{
  "artifact": "ars-delta",
  "artifact_version": "0.1",
  "subject": {
    "agent_id": "acme-ticket-triage",
    "previous_version": "1.4.2",
    "current_version": "1.5.0"
  },
  "previous_ref": {
    "contract_hash": "57907eecb0eb7796fb3fa8ce4e013c011112a1f9c7bd068f00f2d21010993037",
    "agent_version": "1.4.2",
    "declaration_state": "owner_declared",
    "observation_hash": null,
    "observation_completeness": null,
    "reconciliation_hash": null,
    "reconciliation_completeness": null
  },
  "current_ref": {
    "contract_hash": "e92ea6d90dd76e5be2ae36396e5fc3ca91cfde40492ba42ff8d54f468dba90ec",
    "agent_version": "1.5.0",
    "declaration_state": "owner_declared",
    "observation_hash": null,
    "observation_completeness": null,
    "reconciliation_hash": null,
    "reconciliation_completeness": null
  },
  "methodology_ref": {
    "methodology_version": "0.1",
    "standard": {
      "standard_id": "ARS",
      "version": "1.0",
      "hash": "12309637f0a716f9923204a4338c07acca5107a3cb9aa02b0a20b48902926d9c"
    }
  },
  "basis": "declarations_only",
  "completeness": "complete",
  "changes": [
    {
      "change_id": "approval_weakened:draft-reply",
      "category": "approval_weakened",
      "domain": "autonomy",
      "subject": "draft-reply",
      "severity": "critical",
      "authority_expanding": true,
      "before": {
        "path": "tools[draft-reply]/approval",
        "value": {
          "policy": "human_approval",
          "condition": null
        }
      },
      "after": {
        "path": "tools[draft-reply]/approval",
        "value": {
          "policy": "human_approval_conditional",
          "condition": "Required only when the draft quotes content the agent did not author."
        }
      },
      "explanation": "an action that needed a person now needs less of one, or needs one less often. draft-reply moved from human_approval to human_approval_conditional, required only when: Required only when the draft quotes content the agent did not author.. Outside that condition the action now happens with no human in front of it.",
      "claims": [
        "tools[draft-reply]/approval/policy",
        "tools[draft-reply]/approval/condition",
        "tools[draft-reply]/approval/approval_class"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-08",
        "ARS-09",
        "ARS-10",
        "ARS-12",
        "ARS-34",
        "ARS-35"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-08",
          "citation_id": "ARS-1.0-08",
          "applicability": true
        },
        {
          "control_id": "ARS-09",
          "citation_id": "ARS-1.0-09",
          "applicability": true
        },
        {
          "control_id": "ARS-10",
          "citation_id": "ARS-1.0-10",
          "applicability": true
        },
        {
          "control_id": "ARS-12",
          "citation_id": "ARS-1.0-12",
          "applicability": true
        },
        {
          "control_id": "ARS-34",
          "citation_id": "ARS-1.0-34",
          "applicability": true
        },
        {
          "control_id": "ARS-35",
          "citation_id": "ARS-1.0-35",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive"
      ],
      "evidence_retained": [
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retention-covers-artifacts",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-08",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-09",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-10",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-12",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-34",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-35",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [
        {
          "test_id": "gate-enforced:draft-reply",
          "change_id": "approval_weakened:draft-reply",
          "what": "Confirm the approval path that remains on draft-reply is enforced server-side, not only in the client."
        },
        {
          "test_id": "gate-bypass:draft-reply",
          "change_id": "approval_weakened:draft-reply",
          "what": "Attempt to reach draft-reply without the approval the declaration now requires."
        }
      ],
      "reviews_required": [
        {
          "review_id": "approval-owner-review:draft-reply",
          "change_id": "approval_weakened:draft-reply",
          "role": "Head of Customer Operations Engineering",
          "what": "Accept, in writing, that draft-reply may now act with less human involvement than the previous release required."
        },
        {
          "review_id": "approval-design-review:draft-reply",
          "change_id": "approval_weakened:draft-reply",
          "role": "Security review board",
          "what": "Confirm the remaining gate is proportionate to the action's blast radius."
        }
      ],
      "deployment_blocking": false
    },
    {
      "change_id": "destructive_action_added:send-customer-email",
      "category": "destructive_action_added",
      "domain": "tools",
      "subject": "send-customer-email",
      "severity": "critical",
      "authority_expanding": true,
      "before": null,
      "after": {
        "path": "autonomy/destructive_action_inventory[send-customer-email]",
        "value": {
          "action_id": "send-customer-email",
          "tool_id": "send-email",
          "classification": "irreversible",
          "gate": "human_approval"
        }
      },
      "explanation": "the agent can now create, modify, delete, send or spend where it previously could not. A destructive action send-customer-email on send-email was inventoried, classified irreversible and gated at human_approval.",
      "claims": [
        "autonomy/destructive_action_inventory[send-customer-email]"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-08",
        "ARS-09",
        "ARS-10",
        "ARS-18",
        "ARS-19",
        "ARS-22",
        "ARS-34",
        "ARS-37",
        "ARS-41"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-08",
          "citation_id": "ARS-1.0-08",
          "applicability": true
        },
        {
          "control_id": "ARS-09",
          "citation_id": "ARS-1.0-09",
          "applicability": true
        },
        {
          "control_id": "ARS-10",
          "citation_id": "ARS-1.0-10",
          "applicability": true
        },
        {
          "control_id": "ARS-18",
          "citation_id": "ARS-1.0-18",
          "applicability": true
        },
        {
          "control_id": "ARS-19",
          "citation_id": "ARS-1.0-19",
          "applicability": true
        },
        {
          "control_id": "ARS-22",
          "citation_id": "ARS-1.0-22",
          "applicability": true
        },
        {
          "control_id": "ARS-34",
          "citation_id": "ARS-1.0-34",
          "applicability": true
        },
        {
          "control_id": "ARS-37",
          "citation_id": "ARS-1.0-37",
          "applicability": true
        },
        {
          "control_id": "ARS-41",
          "citation_id": "ARS-1.0-41",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-idempotency-keys",
        "ev-incident-taxonomy",
        "ev-review-board-package"
      ],
      "evidence_retained": [
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retention-covers-artifacts",
        "ev-retry-and-loop-bounds",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-08",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-09",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-10",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-18",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-19",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-22",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-34",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-37",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": true
        },
        {
          "control_id": "ARS-41",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [
        {
          "test_id": "tool-behaviour:send-customer-email",
          "change_id": "destructive_action_added:send-customer-email",
          "what": "Exercise send-customer-email against its declared input schema, including the boundary and rejection cases."
