GIOS Studioalpha · read-only
Broker vault-backed
Broker decision — HOW is this authorized request brokered? Fail-closed verification of the ApprovalToken, capability plan, BINDING policy allow, vault references, and scope binding. A single-use grant is issued only on brokered; it authorizes nothing to execute here — only the future Provider Execution runtime (V4) consumes it.
brokeredbinding: truetoken consumed1 vault refgrant issued#6bd217f3
approval token:apptoken:appr-vault-okbinding policy:policy:eval-vision-allowcapability:capperm:emb-a-api
Verification reasons (fail-closed)
brokeredpass
authorized token valid + unexpired + unconsumed; binding policy allow matches the plan profile; vault refs releasable; scope bound — execution brokered to the Provider Execution runtime (V4)
Broker grant & provider handoff (V4 readiness only)
BrokerGrant
idbrokergrant:brk-vault-authorized
approval tokenapptoken:appr-vault-ok
scope hashcff76431
binding / single-usetrue / true
issued / expires (ordinal)100 → 105
executed / dispatchedfalse / false
ProviderExecutionHandoff → V4
ownerfuture-provider-execution
capability kindsapi
vault release refssecret:openai-dev
steps (planned, undispatched)1
provider refdeferred
The grant is what the future Provider Execution runtime (V4) requires before any provider executes. It is single-use, scope-bound, binding, and unexecuted — it is not execution.
Request inputs
execution reasonbroker brk-vault-authorized
consumed approvalappr-vault-ok
binding policy ref (M41)policy:eval-vision-allow
execution intent (M50)—
brokered at ordinal100