====== 4.1 Human Actors ====== [[dido:02-crusible:04-actors-and-responsibilities:start|Go to 4. Actors and Responsibilities]] Human Actors participate directly in [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] operations or make decisions associated with those operations. The actor names on this page identify operational functions rather than mandatory job titles. One person can perform several functions, and an organization can assign one function to several people. Organizational policies can also require separation of duties between particular functions. People identified only as readers, stakeholders, or members of the intended audience do not become Human Actors unless they participate directly in a requirement-defined operation or decision. ===== Authorized User ===== An **Authorized User** interacts with Crucible within the permissions assigned to that user. Depending on the assigned permissions and the selected operation, an Authorized User can: * Select or provide authorized inputs * Initiate an available Crucible operation * Review operation status and results * Access permitted [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] * Use the [[dido:99_annexes:annex-b-terms-and-definitions:c:cli|Command-Line Interface (CLI)]] or [[dido:99_annexes:annex-b-terms-and-definitions:w:web_ui|Web-Based User Interface (Web UI)]] * Perform actions within an authorized [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domain]] Authorization to use Crucible does not by itself authorize access to every environment, resource, operation, or Artifact. ===== Environment Operator ===== An **Environment Operator** performs authorized lifecycle activities for an [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environment]]. Depending on the applicable requirements and assigned permissions, an Environment Operator can: * Select an approved [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_target|Deployment Target]] * Initiate construction, deployment, validation, maintenance, rollback, or removal activities * Review the state and results of an operation * Respond to failed validation or deployment results * Preserve lifecycle records, [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]], and [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] * Operate within the controls applicable to the environment and Security Domain An Environment Operator does not independently change the security classification, access rules, transfer controls, or authorization status of an environment. ===== Security and Compliance Practitioner ===== A **Security and Compliance Practitioner** performs or reviews activities associated with security controls and [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_assessment|Compliance Assessments]]. Depending on organizational responsibilities, this function can include a security engineer, compliance officer, assessor, or auditor. The practitioner can: * Select or review applicable security and compliance criteria * Review configurations and assessment results * Examine [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_finding|Compliance Findings]] * Review Evidence, Provenance, Traceability, and lifecycle records * Identify conditions requiring remediation or further review * Support authorization and audit activities Crucible records and presents assessment information, but the responsible person or authority determines how that information affects compliance, risk, approval, or authorization decisions. ===== Transfer Operator ===== A **Transfer Operator** performs authorized activities associated with moving content across a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundary]]. Depending on the direction and stage of the transfer, a Transfer Operator can: * Select authorized Artifacts for export * Create or review a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] * Verify that the bundle contains the expected manifests, integrity information, and supporting records * Perform the approved transfer procedure * Receive and validate a transferred bundle * Import authorized content into the destination environment * Record export, transfer, receipt, and import results A Transfer Operator performs only the actions authorized by the applicable transfer controls. Crucible does not independently authorize movement across a Transfer Boundary. ===== Authorizing Authority ===== An **[[dido:99_annexes:annex-b-terms-and-definitions:a:authorizing_authority|Authorizing Authority]]** evaluates risk, assessment results, operational information, and supporting Evidence when making an authorization or [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_approval|Operational Approval]] decision. The Authorizing Authority can use information produced or preserved through Crucible, including: * Compliance Findings * Assessment results * Deployment and validation records * Provenance * Traceability * Transfer records * Supporting Evidence Crucible does not grant [[dido:99_annexes:annex-b-terms-and-definitions:a:accreditation|Accreditation]], Operational Approval, or an [[dido:99_annexes:annex-b-terms-and-definitions:a:ato|Authority to Operate (ATO)]]. ===== Responsibility Boundaries ===== Human Actors remain responsible for decisions requiring organizational authority, professional judgment, approval, or risk acceptance. Automated Crucible operations can construct, assess, transfer, deploy, validate, record, and report results, but automation does not replace the people or authorities responsible for: * Granting access to an environment or resource * Establishing applicable security and compliance criteria * Approving movement across a Transfer Boundary * Accepting operational or security risk * Approving deployment or operational use * Granting Accreditation, Operational Approval, or an ATO ===== Requirements Addressed ===== ^ Requirement ^ Statement ^ | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003c]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003c#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003d]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003d#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003e]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003e#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003f]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003f#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003g]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003g#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003#Statement&noheader&nofooter&noeditbtn}} | The linked leaf requirement pages remain the canonical sources. This page groups the Human Actors associated with those requirements and does not establish additional roles or responsibilities. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.