The DIDO-TE SHALL require authorization for each permitted interaction that changes the state of a Resource.
A permitted interaction may change the state of a Resource participating in or affected by a Twin Relationship.
Permission to perform an interaction does not establish authority to change Resource state.
Requiring authorization establishes a separate control decision for state-changing interactions and prevents technical capability, connectivity, interface availability, DDS discovery, Topic matching, or other implementation mechanisms from being interpreted as authority to modify a Resource.
This requirement establishes the authorization requirement. TWIN-010d separately prevents execution when the required authorization is absent or denied.
Verification confirms that:
Verification includes at least one permitted interaction that changes Resource state and confirms that authorization is required independently of interaction permission.
This requirement establishes the authorization prerequisite for a permitted interaction that changes Resource state.
TWIN-010d governs enforcement of that prerequisite by preventing execution when the required authorization is absent or denied.
TBD
Draft
{{section>dido:03-dido-te:99-annexes:annex-c-requirements:03-functional-requirements:03-03-twin-node-requirements:twin-010-control-twin-interaction:twin-010c-require-authorization-for-resource-state-changes#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.