Authorization contracts
Enrichment
The current request contains onlyrecord_ids. The governed contract must
also resolve or create an authorization with:
purpose: a bounded product purpose, not free-form legal language;- selected records;
- actor and workspace;
- provider policy version;
- confirmation timestamp;
- disclosure that external providers may be used;
- explicit statement that no message will be sent.
not_sent draft, and cannot create a
sequence, schedule, send, or expose a recipient coordinate. commercial:discover
covers company search/save and person discovery, commercial:read covers the
safe acquired-contacts read and the quote, and commercial:activate remains
limited to reveal, file and status. Reveal, file and status still require an
accountable human identity; no customer OAuth or provider token passthrough is
used.
Export
Export requires a separate authorization containing:- selected fields;
- destination type;
- actor;
- purpose;
- provider/source rights check;
- suppression check;
- timestamp and policy version.
Send
Sending requires a separate authorization containing:- audience reference;
- sender/provider;
- message or campaign reference;
- actor;
- suppression and bounce snapshot;
- confirmation timestamp;
- policy version.
