Skip to content

Permission Model

The permission model is implemented in argus.core.permissions. It combines institution policy, caller scope, tool whitelist, data module, field category, request purpose, and output level.

Decision Inputs

Input Meaning
institution_id Institution boundary for the request.
caller_id Authenticated machine caller.
caller_scopes Scopes attached to the machine credential.
tool_name Canonical tool evaluated by core.
interface_name CLI, REST, MCP, or task worker.
data_module Data domain such as company facts, filings, events, audit, or licenses.
field_categories Categories requested by the tool operation.
request_purpose Declared purpose such as factual lookup or audit reproduction.
output_level Result detail level such as facts with evidence.

Required Result

Permission denial returns a machine-readable refusal with the audit id, missing permissions, and safe alternative tools. Denied calls must not expose restricted facts or evidence excerpts.

The permission model does not make investment decisions and does not infer customer intent beyond access control.