GOVDOSS
Chapters
Main site

// SOA⁴™ CONTROL CHAIN

Accountable action.
Inspectable evidence.

SOA⁴™ connects a subject and protected object through four controls: authentication, authorization, approval, and action. Every gate contributes evidence to the decision trace.

Explore the model

// CONTROL CHAIN

Who may do what—and why?

Follow the request from accountable actor to protected resource. Select any stage to inspect its question and evidence.

REFERENCE CONTROL CHAINSUBJECT + OBJECT + FOUR CONTROLS

SOA⁴™ control chain

SOA⁴™ control-chain flowA request travels from Subject through Authentication, Authorization, Approval, and Action to the protected Object. Evidence is recorded at every stage.01SUBJECT02AUTHENTICATION03AUTHORIZATION04APPROVAL05ACTION06OBJECTRECORDED OUTCOMES RETURN TO THE NEXT DECISION CYCLE
Context / 01

Subject

Identify the accountable actor: person, service, or agent.

Decision question
Who or what is requesting the operation?
Evidence
Subject record · delegation context
  1. Identify the accountable actor: person, service, or agent.

    Decision question
    Who or what is requesting the operation?
    Evidence
    Subject record · delegation context

// IN ACTION

Evidence travels with the decision.

A decision trace makes authority, policy, approval, execution, outcome, and recovery inspectable.

ILLUSTRATIVE EVIDENCE VIEWAgent action decision traceAuthority is inspectable before, during, and after execution.
TRACE IDSOA4-TRACE-04A7
DECISION STATE AWAITING APPROVAL
SubjectLogistics planning agentVERIFIED
ObjectInventory allocation serviceIN SCOPE
AuthorizationRecommend-only policyPERMITTED
ApprovalAccountable operatorREQUIRED
ActionRelease recommendationWAITING
RecoveryRetain current allocationREADY

Illustrative data only. A real implementation maps fields, policy sources, retention, signatures, and acceptance criteria to the client environment.