Most feedback is excellent and fits our “use, not read” and thin‑waist goals. We’re incorporating it with clarifications to keep the model simple now and extensible later.
Canonical URIs with strict normalization, tenant guards, and explicit error codes.
v1 ARN mapping plus a short HMAC‑based resource_ref for audit/cache.
PEP + Grants with sender‑binding (DPoP/mTLS), jti anti‑replay, atomic use‑count semantics, negative caching, and fail‑closed on PDP outage (except break‑glass).
Batch PDP semantics for /execute and workflows; revalidation rules.