        },
        {
          "test_id": "injection-reaches-tool:send-customer-email",
          "change_id": "destructive_action_added:send-customer-email",
          "what": "Attempt to reach send-customer-email through content the agent did not author, and confirm it is refused where the declaration says it should be."
        }
      ],
      "reviews_required": [
        {
          "review_id": "destructive-action-review:send-customer-email",
          "change_id": "destructive_action_added:send-customer-email",
          "role": "Head of Customer Operations Engineering",
          "what": "Approve the addition of an action that act, and record its compensating action."
        }
      ],
      "deployment_blocking": false
    },
    {
      "change_id": "destructive_action_added:send-email",
      "category": "destructive_action_added",
      "domain": "tools",
      "subject": "send-email",
      "severity": "critical",
      "authority_expanding": true,
      "before": null,
      "after": {
        "path": "tools[send-email]/side_effect",
        "value": "send"
      },
      "explanation": "the agent can now create, modify, delete, send or spend where it previously could not. send-email is classified send, so the agent can now transmit to recipients where it previously could not.",
      "claims": [
        "tools[send-email]/side_effect"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-08",
        "ARS-09",
        "ARS-10",
        "ARS-18",
        "ARS-19",
        "ARS-22",
        "ARS-34",
        "ARS-37",
        "ARS-41"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-08",
          "citation_id": "ARS-1.0-08",
          "applicability": true
        },
        {
          "control_id": "ARS-09",
          "citation_id": "ARS-1.0-09",
          "applicability": true
        },
        {
          "control_id": "ARS-10",
          "citation_id": "ARS-1.0-10",
          "applicability": true
        },
        {
          "control_id": "ARS-18",
          "citation_id": "ARS-1.0-18",
          "applicability": true
        },
        {
          "control_id": "ARS-19",
          "citation_id": "ARS-1.0-19",
          "applicability": true
        },
        {
          "control_id": "ARS-22",
          "citation_id": "ARS-1.0-22",
          "applicability": true
        },
        {
          "control_id": "ARS-34",
          "citation_id": "ARS-1.0-34",
          "applicability": true
        },
        {
          "control_id": "ARS-37",
          "citation_id": "ARS-1.0-37",
          "applicability": true
        },
        {
          "control_id": "ARS-41",
          "citation_id": "ARS-1.0-41",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-idempotency-keys",
        "ev-incident-taxonomy",
        "ev-review-board-package"
      ],
      "evidence_retained": [
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retention-covers-artifacts",
        "ev-retry-and-loop-bounds",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-08",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-09",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-10",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-18",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-19",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-22",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-34",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-37",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": true
        },
        {
          "control_id": "ARS-41",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [
        {
          "test_id": "tool-behaviour:send-email",
          "change_id": "destructive_action_added:send-email",
          "what": "Exercise send-email against its declared input schema, including the boundary and rejection cases."
        },
        {
          "test_id": "injection-reaches-tool:send-email",
          "change_id": "destructive_action_added:send-email",
          "what": "Attempt to reach send-email through content the agent did not author, and confirm it is refused where the declaration says it should be."
        }
      ],
      "reviews_required": [
        {
          "review_id": "destructive-action-review:send-email",
          "change_id": "destructive_action_added:send-email",
          "role": "Head of Customer Operations Engineering",
          "what": "Approve the addition of an action that transmit to recipients, and record its compensating action."
        }
      ],
      "deployment_blocking": false
    },
    {
      "change_id": "external_destination_added:mail-relay.internal.acme.example/transactional",
      "category": "external_destination_added",
      "domain": "data_sinks",
      "subject": "mail-relay.internal.acme.example/transactional",
      "severity": "critical",
      "authority_expanding": true,
      "before": null,
      "after": {
        "path": "data_sinks[customer-mailbox]/permitted_destinations",
        "value": "mail-relay.internal.acme.example/transactional"
      },
      "explanation": "the agent may send data somewhere it previously could not — a new path out. A new external sink customer-mailbox may reach mail-relay.internal.acme.example/transactional, carrying [personal_data].",
      "claims": [
        "data_sinks[customer-mailbox]"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-12",
        "ARS-14",
        "ARS-25",
        "ARS-26",
        "ARS-27",
        "ARS-32",
        "ARS-36",
        "ARS-37",
        "ARS-40"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-12",
          "citation_id": "ARS-1.0-12",
          "applicability": true
        },
        {
          "control_id": "ARS-14",
          "citation_id": "ARS-1.0-14",
          "applicability": true
        },
        {
          "control_id": "ARS-25",
          "citation_id": "ARS-1.0-25",
          "applicability": true
        },
        {
          "control_id": "ARS-26",
          "citation_id": "ARS-1.0-26",
          "applicability": true
        },
        {
          "control_id": "ARS-27",
          "citation_id": "ARS-1.0-27",
          "applicability": true
        },
        {
          "control_id": "ARS-32",
          "citation_id": "ARS-1.0-32",
          "applicability": true
        },
        {
          "control_id": "ARS-36",
          "citation_id": "ARS-1.0-36",
          "applicability": true
        },
        {
          "control_id": "ARS-37",
          "citation_id": "ARS-1.0-37",
          "applicability": true
        },
        {
          "control_id": "ARS-40",
          "citation_id": "ARS-1.0-40",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-correlation-ids",
        "ev-cross-tool-flow-policy",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts"
      ],
      "evidence_retained": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-cost-attribution",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-12",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-14",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-25",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-26",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-27",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-32",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-36",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-37",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": true
        },
        {
          "control_id": "ARS-40",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [
        {
          "test_id": "exfiltration-path:mail-relay.internal.acme.example/transactional",
          "change_id": "external_destination_added:mail-relay.internal.acme.example/transactional",
          "what": "Attempt to move data to mail-relay.internal.acme.example/transactional through injected content, and confirm the path is constrained as declared."
