# Identity-Authority Review Checklist

The per-concern checklist applied to every identity-and-authority verification.

- The acting principal is an identified individual, never a shared or anonymous account.
- The credential presented is current and not expired.
- Access is target-scoped and time-bound (JIT), not standing administrative privilege.
- The approver is a distinct principal from the requester (separation of duties).
- The approver holds authority over the exact target scope of the action.
- The identity's granted scope matches the action's target; no scope mismatch or cross-target reuse.
