Control 1
Evidence and tenant protection
Evidence stays bound to tenant, source visibility, and access controls. Revocation follows the source.
Tenant isolation · Permission propagation · Source visibility
SECURITY
Evidence scope, execution state, provider binding, and audit records remain protected from detection through observed outcome. Controls remain tenant- and deployment-specific.
Security controls
Control 1
Evidence stays bound to tenant, source visibility, and access controls. Revocation follows the source.
Tenant isolation · Permission propagation · Source visibility
Control 2
Revoked, quarantined, or stale evidence cannot silently remain trusted. Freshness must be re-established.
Revocation · Quarantine · Freshness · Conflict handling
Control 3
Idempotency, leases, and fencing prevent duplicate work. Uncertain results remain explicit.
Retries · Duplicate suppression · Unknown outcomes · Compensation boundaries
Control 4
Records connect the request, authorization, dispatch, provider response, reconciliation, and observed result. Receipts preserve the observed state.
Read-back · Final state · Completion projection · Audit receipt
Assurance state
These are possible states, not claims that every operation has achieved them.
Implemented
Behavior exists in the evaluated version.
Contract-tested
Boundary and schema contracts pass.
Integration-tested
The configured integration path passes.
Provider-verified
The provider path has observed verification evidence.
Deployment-authorized
This deployment is eligible to run the operation.
Held
Eligibility is paused pending review or remediation.
Stale
Prior evidence has expired or no longer matches.
Status is specific to the operation, provider, version, environment, tenant, and deployment. Missing, held, stale, expired, or unauthorized evidence fails closed.
Review evidence isolation, duplicate prevention, audit records, and scoped assurance.
Capabilities are enabled and certified by operation, provider, tenant, and deployment.