WITHOUT KINEGRANT
- No action-specific authorization context
- No scope or lifetime constraints
- No local capability verification
- No protocol receipt
KineGrant is the experimental authorization infrastructure for physical AI systems.
Experimental open draft. Open source.
THE DIFFERENCE
Authorization becomes explicit
before a physical action.
REQUEST 鈫?PROOF
Every transition is explicit. Unknown policy fails closed. A deny can stop the path. An allow becomes a request-bound capability鈥攏ot a reusable credential.
Bound capability consumed once. Signed receipt emitted.
PROOF, NOT PROMISES
Run the public reference demo from the v0.1.1 release.
$ python -m pip install -e .
$ kinegrant-demoBOUNDARIES
IAM, PKI, network controls, robotics middleware, and functional-safety systems retain their roles. KineGrant adds a narrow authorization and receipt path for a specific physical action.
Reference profiles are not certification, endorsement, or a claim of production integration.