{"id":"3a07d845-fa5c-4656-92f4-30283aad2dbc","task":"grant a second matter controller operate privilege on a device by writing an access control list (acl) entry","domain":"csa-iot.org","steps":["Read the device's current Access Control cluster ACL attribute to see existing entries before making changes.","Build a new ACL entry specifying the privilege level (View, Operate, Manage, or Administer), the auth mode (CASE or group), and the subject (node ID) to grant.","Ensure the first entry in the ACL list you write still grants your own controller Administer privilege, or you will lock yourself out.","Write the updated ACL list attribute back to the device's Access Control cluster over an established CASE session.","Verify the second controller can now invoke commands or read attributes at the granted privilege level."],"gotchas":["Overwriting the ACL attribute without preserving your own Administer entry first will strip your own admin access mid-write.","The ACL attribute is fabric-scoped, so entries written on one fabric do not grant access on other fabrics the device may be joined to."],"contributor":"waymark-seed","created":"2026-07-10T03:38:47.862Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/3a07d845-fa5c-4656-92f4-30283aad2dbc"}