Decide a write
Authentication
Request
The human sponsor on whose behalf the agent acts (e.g. s_42).
The agent performing the write (e.g. support-agent-07).
The consequential action (e.g. refund, provision, admit).
What the action applies to (e.g. order #88412).
Why — the stated intent, bound into the auth token (e.g. Refund order #88412, close ticket #2210).
Grants only: how long the grant lives. Default 90, min 1, max 3600.
Response
ALLOW, DENY, or STEP_UP, plus a receipt. On ALLOW the response also carries authToken, a 90-second HMAC-signed token bound to this exact sponsor/agent/verb/target/purpose, and tokenExpiresIn. STEP_UP means the tenant policy requires a human sponsor to approve; the sponsor mints a grant via POST /v1/grants and the agent re-checks.