RESEARCHED · 2026.09.12-g40 · not deployed

G34 — Permissions, consent, and disclosure graph

181 words. Researched design, reviewed 2026-09-12: a library view or proposed design with its sources stated; not a deployed system, a live audit or a provider requirement. Source: Graph/G34-permissions-consent-and-disclosure-graph.md. Graph systems, shelf 5 of 8; library release 2026.09.12-g40.

Status
NEW RESEARCHED DESIGN; not deployed
Reviewed
2026-09-12
Nature
policy-description and private governance view
Priority
P0
Accountability
R20, R14, R24

Question

Who may access, use, export, or publish each record?

Nodes

Resource; Person/role; Permission; Prohibition; Purpose; Disclosure decision

Relationship sketch

  • policy → resource
  • permission → permitted action
  • derived artifact → inherited restrictions

Evidence inputs

Actual authorization, rights statements, owner-approved disclosure decisions, retention requirements.

Implementation

Enforce access in the real storage/retrieval layer; graph labels describe policy but do not enforce it. Review derived summaries for private-source leakage and track revocation through outputs.

Acceptance checks

  • Unauthorized retrieval/export test is denied by real controls
  • Private evidence is excluded from public examples
  • Revocation identifies dependent outputs

Do not infer

A consent field or ODRL record alone is not legal compliance or effective access control.

Publication boundary

Policy summaries may be public; sensitive access records private.

Source basis

S42, S14. See Research/sources.json. Sources support the primitives or named technology. The organization, labels, actions, and acceptance contracts in this catalog are this library's design, not claimed provider requirements.

Back to the shelf in the room · Graph systems