Summary

  • RFC 5239 centralizes conference state and call signaling without making the focus, policy engine, floor controller, mixer and notification service one authority.
  • A defensible operational record must join request, identity, authorization, object version, enforcement and observer-specific disclosure. Any single receipt proves only its own control surface.

The mute that was not one event

Imagine Alice asks to mute Bob. A control client addresses a conference object. The conference control server checks whether Alice has the required authority under that object’s policies. If allowed, Bob’s state is changed so his media is not to be mixed. The notification service may tell Bob and Carol, depending on policy. A mixer still has to make the media behavior real.

The dashboard can compress that sequence into a green word: muted. The architecture does not. A successful request proves that an interface accepted an operation. An authorization decision proves that a role was permitted to act. An object update proves that intended state changed. Mixer telemetry proves—or fails to prove—that media treatment followed. A notification proves only what a particular observer was allowed to learn.

When these receipts are kept separately, a dispute can be reconstructed. When they are collapsed, the component with the most convenient log inherits authority it never possessed.

The focus is central, but it is not the whole system

RFC 5239 gives the focus a precise role. It maintains a call-signaling relationship with each participant, producing a star-shaped signaling graph. That says where calls are coordinated. It does not say the focus alone creates policy, modifies every object, arbitrates every floor, processes every media stream or publishes every view of state.

The framework names a conference control server, a floor control server, one or more foci and a notification service around the conference object. These are logical entities; they may share a process or machine. Co-residence does not erase their distinct decisions. If one executable performs all five roles, its audit trail still needs five subjects.

Even the media graph need not mirror signaling. Media may be centrally mixed, distributed or combined differently by media type. A central SIP relationship is therefore not evidence that every audio, video or text unit crossed one mixer.

The conference object is shared state, not sovereign intent

The conference object represents a conference through blueprint, reservation, active and completed stages. It carries membership, capabilities, signaling and media information. Conference policies specify rights, permissions and limitations on operations.

That separation matters. The object records state; policy authorizes transitions; a protocol carries requests; runtime components enforce consequences. A URI identifying a focus is not the XCON-URI identifying an object. A conference-user identifier is not necessarily the user’s signaling identity, and one person may have identifiers for different roles.

The same distinction appears in inheritance. A reservation may be cloned from a blueprint; a sidebar may descend from an active conference; parent-enforceable values may limit the child. A current snapshot cannot explain whether a value came from a blueprint, a parent restriction, a local override or a later privileged mutation. Version lineage is part of the evidence.

Permission to speak is not proof of audible media

Floor control grants temporary permission to access a resource. Current BFCP explicitly warns that holding a floor does not by itself ensure that others cannot use the associated resource. The right and the enforcement are separate.

That is a useful limit on control-plane language. “Floor granted” is evidence of an arbitration result. It is not proof that a mixer admitted the holder’s audio, excluded another source, delivered the mix to every participant or preserved the intended priority. Conversely, audible media without a matching floor record may indicate a policy bypass, an implementation gap or a conference that does not use floor control at all.

The correct audit question is not whether the platform says the user had the floor. It is whether the permission, resource association and actual media behavior can be joined without inventing missing steps.

Notification is a view, not the world

RFC 5239 makes identity visibility role- and policy-dependent. A participant can be public, anonymous or hidden; a moderator may see information withheld from ordinary participants. Notifications can also be filtered so each user receives only authorized state.

Absence from Carol’s roster does not prove absence from the conference. Presence in an administrator view does not prove everyone could see the identity. Two correct notifications can differ. A monitoring system that treats one subscription as canonical may turn privacy filtering into a false integrity alarm—or turn an incomplete view into false assurance.

Keep the observer, role, policy version and disclosure rule with every notification. Without them, the record cannot distinguish censorship, privacy, delay and ordinary authorization.

The evidence chain

For each sensitive operation, preserve six linked receipts: the request and target identifier; the authentication method; the role and policy that authorized the act; the before-and-after object version; the component that enforced media or signaling behavior; and the view disclosed to each observer.

Clock alignment and identifier mapping are not clerical detail. They decide whether a request can be joined to an authorization, whether an object mutation preceded a mixer change, and whether a notification represented the new state or an older snapshot.

RFC 5239 does not report a product failure, exploit or deployment result. It supplies an architectural grammar. Lu Heng’s running-code discipline adds the test: authority should be inferred from attributable actions and operational consequences, not from a label such as “host,” “focus” or “central server.” Central state can be useful. Untraceable authority is not.

Sources