A customer-facing follow-up is prepared. The system checks the current authority for that company and responsibility. Where the approved scope requires approval, the action waits. Where it is permitted, the supported execution path carries it out and records the result. If it fails or remains uncertain, the system must not describe it as completed.
Every action Sabina attempts is written to the record before it is carried out — a row that exists whether the action is committed, refused, or still waiting on a person. Anything that reaches the outside world needs a permit: a signed, single-use token bound to the tenant, the capability, the exact arguments, and a time window. The permit is minted once and consumed once; a verifier can check its signature, but only the authority service can mint one.
The rules an owner writes are restrictions, not grants. There is no instruction in the rule grammar that widens what Sabina can do, spends money, or turns a suggestion into a standing rule — that term does not exist for the compiler to accept. A one-time approval is consumed and expires; it never becomes a standing permission.
Her authority is also bounded by a signed attestation of what she is currently permitted to run. That attestation expires on a fixed schedule, and if it lapses — or the code it is pinned to changes — every capability demotes automatically to propose-only until it is re-signed.
Before anything becomes a spoken or written sentence, a check runs against the record: she cannot claim a booking, a payment, or a change that the system does not show as actually committed.
None of this lives in an editable log. Grants, rule changes, revocations, and approval events are written once and never altered — a rule can be withdrawn, but the record that it existed, who wrote it, and when, stays.