CONTROL

Authorization and policy.

Authorization is explicit and recorded in provenance.

Policy as code

python scanner.py policy evaluate --policy authorization.json --request scan-request.json

Remote Authorized

The optional channel checks target, identity, source, time, certificate fingerprint, and passive scope. Expiry/revocation fail closed.

Rule