ZYZ-STD-CORE - Specialised Constitutional Registries 2
17. Constitutional Role Registry (CRR)
17.1. Introduction
The Constitutional Role Registry (CRR) is the authoritative Constitutional Registry governing all Constitutional Roles recognised within the ZAYAZ constitutional ecosystem.
A Constitutional Role defines the governance function being performed, independent of the authority that performs it, the individual or system acting on behalf of that authority, or the implementation technology through which the action is executed.
The CRR establishes a stable, reusable and technology-independent catalogue of governance participation that can be assigned consistently across all Constitutional Objects.
A Constitutional Role is not:
- a person;
- an organisational job title;
- a user account;
- an email address;
- an identity-provider group;
- an application role;
- a permission set.
It is a governed constitutional definition of how an authority participates in constitutional governance.
17.2. Purpose
The purpose of the Constitutional Role Registry is to separate constitutional participation from constitutional authority.
The CRR provides:
- role identity;
- role semantics;
- governance participation;
- role classifications;
- role compatibility;
- segregation-of-duty support;
- role relationships;
- lifecycle management;
- provenance;
- traceability;
- interoperability.
The CRR enables Constitutional Authorities to exercise their mandates through explicitly governed Constitutional Roles rather than through organisational convention.
17.3. Constitutional Principle
Every constitutionally significant governance function SHALL be represented by a Constitutional Role defined within the Constitutional Role Registry.
Constitutional Authorities SHALL perform governance through Constitutional Role Assignments.
Roles SHALL define participation.
Authorities SHALL define mandate.
Competence SHALL define permitted actions.
These concepts SHALL remain distinct.
17.4. Constitutional Position
The Constitutional Role Registry provides the governance vocabulary used by Constitutional Authorities.
Constitutional Authority
│
│ possesses mandate
▼
Authority Assignment
│
│ assigns
▼
Constitutional Role
│
│ participates in governance of
▼
Constitutional Object
This separation ensures that constitutional governance remains independent of organisational structure and identity management systems.
17.5. Constitutional Role as a Constitutional Object
Every Constitutional Role SHALL be represented as a specialised Constitutional Object.
Each role SHALL possess:
- Constitutional Identifier;
- canonical name;
- semantic definition;
- role classification;
- governance purpose;
- applicability;
- compatibility rules;
- lifecycle;
- provenance;
- relationships;
- validation status.
17.6. Constitutional Role Registry
The Constitutional Role Registry is the authoritative Constitutional Registry governing all recognised Constitutional Roles.
It SHALL govern:
- role identities;
- role definitions;
- classifications;
- participation semantics;
- compatibility rules;
- segregation-of-duty rules;
- inheritance rules;
- lifecycle;
- provenance.
Every Constitutional Role referenced by the constitutional ecosystem SHALL be defined within, or resolvable through, the Constitutional Role Registry.
17.7. Role Identity
Every Constitutional Role SHALL possess a globally unique Constitutional Identifier.
Role identity SHALL remain stable across:
- organisational restructuring;
- personnel changes;
- technology migration;
- identity-provider changes;
- email changes;
- naming changes;
- white-label deployments.
Changing the person performing a role SHALL NOT change the identity of the role.
17.8. Constitutional Role Definition
A Constitutional Role defines a governance function.
It does not define:
- who performs the function;
- whether the performer possesses authority;
- which permissions exist;
- which organisation employs the performer.
Those concerns belong respectively to:
- Constitutional Authorities;
- Authority Assignments;
- Identity Management;
- Access Control.
17.9. Role Classifications
Every Constitutional Role SHALL declare its Role Classification.
Typical classifications include:
Accountability Roles
- Owner
- Sponsor
- Risk Acceptor
Stewardship Roles
- Steward
- Custodian
- Maintainer
- Curator
- Librarian
Authoring Roles
- Author
- Contributor
- Editor
- Drafter
Review Roles
- Reviewer
- Subject Matter Reviewer
- Technical Reviewer
- Regulatory Reviewer
Decision Roles
- Approver
- Signatory
- Ratifier
- Decision Maker
Assurance Roles
- Validator
- Verifier
- Assessor
- Auditor
- Certifier
Interpretation Roles
- Interpreter
- Advisor
- Domain Expert
Publication Roles
- Publisher
- Release Manager
- Disclosure Manager
Operational Roles
- Resolver
- Compiler
- Operator
- Administrator
Oversight Roles
- Observer
- Supervisor
- Escalation Authority
- Appeals Coordinator
Additional classifications MAY be introduced through constitutional governance.
17.10. Governance Function
Every Constitutional Role SHALL define its governance function.