        },
        {
          "test_id": "destination-allowlist:mail-relay.internal.acme.example/transactional",
          "change_id": "external_destination_added:mail-relay.internal.acme.example/transactional",
          "what": "Confirm the destination allowlist is enforced at the call site rather than only declared."
        }
      ],
      "reviews_required": [
        {
          "review_id": "data-flow-review:mail-relay.internal.acme.example/transactional",
          "change_id": "external_destination_added:mail-relay.internal.acme.example/transactional",
          "role": "Data protection reviewer",
          "what": "Approve the path by which data may now reach mail-relay.internal.acme.example/transactional, and record what may travel it."
        }
      ],
      "deployment_blocking": false
    },
    {
      "change_id": "external_destination_added:notifications.vendor.example/dispatch",
      "category": "external_destination_added",
      "domain": "data_sinks",
      "subject": "notifications.vendor.example/dispatch",
      "severity": "critical",
      "authority_expanding": true,
      "before": null,
      "after": {
        "path": "data_sinks[customer-mailbox]/permitted_destinations",
        "value": "notifications.vendor.example/dispatch"
      },
      "explanation": "the agent may send data somewhere it previously could not — a new path out. A new external sink customer-mailbox may reach notifications.vendor.example/dispatch, carrying [personal_data].",
      "claims": [
        "data_sinks[customer-mailbox]"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-12",
        "ARS-14",
        "ARS-25",
        "ARS-26",
        "ARS-27",
        "ARS-32",
        "ARS-36",
        "ARS-37",
        "ARS-40"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-12",
          "citation_id": "ARS-1.0-12",
          "applicability": true
        },
        {
          "control_id": "ARS-14",
          "citation_id": "ARS-1.0-14",
          "applicability": true
        },
        {
          "control_id": "ARS-25",
          "citation_id": "ARS-1.0-25",
          "applicability": true
        },
        {
          "control_id": "ARS-26",
          "citation_id": "ARS-1.0-26",
          "applicability": true
        },
        {
          "control_id": "ARS-27",
          "citation_id": "ARS-1.0-27",
          "applicability": true
        },
        {
          "control_id": "ARS-32",
          "citation_id": "ARS-1.0-32",
          "applicability": true
        },
        {
          "control_id": "ARS-36",
          "citation_id": "ARS-1.0-36",
          "applicability": true
        },
        {
          "control_id": "ARS-37",
          "citation_id": "ARS-1.0-37",
          "applicability": true
        },
        {
          "control_id": "ARS-40",
          "citation_id": "ARS-1.0-40",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-correlation-ids",
        "ev-cross-tool-flow-policy",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts"
      ],
      "evidence_retained": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-cost-attribution",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-12",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-14",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-25",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-26",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-27",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-32",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-36",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-37",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": true
        },
        {
          "control_id": "ARS-40",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [
        {
          "test_id": "exfiltration-path:notifications.vendor.example/dispatch",
          "change_id": "external_destination_added:notifications.vendor.example/dispatch",
          "what": "Attempt to move data to notifications.vendor.example/dispatch through injected content, and confirm the path is constrained as declared."
        },
        {
          "test_id": "destination-allowlist:notifications.vendor.example/dispatch",
          "change_id": "external_destination_added:notifications.vendor.example/dispatch",
          "what": "Confirm the destination allowlist is enforced at the call site rather than only declared."
        }
      ],
      "reviews_required": [
        {
          "review_id": "data-flow-review:notifications.vendor.example/dispatch",
          "change_id": "external_destination_added:notifications.vendor.example/dispatch",
          "role": "Data protection reviewer",
          "what": "Approve the path by which data may now reach notifications.vendor.example/dispatch, and record what may travel it."
        }
      ],
      "deployment_blocking": false
    },
    {
      "change_id": "outbound_transmission_added:send-email",
      "category": "outbound_transmission_added",
      "domain": "tools",
      "subject": "send-email",
      "severity": "critical",
      "authority_expanding": true,
      "before": null,
      "after": {
        "path": "tools[send-email]/outbound_transmission",
        "value": true
      },
      "explanation": "a tool can now carry content out of the trust boundary — a path by which data leaves. send-email can carry content out of the trust boundary.",
      "claims": [
        "tools[send-email]/outbound_transmission"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-12",
        "ARS-19",
        "ARS-22",
        "ARS-25",
        "ARS-26",
        "ARS-27",
        "ARS-37"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-12",
          "citation_id": "ARS-1.0-12",
          "applicability": true
        },
        {
          "control_id": "ARS-19",
          "citation_id": "ARS-1.0-19",
          "applicability": true
        },
        {
          "control_id": "ARS-22",
          "citation_id": "ARS-1.0-22",
          "applicability": true
        },
        {
          "control_id": "ARS-25",
          "citation_id": "ARS-1.0-25",
          "applicability": true
        },
        {
          "control_id": "ARS-26",
          "citation_id": "ARS-1.0-26",
          "applicability": true
        },
        {
          "control_id": "ARS-27",
          "citation_id": "ARS-1.0-27",
          "applicability": true
        },
        {
          "control_id": "ARS-37",
          "citation_id": "ARS-1.0-37",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-cross-tool-flow-policy",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-incident-taxonomy",
        "ev-injection-suite-run"
      ],
      "evidence_retained": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-feedback-loop-instrumented",
        "ev-identity-propagation-trace",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retention-covers-artifacts",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-12",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-19",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-22",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-25",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-26",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-27",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-37",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": true
        }
      ],
      "tests_required": [
        {
          "test_id": "exfiltration-path:send-email",
          "change_id": "outbound_transmission_added:send-email",
          "what": "Attempt to move data to send-email through injected content, and confirm the path is constrained as declared."
