3. Trust and Authorization
Identity determines who; policy determines what.
Learning objectives
By the end of this lesson you will be able to:
- Explain why the DID infrastructure does not replace channel authorization.
- State the principle “identity establishes who; policy establishes what.”
- Author a channel policy that references a peer DID.
- Explain the implications for Open Engineering rules and parsers.
Prerequisites
Implications for rules
Rules and rulesets should be able to reason about:
- the identity of another Pico;
- establishment of subscriptions;
- acceptance or rejection of introductions;
- relationship lifecycle;
- relationship-specific authorization;
- key rotation;
- relationship termination;
- credentials when those become available.
This means Pico rules can increasingly express trust relationships, not merely event-processing behavior.
Implications for parsers
Open Engineering Pico parsers should preserve the distinction between:
Identity
Relationship
Address
Authorization
Messaging
A parser should not treat a DID merely as another form of ECI. They serve different semantic purposes. An ECI primarily identifies a communication channel; a DID identifies a cryptographic actor or relationship. That distinction should survive translation between Open Engineering definitions and Pico Engine/Manifold representations.
Lesson pages
Next
Continue with the Exercise.