Capability-based authorization

Permissions are scopes, not identities: storage.read, storage.create, storage.modify, compute.create, compute.cancel… each token carries the maximum it allows, following least privilege. IAM policy gates them by group — storage scopes for wlcg/xfers, compute scopes for wlcg/pilots — and a request for a scope you are not entitled to does not fail: the server silently issues the token without it.


Topology