        },
        {
          "test_id": "destination-allowlist:send-email",
          "change_id": "outbound_transmission_added:send-email",
          "what": "Confirm the destination allowlist is enforced at the call site rather than only declared."
        }
      ],
      "reviews_required": [
        {
          "review_id": "data-flow-review:send-email",
          "change_id": "outbound_transmission_added:send-email",
          "role": "Data protection reviewer",
          "what": "Approve the path by which data may now reach send-email, and record what may travel it."
        }
      ],
      "deployment_blocking": false
    },
    {
      "change_id": "permission_expanded:lookup-customer",
      "category": "permission_expanded",
      "domain": "permissions",
      "subject": "lookup-customer",
      "severity": "high",
      "authority_expanding": true,
      "before": {
        "path": "tools[lookup-customer]/required_scopes",
        "value": [
          "customers.read",
          "customers.pii.read"
        ]
      },
      "after": {
        "path": "tools[lookup-customer]/required_scopes",
        "value": [
          "customers.read",
          "customers.pii.read",
          "customers.read.all"
        ]
      },
      "explanation": "the agent holds authority it did not hold, so the set of things reachable through a prompt injection is larger. lookup-customer gained [customers.read.all]. Everything reachable through that scope is now reachable through a prompt injection.",
      "claims": [
        "tools[lookup-customer]/required_scopes"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-01",
        "ARS-02",
        "ARS-11",
        "ARS-13",
        "ARS-22",
        "ARS-25",
        "ARS-27",
        "ARS-29",
        "ARS-38",
        "ARS-39"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-01",
          "citation_id": "ARS-1.0-01",
          "applicability": true
        },
        {
          "control_id": "ARS-02",
          "citation_id": "ARS-1.0-02",
          "applicability": true
        },
        {
          "control_id": "ARS-11",
          "citation_id": "ARS-1.0-11",
          "applicability": true
        },
        {
          "control_id": "ARS-13",
          "citation_id": "ARS-1.0-13",
          "applicability": true
        },
        {
          "control_id": "ARS-22",
          "citation_id": "ARS-1.0-22",
          "applicability": true
        },
        {
          "control_id": "ARS-25",
          "citation_id": "ARS-1.0-25",
          "applicability": true
        },
        {
          "control_id": "ARS-27",
          "citation_id": "ARS-1.0-27",
          "applicability": true
        },
        {
          "control_id": "ARS-29",
          "citation_id": "ARS-1.0-29",
          "applicability": true
        },
        {
          "control_id": "ARS-38",
          "citation_id": "ARS-1.0-38",
          "applicability": true
        },
        {
          "control_id": "ARS-39",
          "citation_id": "ARS-1.0-39",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-audit-plane-immutable",
        "ev-exfiltration-channels-enumerated",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe"
      ],
      "evidence_retained": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-identity-separated",
        "ev-budget-ceilings",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-incident-taxonomy",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retention-covers-artifacts",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-01",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-02",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-11",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-13",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-22",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-25",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-27",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-29",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-38",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-39",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [
        {
          "test_id": "scope-exercised:lookup-customer",
          "change_id": "permission_expanded:lookup-customer",
          "what": "Confirm every scope now held by lookup-customer is exercised by its declared function, and that nothing it does not need remains granted."
        },
        {
          "test_id": "scope-blast-radius:lookup-customer",
          "change_id": "permission_expanded:lookup-customer",
          "what": "Establish what the newly granted authority can reach, and confirm nothing outside the declared blast radius is reachable through it."
        }
      ],
      "reviews_required": [
        {
          "review_id": "authorisation-review:lookup-customer",
          "change_id": "permission_expanded:lookup-customer",
          "role": "Security review board",
          "what": "Approve the expanded authority on lookup-customer, or narrow it."
        }
      ],
      "deployment_blocking": false
    },
    {
      "change_id": "skill_added:customer-correspondence",
      "category": "skill_added",
      "domain": "skills",
      "subject": "customer-correspondence",
      "severity": "high",
      "authority_expanding": true,
      "before": null,
      "after": {
        "path": "skills[customer-correspondence]",
        "value": {
          "skill_id": "customer-correspondence",
          "purpose": "Send a reply to the customer directly, rather than drafting it into the ticket for a person to send.",
          "data_classes": [
            "personal_data"
          ],
          "side_effects": [
            "send"
          ],
          "required_permissions": [
            "email.send"
          ]
        }
      },
      "explanation": "the agent was given a capability it did not previously declare. Skill customer-correspondence was added, declaring side effects [send] over data classes [personal_data].",
      "claims": [
        "skills[customer-correspondence]"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-02",
        "ARS-08",
        "ARS-15",
        "ARS-21",
        "ARS-22",
        "ARS-24",
        "ARS-26",
        "ARS-27",
        "ARS-29",
        "ARS-31",
        "ARS-33",
        "ARS-34",
        "ARS-35",
        "ARS-36",
        "ARS-38",
        "ARS-39",
        "ARS-40"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-02",
          "citation_id": "ARS-1.0-02",
          "applicability": true
        },
        {
          "control_id": "ARS-08",
          "citation_id": "ARS-1.0-08",
          "applicability": true
        },
        {
          "control_id": "ARS-15",
          "citation_id": "ARS-1.0-15",
          "applicability": true
        },
        {
          "control_id": "ARS-21",
          "citation_id": "ARS-1.0-21",
          "applicability": true
        },
        {
          "control_id": "ARS-22",
          "citation_id": "ARS-1.0-22",
          "applicability": true
        },
        {
          "control_id": "ARS-24",
          "citation_id": "ARS-1.0-24",
          "applicability": true
        },
        {
          "control_id": "ARS-26",
          "citation_id": "ARS-1.0-26",
          "applicability": true
        },
        {
          "control_id": "ARS-27",
          "citation_id": "ARS-1.0-27",
          "applicability": true
        },
        {
          "control_id": "ARS-29",
          "citation_id": "ARS-1.0-29",
          "applicability": true
        },
        {
          "control_id": "ARS-31",
          "citation_id": "ARS-1.0-31",
          "applicability": true
        },
        {
          "control_id": "ARS-33",
          "citation_id": "ARS-1.0-33",
          "applicability": true
        },
        {
          "control_id": "ARS-34",
          "citation_id": "ARS-1.0-34",
          "applicability": true
        },
        {
          "control_id": "ARS-35",
          "citation_id": "ARS-1.0-35",
          "applicability": true
        },
        {
          "control_id": "ARS-36",
          "citation_id": "ARS-1.0-36",
          "applicability": true
        },
        {
          "control_id": "ARS-38",
          "citation_id": "ARS-1.0-38",
          "applicability": true
        },
        {
          "control_id": "ARS-39",
          "citation_id": "ARS-1.0-39",
          "applicability": true
        },
        {
          "control_id": "ARS-40",
