Reviewer Kit
Start with the product problem, then verify the architecture: BeaconGuard separates identity and invocation access from exact consequential-action authorization, governs which policy authority may control production, and preserves evidence for verification and deterministic reconstruction.
10-minute executive review
- Homepage — why the authorization boundary exists
- Product — what BeaconGuard owns and does not replace
- How It Works — REQUEST ALLOW ≠ ACTION ALLOW
- Controlled Evaluation — current qualification and evaluation path
Architecture review
Security review
Evidence review
Deployment review
What reviewers should be able to answer
- What question does identity answer, and what question does BeaconGuard answer?
- Why does an MCP or A2A permission not automatically authorize the final business side effect?
- How is the exact material action bound before execution?
- What customer-approved release is permitted to govern the decision?
- How is one-time execution authority verified and consumed?
- What evidence ties the decision to the exact action and governing authority?
- What must the verifier trust to reconstruct the decision?
- Which responsibilities remain with the customer and systems of record?
Controlled-evaluation prerequisites
- One bounded consequential workflow
- Representative identity / agent / delegation model
- Representative invocation and execution path
- Material-action contract
- Customer policy and approval requirements
- Evidence and deployment assumptions