SOC 2 posture, audit trail, governance, and the runbooks that operate them
RBAC
reader / editor / admin
Endpoint-level role matrix; tenant-bound principals.
ABAC
deny-first / allow-then
Priority-aware DSL with simulation API.
Doc ACL
creator-owner default
Expiring grants ignored; AUTHZ_DEFAULT_DENY in prod.
docs/runbooks/. Every procedure has a deterministic execution path; most are exercised in CI.0.8.0; envelope encryption in 1.9.0; SOC 2 catalog in 2.0.0; ABAC in 2.2.0. See the release timeline for the full trajectory.