CONTROL
Authorization and policy.
Authorization is explicit and recorded in provenance.
Policy as code
python scanner.py policy evaluate --policy authorization.json --request scan-request.jsonRemote Authorized
The optional channel checks target, identity, source, time, certificate fingerprint, and passive scope. Expiry/revocation fail closed.