Role authorization is enforced on the real path

role authorization is enforced on the real execution path, not only in roles.test.ts. A work item whose bound capability's executor_role does not authorize it is REFUSED, not silently executed.

Text-first. PKT-RS-AUT-0018 is a written packet; this page does not claim a video exists.

Key moments

  1. 0:00 · Role authorization on the real path
  2. 0:36 · Not only in roles.test.ts
  3. 1:12 · Unauthorized work is refused

Transcript

role authorization is enforced on the real execution path, not only in roles.test.ts

Published 2026-07-29