorization. |
| MAY_NOT_CHANGE | Fixed by the authorization and not alterable at execution. |
| MAY_NOT_INCREASE | May be reduced, not raised above the authorized value. |
| MAY_ONLY_SHRINK | The scope may narrow, not widen. |
| GRANT_ALREADY_USED | The grant is spent. A grant is spent once. |
| GRANT_NOT_FOUND | No grant exists for the identifier presented. |
| AUTHORIZATION_NOT_GRANTED | There is no authorization to spend. A record that was refused or asked for verification was never spendable and cannot expire. |
| CONFIRMATION_NOT_OBTAINED | A human step was required and no bound approval was presented. |
| RECEIPT_EXPIRED | Past the expiry, so it applies only where an authorization existed. |
| RECEIPT_NOT_FOUND | Unknown identifier, or one belonging to another caller. |
| OUTSIDE_SCOPE | Outside the scope registered for this agent. |
| PROVIDER_DEADLINE_EXCEEDED | A provider did not answer inside the deadline. The boundary waits twenty seconds and records the expiry, not consent. |
Thirteen codes, plus the class and registry checks the deployment enables.