Library / First Principles Framework (FPF) - Core Conceptual Specification
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 14:36:52 UTC · snapshot created 2026-10-03 14:38:14 UTC · last check 2026-10-03 15:00:09 UTC

F.14:15 - SoTA-Echoing

F.14 does not import access-control, terminology, credential, or modeling-language taxonomies as FPF ontology. It uses the sources below only where they change the anti-explosion rule.

Anti-explosion questionExact source and source-use statusAdoption or rejection in F.14Currentness and reopen condition
Why is a system-role-kind label insufficient for authorization?Rose et al., NIST SP 800-207, Zero Trust Architecture (2020), is a current security-architecture reference that separates a subject’s access to a resource, policy decision, policy administration, and policy enforcement.Adapt the separation. Keep the kind name, assigned System, request, requested resource and action, policy decision, permission, and Work distinct. Reject authorization, capability, or trust inferred from a system-role-kind label.Reopen when NIST replaces SP 800-207 or a stronger authorization architecture changes the separation among subject, policy, decision, and enforcement used by this rule.
Why should role-like convenience names not replace an explicit policy relation?Cutler et al., Cedar: A New Language for Expressive, Fast, Safe, and Analyzable Authorization (OOPSLA 2024 extended version), is a current primary policy-language source separating principal, action, resource, context, policy, and authorization decision while supporting role-, attribute-, and relation-based policies.Adapt only the explicit-policy lesson. Recover the direct policy relation and its participants instead of minting a hybrid system-role kind. Reject importing Cedar entities, schema, or evaluator as FPF ontology.Reopen if current policy-language practice shows that the explicit boundary between participants and policy no longer prevents the name explosion addressed here.
Why must a governed value be recovered before a durable designation or family is minted?ISO 704:2022 is a current terminology standard connecting objects, concepts, definitions, and designations.Adopt. Recover the value and use first; then choose no durable name, an existing designation, a local expression, a NameCard, or a public row only at its own trigger. Reject shared spelling as value identity or semantic equivalence.Reopen when ISO 704 or F.17 and F.18 change the distinction between a value and its designation or the publication threshold used here.
Why are credential presentation, status, and relying use different from the governed value?W3C Verifiable Credentials Data Model v2.0 (2025) is a current W3C Recommendation separating issuer, subject, holder, verifier, credential, presentation, and credential status, and leaving authorization decisions outside the data model.Adapt. Keep status, evidence, credential, view, verifier action, and relying decision distinct. Reject a suffix, badge, credential view, or dashboard row as a system-role kind, assignment, permission, assurance, or decision.Reopen when the VC Recommendation or its status family changes the boundaries among presentation, status, and relying use applied in the worked cases.

SysML is intentionally excluded from the positive SoTA basis and from lineage for this pattern. The official OMG SysML 2.0 specification (September 2025) is recorded only as a rejected-popular comparison: a modeling-language role spelling does not independently establish FPF’s local system-role kind, classification, assignment, capability, permission, Method, or Work. Official status and popularity are not evidence for this anti-explosion question. Reopen that rejection only if demonstrated practice supplies a directly relevant, lower-cost kind-admission and assignment boundary that improves the F.14 cases.