Identity and authorization
Tenant isolation, object/function authorization, scoped roles, and recent strong authentication protect sensitive actions.
- Phishing-resistant MFA path
- Facility and carrier scope
- Separation of duties
Freight Passport treats cargo authorization as a server-side, tenant-scoped decision with current evidence, least privilege, controlled exceptions, and durable history.
Capability map
Tenant isolation, object/function authorization, scoped roles, and recent strong authentication protect sensitive actions.
Credentials are signed, short-lived, one-use, state-bound, and redeemed against current server authority.
The architecture emphasizes provenance, freshness, private storage, data minimization, consent/retention boundaries, and legal hold design.
Controlled overrides, Emergency Operations Mode design, bounded workers, monitoring contracts, and fail-closed behavior define exceptional paths.
Production operations, alerts, backup/restore drills, external assessment, and legal approval remain pilot gates.
See it in context
Use fictional shipment data to explore a valid arrival, a blocked mismatch, a protected change, and a replay attempt.