TC-01 Sample successful and rejected identity workflow outcomes
Registration requests
Every request submitted in this session, with the catalogue's decision and the Trust Controller's decision side by side. Held in memory only: this app is a stand in, not a system of record.
No requests submitted yet
Three prepared requests are one click away on the registration form.
A registration that is accepted, and an identity that is issuedBoth decisions pass. The catalogue emits an Agent Identity Manifest, and the Trust Controller returns an identity outcome carrying the capability envelope the group publishes for that role.
A registration the catalogue refusesThe catalogue refuses it and no manifest is produced, so the Trust Controller is never asked. Four of the registration checks fail, on five findings between them, each naming the field and the reason.
A registration that is accepted, and an identity that is refusedThe catalogue accepts it, because whether an agent should exist is its decision to take. The manifest is emitted and handed over. The Trust Controller then refuses the identity, because the group publishes no capability role for what was asked for, and no CBA authority can grant the role that was named. The catalogue entry survives the refusal.