From a request to a bounded permission
- Grant: create a token for a stated purpose, selected categories, sensitivity level, scope, and duration.
- Active: a service may receive an allowed result only when the request matches a current token.
- Expiring or expired: the permission approaches or reaches its end date without becoming indefinite by default.
- Renew: extend the duration through an explicit user or authorized system action.
- Revoke: end the permission and signal that downstream access should stop.
- Block: prevent new tokens for a named purpose until the block is removed.
Renewal should not hide the decision
The contract defaults automatic renewal to off. A renewable permission is still a choice, not an assumption. A clear renewal experience should show what continues, for how long, and whether the purpose, categories, or scope have changed.