Role authorization is enforced on the real path

role authorization is enforced on the real execution path, not only in roles.test.ts. A work item whose bound capability's executor_role does not authorize it is REFUSED, not silently executed.

Text-first. PKT-RS-AUT-0018 is a written packet; this page does not claim a video exists.

Key moments

  1. Role authorization on the real path
  2. Not only in roles.test.ts
  3. Unauthorized work is refused

Transcript

role authorization is enforced on the real execution path, not only in roles.test.ts

Published 2026-07-29