| |
| dido:02-crusible:04-actors-and-responsibilities:04-01-human-actors [2026/08/01 05:56] – created nick_dido | dido:02-crusible:04-actors-and-responsibilities:04-01-human-actors [2026/08/01 05:59] (current) – nick_dido |
|---|
| [[dido:02-crusible:04-actors-and-responsibilities:start|Go to 4. Actors and Responsibilities]] | [[dido:02-crusible:04-actors-and-responsibilities:start|Go to 4. Actors and Responsibilities]] |
| |
| Human Actors direct, govern, operate, assess, authorize, maintain, or consume [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] capabilities. | Human Actors participate directly in [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] operations or make decisions associated with those operations. |
| |
| The actor names used on this page describe functional responsibilities rather than mandatory organizational titles. One person can perform several roles, and an organization can divide one role among several people. | The actor names on this page identify operational functions rather than mandatory job titles. One person can perform several functions, and an organization can assign one function to several people. Organizational policies can also require separation of duties between particular functions. |
| |
| ===== Program and Product Leadership ===== | People identified only as readers, stakeholders, or members of the intended audience do not become Human Actors unless they participate directly in a requirement-defined operation or decision. |
| |
| **Executives** and **Organizational Leaders** establish organizational priorities, allocate resources, approve shared capabilities, and evaluate the operational and financial effects of adopting Crucible across multiple products or programs. | ===== Authorized User ===== |
| |
| **Program Managers** and **Product Managers** coordinate delivery priorities, resource needs, implementation status, operational risks, provider support, and roadmap decisions. | An **Authorized User** interacts with Crucible within the permissions assigned to that user. |
| |
| These roles do not define technical configuration or independently approve an environment for operation unless the organization assigns them those responsibilities. | Depending on the assigned permissions and the selected operation, an Authorized User can: |
| |
| ===== System Ownership and Governance ===== | * Select or provide authorized inputs |
| | * Initiate an available Crucible operation |
| | * Review operation status and results |
| | * Access permitted [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] |
| | * Use the [[dido:99_annexes:annex-b-terms-and-definitions:c:cli|Command-Line Interface (CLI)]] or [[dido:99_annexes:annex-b-terms-and-definitions:w:web_ui|Web-Based User Interface (Web UI)]] |
| | * Perform actions within an authorized [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domain]] |
| |
| **System Owners** define the mission, operational, security, compliance, and lifecycle expectations applicable to a system or [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environment]]. | Authorization to use Crucible does not by itself authorize access to every environment, resource, operation, or Artifact. |
| |
| **Governance Authorities** establish organizational policies, controls, approval criteria, technical direction, and responsibility assignments. | ===== Environment Operator ===== |
| |
| **[[dido:99_annexes:annex-b-terms-and-definitions:a:authorizing_authority|Authorizing Authorities]]** evaluate risk, assessment results, and supporting [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] when making authorization or [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_approval|Operational Approval]] decisions. | An **Environment Operator** performs authorized lifecycle activities for an [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environment]]. |
| |
| Crucible supports these decisions by producing and preserving relevant information. Crucible does not grant [[dido:99_annexes:annex-b-terms-and-definitions:a:accreditation|Accreditation]], Operational Approval, or an [[dido:99_annexes:annex-b-terms-and-definitions:a:ato|Authority to Operate (ATO)]]. | Depending on the applicable requirements and assigned permissions, an Environment Operator can: |
| |
| ===== Architecture and Engineering ===== | * Select an approved [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_target|Deployment Target]] |
| | * Initiate construction, deployment, validation, maintenance, rollback, or removal activities |
| | * Review the state and results of an operation |
| | * Respond to failed validation or deployment results |
| | * Preserve lifecycle records, [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]], and [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] |
| | * Operate within the controls applicable to the environment and Security Domain |
| |
| **Enterprise Architects**, **System Architects**, and **Solution Architects** define architectural boundaries, shared responsibilities, interfaces, provider contracts, and lifecycle relationships. | An Environment Operator does not independently change the security classification, access rules, transfer controls, or authorization status of an environment. |
| |
| **Platform Engineers** construct and maintain reusable [[dido:99_annexes:annex-b-terms-and-definitions:p:platform|Platforms]], deployment environments, provider integrations, and automation services. | ===== Security and Compliance Practitioner ===== |
| |
| **Infrastructure Engineers** define and deploy infrastructure through [[dido:99_annexes:annex-b-terms-and-definitions:i:iac|Infrastructure as Code (IaC)]] and related provider implementations. | A **Security and Compliance Practitioner** performs or reviews activities associated with security controls and [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_assessment|Compliance Assessments]]. |
| |
| **DevSecOps Engineers** integrate construction, deployment, assessment, dependency management, and Evidence generation into controlled operational workflows. | Depending on organizational responsibilities, this function can include a security engineer, compliance officer, assessor, or auditor. |
| |
| **Software Factory Engineers** establish and operate [[dido:99_annexes:annex-b-terms-and-definitions:s:software_factory|Software Factories]] that use Crucible capabilities. | The practitioner can: |
| |
| **Image Engineers** construct, harden, verify, and maintain [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] and other supported image forms. | * Select or review applicable security and compliance criteria |
| | * Review configurations and assessment results |
| | * Examine [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_finding|Compliance Findings]] |
| | * Review Evidence, Provenance, Traceability, and lifecycle records |
| | * Identify conditions requiring remediation or further review |
| | * Support authorization and audit activities |
| |
