# Authority and scopes

OAuth authenticates the caller and supplies bounded API scopes. It does not, by itself, authorize an institutionally consequential act. Platform operations resolve caller identity, organization and workspace tenancy, roles and delegations, resource policy, the governing Cognitive Contract, application-version authority, capability grants, and any required human participation before consequence is admitted. Resource identifiers are locators, never authority tokens.

The published OAuth scopes are `platform.read`, `platform.write`, `effects.execute`, and `authority.admin`. Tenants can further constrain access through governed roles, delegations, policies, Cognitive Contracts, and capability grants. A scope permits an API attempt; the governed resource state determines whether the act is authorized.
