// SOA⁴™ CONTROL CHAIN
Accountable action.
Inspectable evidence.
SOA⁴™ connects a subject and protected object through four controls: authentication, authorization, approval, and action. Every gate contributes evidence to the decision trace.
Explore the model// CONTROL CHAIN
Who may do what—and why?
Follow the request from accountable actor to protected resource. Select any stage to inspect its question and evidence.
SOA⁴™ control chain
Subject
Identify the accountable actor: person, service, or agent.
- Decision question
- Who or what is requesting the operation?
- Evidence
- Subject record · delegation context
Identify the accountable actor: person, service, or agent.
- Decision question
- Who or what is requesting the operation?
- Evidence
- Subject record · delegation context
Verify identity and the operating context around it.
- Decision question
- Is the subject who they claim to be?
- Evidence
- Identity signal · authentication event
Confirm accountable decision rights and capture rationale.
- Decision question
- Does this action require a human or delegated approval?
- Evidence
- Approval record · decision rationale
Execute within bounds, observe the outcome, and preserve recovery.
- Decision question
- What execution is permitted, monitored, and reversible?
- Evidence
- Action log · outcome · rollback signal
Record the protected data, system, capability, and resulting state.
- Decision question
- What resource is affected, and what changed?
- Evidence
- Object record · before/after state
// IN ACTION
Evidence travels with the decision.
A decision trace makes authority, policy, approval, execution, outcome, and recovery inspectable.
Illustrative data only. A real implementation maps fields, policy sources, retention, signatures, and acceptance criteria to the client environment.