Examples include:
- creating content;
- reviewing proposals;
- approving publication;
- validating conformance;
- interpreting standards;
- maintaining metadata;
- auditing governance;
- supervising lifecycle;
- publishing releases.
The governance function describes participation.
It does not establish constitutional competence.
17.11. Role Scope
Roles MAY define applicability.
Scope MAY include:
- Constitutional Object Types;
- Registries;
- Modules;
- Components;
- Domains;
- Jurisdictions;
- Customers;
- White-label deployments;
- Reporting frameworks.
Scope SHALL remain independent of the authority performing the role.
17.12. Module and Component Roles
Role assignments SHALL preserve both module and component lineage.
A role MAY apply to:
- one module;
- multiple modules;
- one component;
- multiple components;
- a platform domain;
- the complete constitutional ecosystem.
Pergamum Pulse SHALL therefore be capable of determining:
- which roles participate within a module;
- which roles participate within a component;
- where segregation of duties exists;
- where governance gaps exist;
- where excessive concentration of governance exists.
17.13. Role Relationships
Roles MAY participate in governed relationships.
Examples include:
- supports;
- supervises;
- precedes;
- complements;
- excludes;
- escalates-to;
- inherits-from.
Relationships SHALL be explicit.
17.14. Role Compatibility
The CRR MAY define compatible role combinations.
Examples:
Allowed:
- Author + Contributor
- Reviewer + Advisor
- Steward + Maintainer
Restricted:
- Author + Sole Approver
- Validator + Self Publisher
- Auditor + Audited Owner
Compatibility SHALL support constitutional governance without replacing policy evaluation.
17.15. Segregation of Duties
The CRR SHALL support segregation-of-duty definitions.
Examples include:
- an Author SHALL NOT be the sole Approver;
- an Implementer SHALL NOT validate their own implementation;
- an Auditor SHALL remain independent of the governed asset;
- an automated role SHALL NOT approve its own governance definition.
Specific enforcement SHALL be governed by Constitutional Resolution Policies and validated by HECATE.
17.16. Role Assignments
A Constitutional Role becomes effective only through a governed Role Assignment.
A Role Assignment SHALL define:
- Constitutional Authority;
- Constitutional Role;
- governed scope;
- governed object;
- jurisdiction;
- effective period;
- conditions;
- provenance.
A Constitutional Role SHALL NOT imply participation until assigned.
17.17. Authority Relationship
Every Constitutional Role Assignment SHALL reference a Constitutional Authority.
Example:
Constitutional Authority
│
▼
Viroway Governance Council
assigned role
Approver
for
CRP-001
Authorities possess mandate.
Roles describe participation.
Assignments connect the two.
17.18. Representative Assignment
Authorities MAY designate representatives to perform assigned roles.
Representatives MAY include:
- individuals;
- teams;
- committees;
- service accounts;
- automated agents.
Representative assignments SHALL remain outside the Constitutional Role definition.
This separation allows organisational change without altering constitutional governance.
17.19. Identity Independence
Constitutional Roles SHALL remain independent of identity systems.
Identity providers MAY include:
- Microsoft Entra ID;
- Google Workspace;
- Okta;
- LDAP;
- GitHub;
- internal identity systems.
Identity systems authenticate actors.
They do not define Constitutional Roles.
17.20. Organisational Independence
Job titles SHALL NOT normally constitute Constitutional Roles.
For example:
Chief Technology Officer
is an organisational position.
The Constitutional Role may instead be:
- Approver;
- Owner;
- Steward;
- Sponsor.
An organisational position MAY be appointed as the representative of a Constitutional Authority performing those roles.
17.21. Role Competence
Constitutional Roles describe participation.
Competence remains governed by Constitutional Authorities.
For example:
Role:
Approver
Authority:
Architecture Review Council
Competence:
Approve Constitutional Resolution Policies
The same role MAY be exercised by different authorities possessing different competence.
17.22. Role Lifecycle
Every Constitutional Role SHALL participate in constitutional lifecycle management.
Typical states include:
- Draft;
- Proposed;
- Approved;
- Active;
- Deprecated;
- Superseded;
- Retired;
- Archived.
Lifecycle values SHALL originate from Constitutional Value Providers.
17.23. Role Versioning
Role versioning SHALL distinguish between:
- editorial improvements;
- semantic clarification;
- compatibility changes;
- governance changes;
- breaking participation changes.
Role identity SHALL remain stable across compatible revisions.
17.24. Role Provenance
Every Constitutional Role SHALL preserve provenance.
Provenance SHALL include:
- originating authority;
- approval history;
- publication history;
- supersession history;
- stewardship history.