| **Developers** and **Maintainers** create or modify Crucible components, provider implementations, plugins, integrations, and supporting tools. | Crucible records and presents assessment information, but the responsible person or authority determines how that information affects compliance, risk, approval, or authorization decisions. |
| |
| ===== Security, Compliance, and Assessment ===== | ===== Transfer Operator ===== |
| |
| **Cybersecurity Engineers** apply security criteria, review configurations, evaluate controls, assess results, and support remediation activities. | A **Transfer Operator** performs authorized activities associated with moving content across a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundary]]. |
| |
| **Compliance Officers** evaluate compliance criteria, assessment results, exceptions, claims, [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_finding|Compliance Findings]], and supporting Evidence. | Depending on the direction and stage of the transfer, a Transfer Operator can: |
| |
| **Assessors** perform or review assessments using the applicable criteria, methods, and organizational procedures. | * Select authorized Artifacts for export |
| | * Create or review a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] |
| | * Verify that the bundle contains the expected manifests, integrity information, and supporting records |
| | * Perform the approved transfer procedure |
| | * Receive and validate a transferred bundle |
| | * Import authorized content into the destination environment |
| | * Record export, transfer, receipt, and import results |
| |
| **Auditors** examine [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]], [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]], assessment results, lifecycle records, and [[dido:99_annexes:annex-b-terms-and-definitions:a:auditability|Auditability]]. | A Transfer Operator performs only the actions authorized by the applicable transfer controls. Crucible does not independently authorize movement across a Transfer Boundary. |
| |
| These roles can overlap, but organizations should preserve any separation of duties required by applicable policies, controls, or authorization processes. | ===== Authorizing Authority ===== |
| |
| ===== Operations ===== | An **[[dido:99_annexes:annex-b-terms-and-definitions:a:authorizing_authority|Authorizing Authority]]** evaluates risk, assessment results, operational information, and supporting Evidence when making an authorization or [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_approval|Operational Approval]] decision. |
| |
| **Environment Operators** deploy, operate, monitor, maintain, validate, and retire managed Infrastructure Environments within the authority granted to them. | The Authorizing Authority can use information produced or preserved through Crucible, including: |
| |
| **Enclave Operators** import, deploy, operate, and maintain approved content within [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] or [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]. | * Compliance Findings |
| | * Assessment results |
| | * Deployment and validation records |
| | * Provenance |
| | * Traceability |
| | * Transfer records |
| | * Supporting Evidence |
| |
| **Transfer Personnel** prepare, review, move, receive, or import authorized content across a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundary]] according to the applicable handling and approval procedures. | Crucible does not grant [[dido:99_annexes:annex-b-terms-and-definitions:a:accreditation|Accreditation]], Operational Approval, or an [[dido:99_annexes:annex-b-terms-and-definitions:a:ato|Authority to Operate (ATO)]]. |
| | |
| An organization can assign these responsibilities to separate people when security controls, information-handling rules, or separation-of-duty requirements require independent actions. | |
| | |
| ===== Consumers ===== | |
| | |
| **Application Teams** and **Product Teams** consume approved images, infrastructure resources, platform services, [[dido:99_annexes:annex-b-terms-and-definitions:b:baseline|Baselines]], and deployment environments. | |
| | |
| These teams can provide product-specific configuration and mission software while relying on shared Crucible capabilities for common lifecycle activities. | |
| |
| ===== Responsibility Boundaries ===== | ===== Responsibility Boundaries ===== |
| |
| Human Actors remain responsible for decisions requiring organizational authority, professional judgment, or risk acceptance. | Human Actors remain responsible for decisions requiring organizational authority, professional judgment, approval, or risk acceptance. |
| |
| Automated Crucible activities can construct, assess, validate, record, and report results, but automation does not replace the people or authorities responsible for: | Automated Crucible operations can construct, assess, transfer, deploy, validate, record, and report results, but automation does not replace the people or authorities responsible for: |
| |
| * Establishing applicable policies and criteria | * Granting access to an environment or resource |
| * Approving access to environments and resources | * Establishing applicable security and compliance criteria |
| * Authorizing transfers across controlled boundaries | * Approving movement across a Transfer Boundary |
| * Accepting risk | * Accepting operational or security risk |
| * Approving deployment or operational use | * Approving deployment or operational use |
| * Granting Accreditation, Operational Approval, or an ATO | * Granting Accreditation, Operational Approval, or an ATO |
| |
| The applicable leaf requirements in [[dido:02-crusible:99-annexes:annex-c-requirements:start|Annex C: Requirements]] define the required actions and controls. This page groups the Human Actors associated with those actions and does not create additional roles or responsibilities. | ===== Requirements Addressed ===== |
| | |
| | ^ Requirement ^ Statement ^ |
| | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003c]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003c#Statement&noheader&nofooter&noeditbtn}} | |
| | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003d]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003d#Statement&noheader&nofooter&noeditbtn}} | |
| | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003e]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003e#Statement&noheader&nofooter&noeditbtn}} | |
| | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003f]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003f#Statement&noheader&nofooter&noeditbtn}} | |
| | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003g]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003g#Statement&noheader&nofooter&noeditbtn}} | |
| | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002#Statement&noheader&nofooter&noeditbtn}} | |
| | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003#Statement&noheader&nofooter&noeditbtn}} | |
| | |
| | The linked leaf requirement pages remain the canonical sources. This page groups the Human Actors associated with those requirements and does not establish additional roles or responsibilities. |
| |
| ---- | ---- |