A.2.8.PER:4.6 - Expose conflict without inventing precedence
PermissionConflictResolutionResultRef ::= U.EpistemeRef
// resolves only to PermissionConflictResolutionResult@Context
PermissionConflictResolutionResult@Context <: U.Episteme
conflictFindingRef: U.EpistemeRef
governingPrecedencePolicyRef: U.EpistemeRef
resolutionWorkRef: WorkRef
deciderSystemRef: U.EntityRef
deciderSystemRoleAssignmentRef: U.RelationRef constrained to U.SystemRoleAssignment
decisionAuthorityRelationOccurrenceRef: U.RelationRef constrained to the direct decision-authority relation kind
selectedGrantOccurrenceRef?: U.RelationRef constrained to GrantedPermissionRelation@Context
selectedNormClaimAddress?: ClaimAddress
effectiveScope: U.ClaimScope
effectiveWindow: QualificationWindowPolicy
reopenConditionClaimAddress: ClaimAddress
PermissionNormConflictFinding@Context <: U.Episteme
grantedPermissionOccurrenceRef: U.RelationRef constrained to GrantedPermissionRelation@Context
conflictingNormClaimAddress: ClaimAddress
overlapScope: U.ClaimScope
overlapWindow: QualificationWindowPolicy
governingPrecedencePolicyRef: U.EpistemeRef
applicablePrecedenceRuleAddress?: ClaimAddress
decisionAuthorityRelationOccurrenceRef?: U.RelationRef constrained to the direct decision-authority relation kind
resolutionWorkRef?: WorkRef
resolutionResultRef?: PermissionConflictResolutionResultRef
blockedWorkOrRelianceRef: U.EntityRef
disposition: unresolved | settledByApplicableRule | settledByDecisionResult
reopenConditionClaimAddress: ClaimAddress
Create the finding only when the grant and current prohibition or commitment concern the same beneficiary/action content, overlapping scope/window, and incompatible practical conclusions. Check that match directly from the two claims and their participants. Permission and an obligation to perform the same action are not automatically in conflict.
Resolve the conflict through exactly one of two branches:
- The current policy already decides.
applicablePrecedenceRuleAddresscites the policy claim whose stated conditions match this beneficiary, action, scope, and window. SetsettledByApplicableRuleonly when that rule itself selects which claim governs the blocked use. - A decision is required. Name the admitted
U.Systemthat decides, the covering assignment under which it performs the datedresolutionWorkRef, and the independently obtaining authority relation whose predicate is defined by its subject pattern and which authorizes this decision. The direct result relation for that decision must connect the Work to a currentPermissionConflictResolutionResult@Contextselecting either the grant occurrence or the conflicting norm claim for the stated scope/window.
PermissionConflictResolutionResult@Context is the exact decision result for this conflict. Exactly one of selectedGrantOccurrenceRef or selectedNormClaimAddress is filled. Its deciderSystemRoleAssignmentRef must cover resolutionWorkRef and have deciderSystemRef as holder; decisionAuthorityRelationOccurrenceRef must independently authorize that decision. If no policy rule decides and no such current result exists, the disposition remains unresolved, even when a responsible office or system-role kind is named. Permit text, readiness, or a passing gate does not silently defeat the prohibition.