Revocation Rule. The explicit rule for when delegated authority, approvals, credentials, connectors, modules, sessions, artifacts, or access grants stop being valid before their normal expiration. A revocation rule turns "do not use this anymore" into enforceable system state.
Revocation matters because authority is not permanent merely because it was once granted. The system must know who may revoke, which event or evidence triggers revocation, which dependent work is blocked, and which caches, workers, connectors, projections, or fallback paths must observe the revoked state before acting.