MO-004c — Authorized Resource Use

Crucible SHALL access only Authorized Resources for the identified operational environment.

This requirement derives from:

The Original Requirement states:

The system SHALL support both connected and disconnected operational environments.[C1]

MO-004c preserves the constraint that Crucible operates within the resource-authorization boundary established for the identified operational environment.

The separate requirements derived from MO-004 address:

A resource can be available within an operational environment without being authorized for use.

Examples include:

  • An unapproved repository
  • An unapproved package
  • An unapproved container registry
  • An unapproved network service
  • An unapproved external endpoint
  • An imported Artifact that has not completed admission checks
  • A resource whose authorization has expired
  • A resource whose authorization has been revoked
  • A resource authorized for a different operational environment
  • A resource authorized for a different Operational Lifecycle activity

An Authorized Resource has an identified authorization for the operational environment and intended use.

Restricting Crucible to Authorized Resources supports:

  • Enforcement of environment boundaries
  • Supply-chain control
  • Prevention of unapproved dependency use
  • Prevention of unauthorized external communication
  • Configuration control
  • Security control enforcement
  • Compliance evaluation
  • Generation of auditable Evidence

This requirement does not require every Authorized Resource to be available within the operational environment.

This requirement does not identify the resources required for execution in a Disconnected Environment. MO-004b addresses disconnected execution, and MO-004d addresses resource availability.

This requirement applies to:

Verification confirms that:

  1. The operational environment is identified
  2. The Authorized Resources for the identified operational environment are identified
  3. Each resource accessed by Crucible has a valid authorization for the identified operational environment
  4. Each resource authorization permits the intended use
  5. Crucible does not access a resource absent from the Authorized Resource set
  6. Crucible does not access a resource whose authorization has expired or been revoked
  7. Crucible does not access a resource authorized only for another operational environment
  8. Each attempted access to an unauthorized resource is denied
  9. Each attempted unauthorized resource access is recorded
  10. The verification record preserves Traceability among the operational environment, Authorized Resource set, accessed resources, authorization records, access decisions, and recorded results

Implemented and Verified

Assess whether the current Crucible implementation accesses only Authorized Resources for the identified operational environment.

Review and accept MO-004c as a proposed derived requirement created from the evaluation and decomposition of MO-004 in the Crucible System Requirements Specification, Version 1.1 Draft.


The following unresolved issues affect this requirement:

Identify the authority that authorizes resources for each operational environment.

Define the authorization record required for each Authorized Resource.

Define how authorization scope, expiration, revocation, and intended use affect resource access.

Define the behavior required when Crucible encounters or attempts to access an unauthorized resource.

Define when an imported resource becomes authorized for use within an operational environment.


This requirement page should retain the stable requirement identifier MO-004c.

This page is a leaf requirement page and omits a trailing :start from its namespace.

The parent MO-004 page is a non-leaf page and retains a trailing :start in its namespace.

Changes to the Statement should preserve:

  • Crucible as the responsible actor
  • Authorized Resources as the permitted resources
  • The identified operational environment as the authorization context
  • Prohibition of access to resources outside the Authorized Resource set

The authorization record for each Authorized Resource should identify:

  • The resource identifier
  • The resource type
  • The operational environment
  • The permitted use
  • The authorizing authority
  • The authorization date
  • The authorization status
  • The authorization expiration condition
  • Any restrictions

Material changes should receive review and should update the verification criteria, source records, and Issues section.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004c#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/01-mission-objectives/mo-004/mo-004c.txt
  • Last modified: 2026/07/30 05:24
  • by nick_dido