GURDN

Documentation / How it acts

Authorisation

What must be true before anything changes.

Nothing is applied because a rule fired. Authorisation is a separate stage of the pipeline, and a decision that has not passed it cannot reach the privileged service.

Levels

Operations are not equal, so the authority required is not uniform. Reading state requires no authority to mutate anything. An ordinary change requires explicit confirmation. A change made under a policy the user has already accepted carries that policy as its authority, and is recorded as such. The emergency path is separate again and cannot be reached by an operation that merely claims urgency.

Why it is a stage and not a checkbox

A tool that decides and acts in the same breath reconfigures your network while you are in a meeting. Separating the two means three things can be true at once: GURDN can be confident, the change can be visible before it happens, and you can decline.

  • What GURDN intends to do is shown first, with the state it expects afterwards.
  • How it would undo the change is shown at the same time, before the change is made.
  • The authorisation is recorded, so a later question about why the machine changed has an answer.

Expiry and reuse

An authorisation is for an operation at a moment, not a standing permission. It expires, and an expired one cannot be used. A previously granted authorisation cannot be replayed to justify a second change, which is checked at the privileged boundary rather than only in the interface.

The interface cannot promote itself

The desktop interface holds no privilege. It cannot perform an operation, and it cannot assert a level of authority the engine did not establish. The engine in turn cannot bypass the checks the privileged service makes: the service validates the request it receives rather than trusting that the caller validated it already.

This matters because the alternative is a product where compromising the user interface is the same as compromising the machine's network configuration. See the security model.

Not reapplied silently

If a change GURDN made is undone outside GURDN, it reports that the machine no longer matches what was applied. It does not quietly put it back. Reapplying a change the user never re-authorised is precisely the behaviour the design rules out.