Customer ownership
Only a customer administrator grants or revokes provider authority.
Customers grant named provider operators exact, expiring permissions for threat and posture workflows. Provider tokens stay bound to the provider tenant; every customer operation requires a live delegation, executes through a customer-side delegated principal, and records evidence for both parties.
Only a customer administrator grants or revokes provider authority.
Each delegation names provider operators and a closed permission set.
Provider requests are token-bound to their own tenant and separately checked against the target customer.
Grant, delegated action, expiration, and revocation are recorded in both tenant audit chains.
Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.
Document the environment, threat model, and integration boundary.
Select protocols, signals, policies, and failure behavior.
Test vendor-specific APIs, tenant isolation, and abuse paths.
Mark available only after deployed end-to-end verification.