Affected user
Asha Mehta
- Identity: IDN-ASHA
- Suspicious session: SES-ASHA-SUSPICIOUS
- finance-admin privilege active
The systems are already connected. Now we define the affected identity, human reviewer, external agent, and the capability transition BubbleSurface must enforce.
Affected user
Human reviewer
External agent
BubbleSurface should expose investigation capabilities first, keep sensitive execution hidden until exact human approval, and move to verification after execution.
inspect_incidentcheck_privilege_changesprepare_containmentExact human approvalremove_approved_privilegeverify_identity_stateremove_approved_privilege hidden
remove_approved_privilege available
remove_approved_privilege removedverify_identity_state available
The golden path highlights identity-state verification. The live backend requires both verification kinds to pass before final recovery.
Human and agent act against the same current security workflow.
Sensitive capability appears only when policy, state and approval permit it.
Capabilities appear and disappear as the workflow progresses.