One contract, whatever the language.
B5 enforces in-process in .NET. Most estates are not only .NET. A language-neutral contract for decisions, evidence, permits and revocation is what stops the rest of the estate becoming a second, weaker authorization model.
1. What this enforces
The shape of the conversation rather than the enforcement itself: what a decision request and response contain, what an evidence record contains, what a short-lived permit asserts and how a revocation propagates.
2. Where it enforces
At the boundary between a B5 enforcement point and a non-.NET caller or peer. In-process enforcement remains the strong form; the protocol is how everything else participates honestly.
3. What evidence it produces
Evidence records that verify identically regardless of which runtime produced the decision. If evidence from a non-.NET participant verifies differently, the protocol has failed.
4. Why you cannot assemble this from what you already own
Reimplementing the decision model per language guarantees drift, and drift in authorization is a security defect rather than an inconsistency. A shared wire contract with a conformance suite is the only version of this that holds.
5. What Q4 2026 adds
Polyglot Protocol and Lightweight SDKs
Language-neutral decision, evidence, permit, entity resolution and revocation contracts, with selective SDKs.
6. Acceptance criteria
The specification defines this capability against the three baseline criteria that apply to every Q4 2026 extension — documentation with failure modes and a runbook, automated coverage of primary and abuse cases, and telemetry that emits evidence without exposing prohibited data. Capability-specific criteria have not been written yet, and this page will state them when they are rather than inventing them now.
- The capability is documented with configuration, failure modes, security implications and an operational runbook.
- Automated unit, integration, negative and regression tests cover the primary and abuse cases.
- Telemetry and audit evidence are emitted without exposing prohibited sensitive data.
7. What is still open
The following are genuinely undecided rather than merely undocumented, and each one changes what the capability is:
- Whether the contract is defined against an existing standard or specified independently, and how interoperability is demonstrated either way.
- Permit lifetime and the revocation propagation target — a permit that outlives revocation reopens the fail-closed question.
- Whether non-.NET participants may produce evidence or only consume decisions.
Every Q4 2026 extension is also held to four platform-wide requirements, six test classes and four release gates. They are published once, on the Q4 2026 roadmap, rather than repeated on every page.
Talk to a human.
Get architecture guidance, Test Mode access, integration review, or help choosing the right B5 identity and authorization pattern.