{
  "$comment": "The canonical vocabulary of scope identifiers used by every independent authorization enforcement point in this project: yubikey-mtls-demo/approver.js (APPROVABLE_SCOPES), security/mtls/server.py (REQUIRED_SCOPE), and security/delegation/core.mjs (PROPOSE, FINALIZE). None of these currently share one authorization engine — a security review flagged that as a drift risk, since a scope rename applied to only some of them would silently reopen an authorization gap in whichever wasn't updated. This file doesn't unify the engines, but it removes the need to retype the same string independently in each: every consumer reads its constant's value from here by key, so a rename only ever needs to happen in this one place.",
  "scopes": {
    "PROPOSE": {
      "id": "maple.lot.grade.propose",
      "description": "Propose a synthetic grade determination for a maple-syrup lot."
    },
    "FINALIZE": {
      "id": "maple.lot.grade.finalize",
      "description": "Finalize a previously proposed grade determination. Never granted by the same grant that authorizes PROPOSE (see security/delegation/POLICY.md)."
    },
    "MEASUREMENT_READ": {
      "id": "maple.measurement.read",
      "description": "Read raw Raman/quality measurement data for a lot."
    },
    "AMAZON_CHECKOUT": {
      "id": "amazon.checkout.execute",
      "description": "Execute a checkout/purchase on Amazon on a customer's behalf. Illustrative: a relying party (Amazon), not this project, would define and own this scope's actual semantics in a real integration."
    },
    "AMAZON_PURCHASE_HISTORY": {
      "id": "amazon.account.read.purchase-history",
      "description": "Read a customer's Amazon purchase history. Illustrative: kept separate from AMAZON_CHECKOUT deliberately, so a grant for one does not imply the other -- narrow, resource-specific grants were the missing piece in the real Meta Muse / Amazon case this scope pair models (see research/ and site/agentic-control-plane.html)."
    },
    "PURCHASE": {
      "id": "procurement.purchase.create",
      "description": "Create a synthetic purchase from an approved vendor, within the per-transaction and aggregate money limits of every grant in the delegation chain (VDA-01). Read by security/delegation/core.mjs. Synthetic: no payment is made."
    }
  }
}
