There was one time I booked a flight ticket right before departure.

Payment successful. The money has been deducted from the account.

But instead of showing “Booking successful,” the screen only displayed a short line:

“Processing.”

At that time, my first reaction was to think the system was delayed.

Everything I needed to do was already done.

So what else do we have to wait for?

Later I realized that maybe the system wasn’t really slow.

It just isn’t ready to let that transaction complete immediately.

That sounds strange.

Because we often think a decision has only two possibilities: allowed or not allowed.

But in practice, there’s another option.

It’s allowed, but not now.

This makes me think quite a lot when reading about @NewtonProtocol.

What I find interesting isn’t whether the policy answers “allow” or “deny”.

Also, in a smaller question:

Does a valid execution necessarily have to happen as soon as it’s requested?

I don’t think so.

There are executions where the value of the decision isn’t just about whether to allow it or not.

It’s also about the time when the system chooses to actually make that decision happen.

At that point, “waiting” is no longer a sign of a slow system.

It can be part of the decision itself.

That’s the point I find quite different.

Normally, we treat time as just the distance between pressing the button and finishing.

But there are also cases where time becomes a parameter of authorization.

Not because the execution is wrong.

But execution being correct doesn't necessarily mean it should happen immediately.

Disagreeing.

If a policy always chooses to delay for greater safety, the experience will quickly become unpleasant. Users will start to feel that every action is slow, even when there is no clear reason.

But if the default policy is that every valid execution must be carried out right away, the system also loses an important way of handling the space between the two choices: “allow” and “deny”.

What I want to see from @NewtonProtocol isn’t only the ability to make a decision.

It’s about how a policy determines when an execution should happen immediately, and when the choice to wait a bit longer is actually a more reasonable decision.

To me, a good authorization layer doesn’t just determine what’s allowed to happen.

It also understands that sometimes, timing is part of that very decision.

#Newt $SPCXB $LAB $NEWT