17.25. Role Traceability
Traceability SHALL determine:
- which authorities perform a role;
- which objects reference the role;
- where the role is applied;
- which versions exist;
- which assignments were effective at a given time.
17.26. Role Resolution
Roles SHALL be resolved through the Constitutional Resolution Architecture.
Role Identifier
│
▼
CRG
│
▼
CRP
│
▼
Constitutional Role Registry
│
▼
Constitutional Role
Consumers SHALL reference Constitutional Roles through Constitutional Identifiers.
17.27. Role Validation
HECATE SHALL validate:
- role identity;
- semantic completeness;
- role classification;
- compatibility rules;
- segregation-of-duty definitions;
- lifecycle;
- provenance;
- assignments.
Invalid roles SHALL NOT participate in constitutional governance.
17.28. Role Interoperability
Constitutional Roles SHALL remain independent of:
- workflow engines;
- IAM platforms;
- BPM systems;
- approval software;
- repository permissions;
- cloud providers.
Technology MAY implement roles.
Technology SHALL NOT define constitutional participation.
17.29. Role Compilation
The Constitutional Compiler MAY compile roles into:
- workflow definitions;
- approval matrices;
- RACI views;
- IAM mappings;
- governance dashboards;
- audit models;
- documentation;
- AI governance context.
Compiled artefacts SHALL preserve Constitutional Role identity.
17.30. Role Publication
Roles MAY be published for:
- governance participants;
- developers;
- auditors;
- regulators;
- customers;
- white-label deployments;
- AI systems.
Publication SHALL preserve constitutional meaning.
17.31. Role Conformance
A Constitutional Role conforms where it:
- is represented as a Constitutional Object;
- possesses stable constitutional identity;
- defines a governance function;
- declares its role classification;
- participates through governed assignments;
- remains independent of organisational positions;
- remains independent of identity systems;
- supports segregation-of-duty definitions;
- preserves provenance;
- supports HECATE validation.
17.32. Relationship to Other Constitutional Components
The Constitutional Role Registry provides the authoritative governance vocabulary used throughout the constitutional ecosystem.
Its relationship to other constitutional components is as follows:
- the Constitutional Authorities define who possesses legitimate constitutional mandate;
- the Constitutional Role Registry defines the governance functions through which authorities participate;
- Authority Assignments bind authorities, roles and governed scope together;
- the Constitutional Metadata Dictionary defines metadata describing roles and assignments;
- Constitutional Value Providers supply controlled values for role classifications, assignment states, participation modes and decision models;
- Constitutional Resolution Policies govern how roles and assignments are resolved;
- Constitutional Registries reference roles for governance participation;
- Constitutional Knowledge Assets identify governance participation through Constitutional Roles rather than organisational positions;
- HECATE validates role assignments, segregation of duties and governance consistency;
- the Constitutional Compiler transforms Constitutional Roles into implementation-specific workflow and governance artefacts.
17.33. Foundational Principle
A Constitutional Role is the governed Constitutional Object that defines a constitutional governance function.
Constitutional Roles describe how an authority participates in governance, while Constitutional Authorities define who possesses the legitimate mandate and competence to perform that participation.
Constitutional Roles SHALL remain independent of organisational positions, identity providers, user accounts, application permissions and implementation technologies. Participation SHALL occur only through governed Role Assignments that explicitly bind a Constitutional Authority, a Constitutional Role and a defined governance scope.
By separating governance participation from constitutional authority, ZAYAZ establishes a reusable, technology-independent and auditable governance model that remains stable across organisational change, personnel turnover and implementation evolution.
Architectural note
This chapter completes the constitutional governance model by cleanly separating four distinct concerns:
Constitutional Authority
│
│ possesses mandate
▼
Constitutional Role
│
│ defines governance function
▼
Authority & Role Assignment
│
│ applies within a governed scope
▼
Representative Assignment
│
│ identifies the acting person, team or service
▼
Identity Provider / IAM
This architecture directly addresses the concern raised in the earlier proposal you uploaded: governance should never be tied directly to individuals, email addresses or job titles. Instead, those operational details become replaceable implementation mappings, while the constitutional model remains stable, traceable and technology-independent.
With the introduction of the CRR, the governance stack is now complete:
- CA answers: Who possesses legitimate constitutional mandate?
- CRR answers: What governance function is being performed?
- Authority & Role Assignments answer: Which authority performs which role, where, when and under what conditions?
- IAM / Directory Services answer: Which authenticated person, team or service currently represents that authority?
This provides a durable foundation for the next chapter, Constitutional Value Providers (CVP), which will define the controlled vocabularies and classifications used by Authorities, Roles, Metadata Definitions and the wider constitutional ecosystem.