          "citation_id": "ARS-1.0-40",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-cost-attribution",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "evidence_retained": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-correlation-ids",
        "ev-cross-tool-flow-policy",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-02",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-08",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-15",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-21",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-22",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-24",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-26",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-27",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-29",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-31",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-33",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-34",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-35",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-36",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-38",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-39",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-40",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [],
      "reviews_required": [],
      "deployment_blocking": false
    },
    {
      "change_id": "tool_added:send-email",
      "category": "tool_added",
      "domain": "tools",
      "subject": "send-email",
      "severity": "high",
      "authority_expanding": true,
      "before": null,
      "after": {
        "path": "tools[send-email]",
        "value": {
          "side_effect": "send",
          "required_scopes": [
            "email.send"
          ],
          "approval": "human_approval_conditional"
        }
      },
      "explanation": "the agent can take an action it previously could not. Tool send-email (send_email) was added, classified send, gated at human_approval_conditional, holding [email.send].",
      "claims": [
        "tools[send-email]"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-01",
        "ARS-02",
        "ARS-04",
        "ARS-06",
        "ARS-07",
        "ARS-08",
        "ARS-09",
        "ARS-10",
        "ARS-11",
        "ARS-12",
        "ARS-14",
        "ARS-16",
        "ARS-18",
        "ARS-19",
        "ARS-21",
        "ARS-22",
        "ARS-23",
        "ARS-24",
        "ARS-25",
        "ARS-26",
        "ARS-27",
        "ARS-29",
        "ARS-31",
        "ARS-32",
        "ARS-33",
        "ARS-34",
        "ARS-35",
        "ARS-38",
        "ARS-39"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-01",
          "citation_id": "ARS-1.0-01",
          "applicability": true
        },
        {
          "control_id": "ARS-02",
          "citation_id": "ARS-1.0-02",
          "applicability": true
        },
        {
          "control_id": "ARS-04",
          "citation_id": "ARS-1.0-04",
          "applicability": true
        },
        {
          "control_id": "ARS-06",
          "citation_id": "ARS-1.0-06",
          "applicability": true
        },
        {
          "control_id": "ARS-07",
          "citation_id": "ARS-1.0-07",
          "applicability": true
        },
        {
          "control_id": "ARS-08",
          "citation_id": "ARS-1.0-08",
          "applicability": true
        },
        {
          "control_id": "ARS-09",
          "citation_id": "ARS-1.0-09",
          "applicability": true
        },
        {
          "control_id": "ARS-10",
          "citation_id": "ARS-1.0-10",
          "applicability": true
        },
        {
          "control_id": "ARS-11",
          "citation_id": "ARS-1.0-11",
          "applicability": true
        },
        {
          "control_id": "ARS-12",
          "citation_id": "ARS-1.0-12",
          "applicability": true
        },
        {
          "control_id": "ARS-14",
          "citation_id": "ARS-1.0-14",
          "applicability": true
        },
        {
          "control_id": "ARS-16",
          "citation_id": "ARS-1.0-16",
          "applicability": true
        },
        {
          "control_id": "ARS-18",
          "citation_id": "ARS-1.0-18",
          "applicability": true
        },
        {
          "control_id": "ARS-19",
          "citation_id": "ARS-1.0-19",
          "applicability": true
        },
        {
          "control_id": "ARS-21",
          "citation_id": "ARS-1.0-21",
          "applicability": true
        },
        {
          "control_id": "ARS-22",
          "citation_id": "ARS-1.0-22",
          "applicability": true
        },
        {
          "control_id": "ARS-23",
          "citation_id": "ARS-1.0-23",
          "applicability": true
        },
        {
          "control_id": "ARS-24",
          "citation_id": "ARS-1.0-24",
          "applicability": true
        },
        {
          "control_id": "ARS-25",
          "citation_id": "ARS-1.0-25",
          "applicability": true
        },
        {
          "control_id": "ARS-26",
          "citation_id": "ARS-1.0-26",
          "applicability": true
        },
        {
          "control_id": "ARS-27",
          "citation_id": "ARS-1.0-27",
          "applicability": true
        },
        {
          "control_id": "ARS-29",
          "citation_id": "ARS-1.0-29",
          "applicability": true
        },
        {
          "control_id": "ARS-31",
          "citation_id": "ARS-1.0-31",
          "applicability": true
        },
        {
          "control_id": "ARS-32",
          "citation_id": "ARS-1.0-32",
          "applicability": true
        },
        {
          "control_id": "ARS-33",
          "citation_id": "ARS-1.0-33",
          "applicability": true
        },
        {
          "control_id": "ARS-34",
          "citation_id": "ARS-1.0-34",
          "applicability": true
        },
        {
          "control_id": "ARS-35",
          "citation_id": "ARS-1.0-35",
          "applicability": true
        },
        {
          "control_id": "ARS-38",
          "citation_id": "ARS-1.0-38",
          "applicability": true
        },
        {
          "control_id": "ARS-39",
          "citation_id": "ARS-1.0-39",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "evidence_retained": [
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-feedback-loop-instrumented",
        "ev-incident-taxonomy",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retention-covers-artifacts",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-supply-chain-pinned",
        "ev-trace-retention-acl"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-01",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-02",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-04",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-06",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-07",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-08",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-09",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-10",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-11",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-12",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-14",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-16",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-18",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-19",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-21",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-22",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-23",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-24",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-25",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-26",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-27",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-29",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-31",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-32",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-33",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-34",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-35",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-38",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-39",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [
        {
          "test_id": "tool-behaviour:send-email",
          "change_id": "tool_added:send-email",
          "what": "Exercise send-email against its declared input schema, including the boundary and rejection cases."
