MODEL2 COMMERCIAL CONTROL AUTHORITY

Ruler Control Room

Authoritative commercial state. Client-reported online booleans are never trusted.

DeploymentsScoped authority objects
CriticalNon-active authority states
Security eventsRecent authenticated events
AuthorityRULERCache is never authoritative
DERIVED AUTHORITY

Fleet overview

NO SESSION
Tenant / DeploymentStateCommercialLease / GenerationsIntegrityEvidenceControls
AUTHENTICATED DEVICE SIGNALS

Security events

Authenticate to load security events.
APPEND-ONLY AUTHORITY HISTORY

Audit ledger

Authenticate to load audit records.
PHISHING-RESISTANT ADMIN AUTH

Operator login

Password-only privileged access is forbidden. Session and state-changing actions remain CSRF/origin/RBAC/generation checked.

ONE-TIME ENROLLMENT

Register passkey

The bootstrap token is stored server-side only as a SHA-256 digest, expires, and is single-use.

Authenticate with a registered WebAuthn credential. Administrative commands remain fail-closed.