====== NOD-005a — Authorize Node Execution ======
The [[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] SHALL obtain authorization from an [[dido:99_annexes:annex-b-terms-and-definitions:a:authorizing_authority|Authorizing Authority]] before a [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Node]] participates in [[dido:99_annexes:annex-b-terms-and-definitions:t:test_execution|Test Execution]].
===== Statement =====
The [[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] SHALL obtain authorization from an [[dido:99_annexes:annex-b-terms-and-definitions:a:authorizing_authority|Authorizing Authority]] before a [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Node]] participates in [[dido:99_annexes:annex-b-terms-and-definitions:t:test_execution|Test Execution]].
===== Derived From =====
* [[dido:03-dido-te:99-annexes:annex-c-requirements:03-functional-requirements:03-02-node-requirements:nod-005-execute-a-node:start|NOD-005 — Execute a Node]]
* [[dido:03-dido-te:99-annexes:annex-c-requirements:03-functional-requirements:03-02-node-requirements:nod-004-control-the-node-lifecycle:nod-004c-confirm-node-readiness|NOD-004c — Confirm Node Readiness]]
* [[dido:03-dido-te:99-annexes:annex-b-references:dte-005|[DTE5] DIDO-TE Requirements Register]], source requirement identifier and obligation to be assigned
* [[dido:03-dido-te:99-annexes:annex-b-references:dte-006|[DTE6] Structured Information Processing Reference Architecture (SIP-RA)]]
* [[dido:03-dido-te:99-annexes:annex-b-references:dte-007|[DTE7] Federated Data Interpretation Systems Reference Architecture (FDIS-RA)]]
===== Rationale =====
Node execution authorization establishes that an identified Node may perform an identified role within a specific Test Execution.
The authorization associates the Node with the governing [[dido:99_annexes:annex-b-terms-and-definitions:n:node_definition|Node Definition]], [[dido:99_annexes:annex-b-terms-and-definitions:n:node_implementation|Node Implementation]], [[dido:99_annexes:annex-b-terms-and-definitions:n:node_configuration|Node Configuration]], and [[dido:99_annexes:annex-b-terms-and-definitions:t:test_definition|Test Definition]]. It identifies the permitted activity, Test Inputs, Node Bindings, Test Resources, operating constraints, responsible authority, and period of validity.
Successful configuration, validation, startup, and readiness do not independently authorize a Node to participate in Test Execution. Authorization provides the explicit governance decision that permits execution under specified conditions.
An absent, expired, ambiguous, excessive, or unauthorized execution authorization may allow the wrong Node, Node Configuration, activity, input, resource, or participant to affect Test Execution.
===== Applies To =====
* [[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]]
* [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Node]]
* [[dido:99_annexes:annex-b-terms-and-definitions:n:node_definition|Node Definition]]
* [[dido:99_annexes:annex-b-terms-and-definitions:n:node_implementation|Node Implementation]]
* [[dido:99_annexes:annex-b-terms-and-definitions:n:node_configuration|Node Configuration]]
* [[dido:99_annexes:annex-b-terms-and-definitions:n:node_binding|Node Binding]]
* [[dido:99_annexes:annex-b-terms-and-definitions:t:test_definition|Test Definition]]
* [[dido:99_annexes:annex-b-terms-and-definitions:t:test_input|Test Input]]
* [[dido:99_annexes:annex-b-terms-and-definitions:t:test_resource|Test Resource]]
* [[dido:99_annexes:annex-b-terms-and-definitions:t:test_environment|Test Environment]]
* [[dido:99_annexes:annex-b-terms-and-definitions:t:test_execution|Test Execution]]
* [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]
* [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]
===== Verification =====
Verification confirms that:
* Each Node execution authorization has a unique identity.
* Each authorization identifies the Node permitted to execute.
* Each authorization identifies the applicable Test Execution and Test Definition.
* Each authorization identifies the applicable Node Definition, Node Implementation, and Node Configuration.
* Each authorization identifies the responsible authority and the basis for authorization.
* Each authorization identifies the permitted Node role, activity, Test Inputs, Node Bindings, Test Resources, parameters, and operating constraints.
* Each authorization identifies its effective time, expiration time, and applicable revocation conditions.
* The DIDO-TE confirms that the Node has a current and successful validation result.
* The DIDO-TE confirms that the Node has a current and successful readiness result.
* The DIDO-TE confirms that each mandatory Node Binding and Test Resource is available.
* The DIDO-TE confirms that the authorization satisfies applicable security, access-control, isolation, jurisdictional, residency, and Governance constraints.
* The DIDO-TE verifies the authorization before initiating Node execution.
* The DIDO-TE prevents execution by a Node whose identity, implementation, configuration, role, or Test Execution differs from the authorization.
* The DIDO-TE prevents execution under a missing, incomplete, expired, revoked, ambiguous, altered, or unauthorized authorization.
* The DIDO-TE prevents Node activity, Test Inputs, interactions, and resource use outside the authorized scope.
* A material change to the Node Definition, Node Implementation, Node Configuration, Node Binding, Test Definition, Test Environment, or Test Resource invalidates the authorization and requires renewed authorization.
* The DIDO-TE records the authorization identity, responsible authority, basis, scope, constraints, effective period, verification, changes, revocation, and resulting status.
* The DIDO-TE maintains Traceability among the authorization, Node Definition, Node Implementation, Node Configuration, validation result, readiness result, Test Definition, Test Environment, Test Execution, Test Inputs, Node Bindings, Test Resources, and resulting Evidence.
* Execution under a missing, incomplete, expired, revoked, excessive, unauthorized, ambiguous, or untraceable authorization constitutes nonconformance with this requirement.
Verification includes:
* Inspection of the execution authorization and its unique identity
* Inspection of the responsible authority and basis for authorization
* Inspection of the authorized Node, role, activity, inputs, resources, constraints, and validity period
* Confirmation of successful Node validation and readiness results
* Confirmation that authorization applies to the intended Node Configuration and Test Execution
* A negative assessment involving an expired authorization
* A negative assessment involving a different Node or Node Configuration
* A negative assessment involving activity outside the authorized scope
* Confirmation that a material change invalidates the authorization
* Inspection of authorization, revocation, Evidence, and Traceability records
===== Referenced By =====
{{backlinks>.}}
===== Related Architecture Sections =====
* Add links to the architecture sections governing Node authorization, Node validation, Node readiness, access control, Test Execution, Evidence, and Traceability.
===== Delivery Phase =====
Assign the applicable delivery phase.
===== Requirement Status =====
Draft
===== Statement Reference =====
Use the following syntax to reference this requirement’s Statement section from another DokuWiki page:
{{section>dido:03-dido-te:99-annexes:annex-c-requirements:03-node-requirements:nod-005-execute-a-node:nod-005a-authorize-node-execution#Statement&noheader&nofooter&noeditbtn}}
----
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.