Operating Control
Authorization
Establish the rule that a governed QR action proceeds only when the requesting actor, system or action holds the authority required to continue.
- Protocol Family
- Operations
- Status
- Published
- Version
- 1.0
- Effective Date
- 2026-08-13
- Related Department
- QRProtocol.us
- Scope
- Every governed QR interaction that requests an action after a scan event.
- Purpose
- Establish the rule that a governed QR action proceeds only when the requesting actor, system or action holds the authority required to continue.
- Dependencies
- operating-sequence
A scan is a request. Authorization decides whether it continues.
Reading a QR code proves only that a symbol was read. It does not establish that the requesting actor, system or action holds the authority required to continue. Authorization is the separate determination that supplies that answer.
Authorization asks three questions
- •Who or what is requesting the action?
- •Does that actor or system hold the authority required for this action?
- •Does the current state of the QR object permit the action being requested?
Authorization is evaluated against state. The same QR object may permit an action for one requesting actor and refuse it for another, and may permit an action while active and refuse it after suspension, expiration or revocation.
Possession of the label is not authority. Authority is determined, not assumed.
Refusal is a governed outcome
When authority cannot be established, the action does not execute. The interaction is routed to Failures & Exceptions and, where required, recorded.
Definition
Authorization is the determination that the requesting actor, system or action holds the authority required to continue.
Governing Rule
No governed action executes before authorization is determined. A scan is a request, not a permission.
What it governs
- — Whether the requesting actor or system may continue
- — The point in the sequence at which authority is determined
- — What must occur when authority cannot be established
Permitted
- — Refusing an action while the QR object itself remains registered and active
- — Different authorization outcomes for the same QR object under different requesting actors
Not permitted
- — Treating a successful scan as authorization
- — Executing an action before authorization is determined
- — Inferring authority from possession of the physical label
- When the condition passes
- The interaction continues to the next step of the operating sequence.
- When the condition fails
- The action is refused and handled under Failures & Exceptions. Refusal is a governed outcome, not a malfunction.
- Department performing the operation
- Protocol defines the authorization rule. The authority conditions and their evaluation operate within the Codex environment at QRCodex.us.
- Record / evidence required
- Where the applicable Protocol requires it, the authorization determination and its outcome are recorded.
- Where the operational record lives
- QRCodex.us.
Direct Answers
Does scanning a registered QR code authorize an action?
No. A scan is the entry event. Authorization is a separate determination that the requesting actor, system or action holds the authority required to continue.
Read Next
Revision History
- v1.0 — 2026-08-13 — Established from approved Protocol vocabulary and the operating sequence.
Related Protocols
Operations
Operating Sequence
Define the ordered sequence a governed QR interaction follows from scan through recorded outcome.
Operations
State Control
Define the conditions Protocol evaluates before permitting system behavior.
Safety
Failures & Exceptions
Establish defined system behavior for conditions that cannot proceed normally.
Audit
Audit & Recording
Establish the recording requirements that make governed QR activity reconstructable.
