A16
Approval and deletion only by humans
Unit E1 · Screens M9, M21, M23 · MCP dokument_status_wechseln, dokument_loeschen, workflow_konfiguration_aendern · status approved (Thomas Frei on 2026-09-09 with E5, the last building block; E1: agent eligibility per role with rollen_konfiguration_lesen, rollen_konfiguration_aendern and the nurPerson lock in the registry; E4: deletion lock; E5: approval lock via a command predicate that reserves the Approve transition for persons only)
- AC1 Approving and deleting (Document, Directive, master data, Subscriptions of other Identities) by an Identity of type Agent are rejected, regardless of roles and scopes.
- AC2 For each Role it is configurable whether Agents may hold it (F11); assigning a Role that is not permitted to an Agent is rejected.
- AC3 The configuration is audited and visible in M23.