Permission Model¶
The permission model is implemented in argus.core.permissions. It combines institution policy, caller scope, tool whitelist, data module, field category, request purpose, and output level.
Decision Inputs¶
| Input | Meaning |
|---|---|
institution_id |
Institution boundary for the request. |
caller_id |
Authenticated machine caller. |
caller_scopes |
Scopes attached to the machine credential. |
tool_name |
Canonical tool evaluated by core. |
interface_name |
CLI, REST, MCP, or task worker. |
data_module |
Data domain such as company facts, filings, events, audit, or licenses. |
field_categories |
Categories requested by the tool operation. |
request_purpose |
Declared purpose such as factual lookup or audit reproduction. |
output_level |
Result detail level such as facts with evidence. |
Required Result¶
Permission denial returns a machine-readable refusal with the audit id, missing permissions, and safe alternative tools. Denied calls must not expose restricted facts or evidence excerpts.
The permission model does not make investment decisions and does not infer customer intent beyond access control.