{
  "$schema": "https://finance.entelekron.org/schemas/financial-authority-register.schema.json",
  "schemaVersion": "1.0.0",
  "controlPlaneId": "tvk-group:entelekron-financial-infrastructure",
  "canonicalAssetId": "tvk-group:tvkusd",
  "registryId": "tvkusd-financial-authority-prelaunch-v1",
  "status": "no-production-authorities",
  "asOf": "2026-08-14T00:00:00Z",
  "productionIdentityProvider": null,
  "humanAuthorities": [],
  "workloadIdentities": [],
  "roleAssignments": [],
  "authorityDomains": [
    "issuer-governance",
    "legal-and-compliance",
    "reserve-control",
    "treasury-operations",
    "mint-operations",
    "payment-operations",
    "key-custody",
    "security-assurance",
    "reconciliation",
    "incident-command",
    "production-release",
    "independent-audit"
  ],
  "separationOfDuties": {
    "minimumIndependentApprovers": 2,
    "requesterMayBeSoleApprover": false,
    "approverMayBeSoleSigner": false,
    "signerMayBeSoleReconciler": false,
    "reserveControllerMaySolelyCompleteMint": false,
    "paymentOperatorMaySolelyReleaseAndReconcile": false,
    "keyCustodianMaySolelyRecoverAndActivate": false,
    "incidentCommanderMaySolelyResumeProduction": false,
    "auditorMayHoldValueMovementAuthority": false,
    "breakGlassMayBypassSegregatedBooks": false
  },
  "identityRequirements": {
    "phishingResistantMfaRequired": true,
    "hardwareBoundAuthenticationRequiredForHighImpactRoles": true,
    "sharedAccountsPermitted": false,
    "standingAdministrativeAccessPermitted": false,
    "justInTimeElevationRequired": true,
    "timeBoundApprovalRequired": true,
    "sessionAndDecisionEvidenceRequired": true,
    "periodicAccessRecertificationRequired": true
  },
  "authority": {
    "aiCanHoldProductionRole": false,
    "aiCanApprove": false,
    "aiCanSign": false,
    "aiCanCreateOrElevateIdentity": false,
    "singleHumanCanCompleteHighImpactAction": false,
    "repositoryMembershipCreatesFinancialAuthority": false
  },
  "notice": "The register defines future authority domains and separation rules. No person, workload, identity provider or production role assignment is approved."
}
