Skip to content

Workload Authorization

Compute authorization grants a specific signed workload permission to operate on selected buckets under a defined execution policy.

An authorization identifies:

  • the workload and immutable digest;
  • the publisher and requesting identity;
  • permitted buckets and operations;
  • eligible execution nodes;
  • the validity period and invocation limits;
  • allowed result and artifact recipients;
  • the governing approval or policy decision.

Authorization is workload-scoped. It does not give the workload publisher, requester or result recipient direct read access to source records unless that access is granted separately by the bucket permission model.

Changing the workload digest, requested buckets or material execution policy requires a new authorization decision.

Audience-first NOOSChain documentation.