Guide · execution boundary

Make the executor refuse an ungranted action.

A signed assessment records a decision. An Action Authority grant becomes a control only when the code that reaches the real system redeems that exact grant before it continues.

The enforceable flow

  • ·Create a bounded Action Authority mandate for one subject, action, resource, time window and use budget.
  • ·Ask Fidacy to decide the exact request, including the locally calculated context hash.
  • ·On ALLOW, pass the returned grant to the executor. A DENY has a signed receipt but no grant.
  • ·Redeem the grant immediately before the executor calls Stripe, a CRM, mail provider or another protected system.
  • ·Persist the downstream response beside the Fidacy decision if you need proof that the external system completed the effect.

Redeem once, immediately before the side effect

POST/v1/action-grants/redeem

Redemption is an atomic server-side claim against the issued JWS grant. A valid grant returns 200 with status: redeemed. A replay returns 409 grant_replayed; an expired, malformed or mismatched grant returns 400 invalid_grant. In either failure case, the executor must not call the protected system.

const redeemed = await fetch("https://api.fidacy.com/v1/action-grants/redeem", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.FIDACY_ENGINE_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({ grant }),
});

if (!redeemed.ok) {
  // Stop here. Do not call the PSP, CRM, mail provider or other side effect.
  throw new Error("Fidacy action grant was not redeemed");
}

const result = await protectedSystem.perform(exactRequest);
// Save result.reference with the action decision in your operational system.

What Fidacy proves at this boundary

  • ·A signed action-decision receipt proves Fidacy's decision over the submitted action, resource and context hash.
  • ·A successful redemption proves the Fidacy executor accepted the grant once before continuing its own path.
  • ·The subsequent system response proves the downstream effect only if you retain and reconcile that response.
  • ·Actions that bypass the Fidacy-connected executor are outside this boundary. They are not silently counted as protected.
Do not make redemption advisory. The protected API call must live after the successful redemption check, and there must not be a second raw code path that can perform the same effect without it.

Operate and investigate

Revoke the mandate to stop future decisions, inspect the action-decision feed and export an Incident Pack for a single event. Use Control Coverage for the separate question of whether the surrounding connector is current and whether recent evidence is complete.

POST /v1/action-mandates/:id/revoke
GET  /v1/action-decisions
GET  /v1/action-decisions/:id/incident-pack
GET  /v1/control-coverage/report