# BP-V07 (Access and authority)

Adrian Sutherland · Version 1.0 · September 2026

© 2005–2026 Adrian Sutherland.

Refreshed for the September 2026 website update.

Licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Keep the [edition note](https://architectureportal.org/downloads/blueprint/1.0/edition.md) with adaptations.

- Question: Current permission controls each read and action.
- Design state: SOFT-01 (Later software option)
- Level: Logical
- Design: Proposed; checks unrun
- Scope: Case reads, acceptance and receipt retrieval
- ASAF aspects: Security, Systems, Information
- View page: /blueprint/security
- Editable source: security.mmd
- Export: security.svg

## Reading the view

The caller uses a staff client. The case service checks trusted identity, current policy and requested resource before performing the permitted operation. Protected case and receipt records remain behind this decision. A restricted summary workflow reads permitted context and returns a proposal for human review. Security records support authorised investigation.

## Key

- Groups show where responsibilities differ; being inside a network is not permission.
- Arrows identify permitted information or actions; actual policy and deployment are still to be selected.

## Linked records

- [SEC-A1 (Service authorisation)](/blueprint/objects#sec-a1)
- [SEC-R1 (Excess disclosure)](/blueprint/objects#sec-r1)
- [SEC-R2 (Unauthorised acceptance)](/blueprint/objects#sec-r2)
- [SEC-R3 (Unsafe summary use)](/blueprint/objects#sec-r3)
- [SEC-R4 (Altered records or traces)](/blueprint/objects#sec-r4)
- [SEC-O1 (Security operation record)](/blueprint/objects#sec-o1)

The view page supplies the decisions, open choices and checks. The object
reference supplies each identifier's meaning and source.