        },
        {
          "test_id": "injection-reaches-tool:send-email",
          "change_id": "tool_added:send-email",
          "what": "Attempt to reach send-email through content the agent did not author, and confirm it is refused where the declaration says it should be."
        }
      ],
      "reviews_required": [],
      "deployment_blocking": false
    },
    {
      "change_id": "model_changed:primary-reasoner",
      "category": "model_changed",
      "domain": "models",
      "subject": "primary-reasoner",
      "severity": "moderate",
      "authority_expanding": false,
      "before": {
        "path": "models[primary-reasoner]",
        "value": {
          "identifier": "claude-sonnet-4-5-20250929",
          "version": "20250929"
        }
      },
      "after": {
        "path": "models[primary-reasoner]",
        "value": {
          "identifier": "claude-sonnet-4-6-20260401",
          "version": "20260401"
        }
      },
      "explanation": "the model behind a logical role is not the model the evaluations were run against. Role primary-reasoner moved from claude-sonnet-4-5-20250929@20250929 to claude-sonnet-4-6-20260401@20260401.",
      "claims": [
        "models[primary-reasoner]/identifier",
        "models[primary-reasoner]/version"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-15",
        "ARS-16",
        "ARS-21",
        "ARS-25",
        "ARS-28",
        "ARS-31",
        "ARS-35"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-15",
          "citation_id": "ARS-1.0-15",
          "applicability": true
        },
        {
          "control_id": "ARS-16",
          "citation_id": "ARS-1.0-16",
          "applicability": true
        },
        {
          "control_id": "ARS-21",
          "citation_id": "ARS-1.0-21",
          "applicability": true
        },
        {
          "control_id": "ARS-25",
          "citation_id": "ARS-1.0-25",
          "applicability": true
        },
        {
          "control_id": "ARS-28",
          "citation_id": "ARS-1.0-28",
          "applicability": true
        },
        {
          "control_id": "ARS-31",
          "citation_id": "ARS-1.0-31",
          "applicability": true
        },
        {
          "control_id": "ARS-35",
          "citation_id": "ARS-1.0-35",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-cost-attribution",
        "ev-injection-suite-run",
        "ev-supply-chain-pinned",
        "ev-trace-retention-acl"
      ],
      "evidence_retained": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-correlation-ids",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retention-covers-artifacts",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-15",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-16",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-21",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-25",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-28",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-31",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        },
        {
          "control_id": "ARS-35",
          "accepted_kinds": [
            "automatically_verified",
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [
        {
          "test_id": "eval-suite:primary-reasoner",
          "change_id": "model_changed:primary-reasoner",
          "what": "Re-run the versioned evaluation suite against the model now in use."
        }
      ],
      "reviews_required": [],
      "deployment_blocking": false
    },
    {
      "change_id": "approval_strengthened:class_customer-facing-send",
      "category": "approval_strengthened",
      "domain": "autonomy",
      "subject": "class:customer-facing-send",
      "severity": "informational",
      "authority_expanding": false,
      "before": {
        "path": "autonomy/approval_classes[customer-facing-send]/applies_to",
        "value": [
          "draft-reply"
        ]
      },
      "after": {
        "path": "autonomy/approval_classes[customer-facing-send]/applies_to",
        "value": [
          "draft-reply",
          "send-email"
        ]
      },
      "explanation": "an action now needs more human authority than it did. Approval class customer-facing-send now also covers [send-email].",
      "claims": [
        "autonomy/approval_classes[customer-facing-send]/applies_to"
      ],
      "observed_support": [],
      "affected_controls": [
        "ARS-10"
      ],
      "affected_control_detail": [
        {
          "control_id": "ARS-10",
          "citation_id": "ARS-1.0-10",
          "applicability": true
        }
      ],
      "evidence_invalidated": [
        "ev-approval-volume-measured"
      ],
      "evidence_retained": [
        "ev-approval-gate-enforced",
        "ev-audit-identity-separated",
        "ev-audit-plane-immutable",
        "ev-budget-ceilings",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-no-secrets-in-prompts",
        "ev-prompt-config-versioned",
        "ev-retention-covers-artifacts",
        "ev-retry-and-loop-bounds",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "new_evidence_required": [
        {
          "control_id": "ARS-10",
          "accepted_kinds": [
            "manually_verified",
            "attested"
          ],
          "attestation_alone_sufficient": false
        }
      ],
      "tests_required": [],
      "reviews_required": [],
      "deployment_blocking": false
    }
  ],
  "structural_diff": {
    "note": "A faithful record of every path that changed. It is retained BECAUSE it is faithful — it is what the semantic layer above is checked against — and it is not the answer to any question a release board asks.",
    "changed_paths": 12,
    "entries": [
      {
        "path": "autonomy/approval_classes[customer-facing-send]/applies_to",
        "kind": "modified",
        "before": [
          "draft-reply"
        ],
        "after": [
          "draft-reply",
          "send-email"
        ]
      },
      {
        "path": "autonomy/destructive_action_inventory[send-customer-email]",
        "kind": "added",
        "before": null,
        "after": {
          "action_id": "send-customer-email",
          "tool_id": "send-email",
          "classification": "irreversible",
          "gate": "human_approval"
        }
      },
      {
        "path": "data_sinks[customer-mailbox]",
        "kind": "added",
        "before": null,
        "after": {
          "sink_id": "customer-mailbox",
          "direction": "outbound",
          "data_classifications": [
            "personal_data"
          ],
          "external": true,
          "permitted_destinations": [
