====== Authority ====== [[dido:99_annexes:annex-b-terms-and-definitions:start|Go up to Terms and Definitions]] ===== Discussion ===== Authority is the recognized right or power of an [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actor]] to direct actions, make decisions, grant permissions, approve outcomes, or impose obligations within a defined scope. An Actor can derive Authority from: * A law * A regulation * A contract * A charter * An organizational structure * A delegation * A [[dido:99_annexes:annex-b-terms-and-definitions:p:policy|Policy]] * A [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_policy|Governance Policy]] * An assigned [[dido:99_annexes:annex-b-terms-and-definitions:r:role|Role]] * Another recognized source Authority can include the right or power to: * Establish Policies * Establish Governance Policies * Assign Roles * Allocate [[dido:99_annexes:annex-b-terms-and-definitions:r:resource|Resources]] * Approve [[dido:99_annexes:annex-b-terms-and-definitions:b:baseline|Baselines]] * Establish [[dido:99_annexes:annex-b-terms-and-definitions:v:validation_criteria|Validation Criteria]] * Approve [[dido:99_annexes:annex-b-terms-and-definitions:t:test_definition|Test Definitions]] * Authorize [[dido:99_annexes:annex-b-terms-and-definitions:t:test_execution|Test Execution]] * Assign or approve [[dido:99_annexes:annex-b-terms-and-definitions:v:verdict|Verdicts]] * Make [[dido:99_annexes:annex-b-terms-and-definitions:v:validation_decision|Validation Decisions]] * Grant exceptions or waivers * Enforce obligations * Resolve disputes * Delegate Authority * Revoke delegated Authority An Authority assignment can identify: * The authorized Actor * The source of Authority * The applicable Role * The permitted decisions and actions * The applicable scope * The applicable [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_domain|Governance Domain]] * The effective time * The expiration time * The delegation rules * The applicable limitations * The applicable conditions * The applicable Policies * The applicable Governance Policies * Its [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] * Its [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] ===== Definition ===== //recognized right or power of an [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actor]] to direct actions, make decisions, grant permissions, approve outcomes, or impose obligations within a defined scope// ===== Source ===== Adapted from: * [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actor]] * [[dido:99_annexes:annex-b-terms-and-definitions:r:role|Role]] * [[dido:99_annexes:annex-b-terms-and-definitions:p:policy|Policy]] * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_policy|Governance Policy]] * DIDO Reference Architecture * DIDO Reference Implementation Conceptual Model * DIDO-TE draft Requirements Register ===== Note ===== Authority differs from an [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actor]]: * An Actor identifies the participant * Authority identifies the recognized right or power exercised by that Actor An Actor does not possess Authority merely because the Actor can technically perform an action. Authority differs from a [[dido:99_annexes:annex-b-terms-and-definitions:r:role|Role]]: * A Role identifies responsibilities, permissions, and expected behaviors * Authority establishes the recognized right or power to direct actions or make decisions A Role can confer Authority when an authorized source assigns the Role to an Actor. Authority differs from responsibility: * Authority establishes the right or power to direct an action or make a decision * Responsibility establishes an obligation to perform an action or account for an outcome An Actor can have responsibility without possessing final decision Authority. An Actor can also possess Authority while delegating performance responsibility to another Actor. Authority differs from [[dido:99_annexes:annex-b-terms-and-definitions:a:authorization|Authorization]]: * Authority establishes the recognized right or power to grant permission or make a decision * Authorization grants permission to perform a specified action or access a specified Resource An Actor with Authority can issue an Authorization within the scope of that Authority. Authority must have a defined scope. Authority granted for one Organization, Governance Domain, system, Resource, decision type, or period does not automatically apply outside that scope. Authority can be delegated only when the source of Authority permits delegation. A delegation should identify: * The delegating Actor * The receiving Actor * The delegated Authority * The applicable scope * The effective time * The expiration time * The conditions and limitations * The right to redelegate * The revocation process * The applicable Provenance * The applicable Traceability Technical access does not establish Authority. Conversely, an Actor can possess Authority but lack the technical access needed to exercise it. ===== Example ===== An [[dido:99_annexes:annex-b-terms-and-definitions:o:organization|Organization]] assigns the Approval Authority Role to a designated User. The assignment grants the User Authority to make Validation Decisions for a defined DIDO-TE Governance Domain. The Authority permits the User to: * Review the applicable Test Runs * Review the applicable Test Results * Review the assigned Verdicts * Review the supporting Evidence * Apply the approved Validation Criteria * Approve or reject the proposed Validation Decision The Authority does not permit the User to modify the Test Results or approve Validation Decisions outside the defined Governance Domain. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.