Skip to main content

Principal-Type Audit

This document lives with the guides:

Principal-Type Audit (Phase 11)

It inventories every sensitive principal_type check in vault/src/ and classifies allowlist vs denylist patterns for platform_delegated safety.