            "mail-relay.internal.acme.example/transactional",
            "notifications.vendor.example/dispatch"
          ]
        }
      },
      {
        "path": "identity/agent_version",
        "kind": "modified",
        "before": "1.4.2",
        "after": "1.5.0"
      },
      {
        "path": "identity/repository/revision",
        "kind": "modified",
        "before": "v1.4.2",
        "after": "v1.5.0"
      },
      {
        "path": "models[primary-reasoner]/identifier",
        "kind": "modified",
        "before": "claude-sonnet-4-5-20250929",
        "after": "claude-sonnet-4-6-20260401"
      },
      {
        "path": "models[primary-reasoner]/version",
        "kind": "modified",
        "before": "20250929",
        "after": "20260401"
      },
      {
        "path": "skills[customer-correspondence]",
        "kind": "added",
        "before": null,
        "after": {
          "skill_id": "customer-correspondence",
          "purpose": "Send a reply to the customer directly, rather than drafting it into the ticket for a person to send.",
          "data_classes": [
            "personal_data"
          ],
          "side_effects": [
            "send"
          ],
          "required_permissions": [
            "email.send"
          ]
        }
      },
      {
        "path": "tools[draft-reply]/approval/condition",
        "kind": "modified",
        "before": null,
        "after": "Required only when the draft quotes content the agent did not author."
      },
      {
        "path": "tools[draft-reply]/approval/policy",
        "kind": "modified",
        "before": "human_approval",
        "after": "human_approval_conditional"
      },
      {
        "path": "tools[lookup-customer]/required_scopes",
        "kind": "modified",
        "before": [
          "customers.pii.read",
          "customers.read"
        ],
        "after": [
          "customers.pii.read",
          "customers.read",
          "customers.read.all"
        ]
      },
      {
        "path": "tools[send-email]",
        "kind": "added",
        "before": null,
        "after": {
          "tool_id": "send-email",
          "display_name": "send_email",
          "aliases": [],
          "side_effect": "send",
          "input_schema_ref": "tools.json#/tools/5/input_schema",
          "outbound_transmission": true,
          "auth_mechanism": "workload_identity_federation",
          "effective_principal": "end_user",
          "required_scopes": [
            "email.send"
          ],
          "approval": {
            "policy": "human_approval_conditional",
            "approval_class": "customer-facing-send",
            "condition": "Required only when the recipient address is not the customer of record on the ticket."
          },
          "idempotent": true,
          "timeout_ms": 120000,
          "retry": {
            "max_attempts": 3,
            "backoff": "exponential"
          },
          "environments_allowed": [
            "development",
            "staging",
            "production"
          ],
          "dynamic_loading_allowed": false
        }
      }
    ],
    "cosmetic": [
      {
        "path": "identity/agent_version",
        "why": "the version label itself — the changes it labels are what this artifact is about"
      },
      {
        "path": "identity/repository/revision",
        "why": "where the code lives"
      }
    ],
    "cosmetic_allowlist": [
      {
        "pattern": "/^identity\\/display_name$/",
        "why": "a human-readable name; identity is by agent_id"
      },
      {
        "pattern": "/^identity\\/business_purpose$/",
        "why": "prose describing what the agent is for"
      },
      {
        "pattern": "/^identity\\/owner\\//",
        "why": "who to contact; changes accountability records, not what the agent may do"
      },
      {
        "pattern": "/^identity\\/repository\\//",
        "why": "where the code lives"
      },
      {
        "pattern": "/^identity\\/agent_version$/",
        "why": "the version label itself — the changes it labels are what this artifact is about"
      },
      {
        "pattern": "/^skills\\[[^\\]]*\\]\\/purpose$/",
        "why": "prose describing a skill"
      },
      {
        "pattern": "/^prompts\\[[^\\]]*\\]\\/purpose$/",
        "why": "prose describing a prompt"
      },
      {
        "pattern": "/^prompts\\[[^\\]]*\\]\\/source_location$/",
        "why": "where a prompt file lives; the content hash is what says whether it changed"
      },
      {
        "pattern": "/^tools\\[[^\\]]*\\]\\/display_name$/",
        "why": "a human-readable tool name; identity is by tool_id"
      },
      {
        "pattern": "/^models\\[[^\\]]*\\]\\/role$/",
        "why": "the logical name for what a model does"
      },
      {
        "pattern": "/^autonomy\\/approval_classes\\[[^\\]]*\\]\\/description$/",
        "why": "prose describing an approval class"
      },
      {
        "pattern": "/^autonomy\\/maximum_plausible_blast_radius\\/description$/",
        "why": "prose describing a blast radius; the scope and ceiling are the claim"
      }
    ],
    "unclaimed_paths": []
  },
  "evidence": {
    "ledger_present": true,
    "ledger_size": 29,
    "invalidated": [
      "ev-approval-gate-enforced",
      "ev-approval-volume-measured",
      "ev-audit-plane-immutable",
      "ev-correlation-ids",
      "ev-cost-attribution",
      "ev-cross-tool-flow-policy",
      "ev-destructive-inventory-complete",
      "ev-eval-covers-destructive",
      "ev-eval-suite-versioned",
      "ev-exfiltration-channels-enumerated",
      "ev-feedback-loop-instrumented",
      "ev-idempotency-keys",
      "ev-identity-propagation-trace",
      "ev-incident-taxonomy",
      "ev-injection-suite-run",
      "ev-retention-covers-artifacts",
      "ev-review-board-package",
      "ev-scope-minimality-review",
      "ev-scope-static-scan",
      "ev-server-side-authz-probe",
      "ev-supply-chain-pinned",
      "ev-timeout-discipline",
      "ev-trace-retention-acl",
      "ev-untrusted-segregation"
    ],
    "retained": [
      "ev-audit-identity-separated",
      "ev-budget-ceilings",
      "ev-no-secrets-in-prompts",
      "ev-prompt-config-versioned",
      "ev-retry-and-loop-bounds"
    ],
    "retention_note": "Retained evidence survives BY IDENTITY. An item is retained exactly when its stable id is in the prior ledger and in no invalidation set. It is never re-derived and never re-checked here: a second pass that concluded an item \"still looks fine\" would let a bug in the invalidation mapping quietly restore evidence it had just invalidated."
  },
  "required_tests": [
    {
      "test_id": "destination-allowlist:mail-relay.internal.acme.example/transactional",
      "change_id": "external_destination_added:mail-relay.internal.acme.example/transactional",
      "what": "Confirm the destination allowlist is enforced at the call site rather than only declared."
    },
    {
      "test_id": "destination-allowlist:notifications.vendor.example/dispatch",
      "change_id": "external_destination_added:notifications.vendor.example/dispatch",
      "what": "Confirm the destination allowlist is enforced at the call site rather than only declared."
    },
    {
      "test_id": "destination-allowlist:send-email",
      "change_id": "outbound_transmission_added:send-email",
      "what": "Confirm the destination allowlist is enforced at the call site rather than only declared."
    },
    {
      "test_id": "eval-suite:primary-reasoner",
      "change_id": "model_changed:primary-reasoner",
      "what": "Re-run the versioned evaluation suite against the model now in use."
    },
    {
      "test_id": "exfiltration-path:mail-relay.internal.acme.example/transactional",
      "change_id": "external_destination_added:mail-relay.internal.acme.example/transactional",
      "what": "Attempt to move data to mail-relay.internal.acme.example/transactional through injected content, and confirm the path is constrained as declared."
    },
    {
      "test_id": "exfiltration-path:notifications.vendor.example/dispatch",
      "change_id": "external_destination_added:notifications.vendor.example/dispatch",
      "what": "Attempt to move data to notifications.vendor.example/dispatch through injected content, and confirm the path is constrained as declared."
    },
    {
      "test_id": "exfiltration-path:send-email",
      "change_id": "outbound_transmission_added:send-email",
      "what": "Attempt to move data to send-email through injected content, and confirm the path is constrained as declared."
    },
    {
      "test_id": "gate-bypass:draft-reply",
      "change_id": "approval_weakened:draft-reply",
      "what": "Attempt to reach draft-reply without the approval the declaration now requires."
    },
    {
      "test_id": "gate-enforced:draft-reply",
      "change_id": "approval_weakened:draft-reply",
      "what": "Confirm the approval path that remains on draft-reply is enforced server-side, not only in the client."
    },
    {
      "test_id": "injection-reaches-tool:send-customer-email",
      "change_id": "destructive_action_added:send-customer-email",
      "what": "Attempt to reach send-customer-email through content the agent did not author, and confirm it is refused where the declaration says it should be."
    },
    {
      "test_id": "injection-reaches-tool:send-email",
      "change_id": "destructive_action_added:send-email",
      "what": "Attempt to reach send-email through content the agent did not author, and confirm it is refused where the declaration says it should be."
    },
    {
      "test_id": "scope-blast-radius:lookup-customer",
      "change_id": "permission_expanded:lookup-customer",
      "what": "Establish what the newly granted authority can reach, and confirm nothing outside the declared blast radius is reachable through it."
    },
    {
      "test_id": "scope-exercised:lookup-customer",
      "change_id": "permission_expanded:lookup-customer",
      "what": "Confirm every scope now held by lookup-customer is exercised by its declared function, and that nothing it does not need remains granted."
    },
    {
      "test_id": "tool-behaviour:send-customer-email",
      "change_id": "destructive_action_added:send-customer-email",
      "what": "Exercise send-customer-email against its declared input schema, including the boundary and rejection cases."
    },
    {
      "test_id": "tool-behaviour:send-email",
      "change_id": "destructive_action_added:send-email",
      "what": "Exercise send-email against its declared input schema, including the boundary and rejection cases."
    }
  ],
  "required_reviews": [
    {
      "review_id": "approval-design-review:draft-reply",
      "change_id": "approval_weakened:draft-reply",
      "role": "Security review board",
      "what": "Confirm the remaining gate is proportionate to the action's blast radius."
    },
    {
      "review_id": "approval-owner-review:draft-reply",
      "change_id": "approval_weakened:draft-reply",
      "role": "Head of Customer Operations Engineering",
      "what": "Accept, in writing, that draft-reply may now act with less human involvement than the previous release required."
    },
    {
      "review_id": "authorisation-review:lookup-customer",
      "change_id": "permission_expanded:lookup-customer",
      "role": "Security review board",
      "what": "Approve the expanded authority on lookup-customer, or narrow it."
    },
    {
      "review_id": "data-flow-review:mail-relay.internal.acme.example/transactional",
      "change_id": "external_destination_added:mail-relay.internal.acme.example/transactional",
      "role": "Data protection reviewer",
      "what": "Approve the path by which data may now reach mail-relay.internal.acme.example/transactional, and record what may travel it."
    },
    {
      "review_id": "data-flow-review:notifications.vendor.example/dispatch",
      "change_id": "external_destination_added:notifications.vendor.example/dispatch",
      "role": "Data protection reviewer",
      "what": "Approve the path by which data may now reach notifications.vendor.example/dispatch, and record what may travel it."
    },
    {
      "review_id": "data-flow-review:send-email",
      "change_id": "outbound_transmission_added:send-email",
      "role": "Data protection reviewer",
      "what": "Approve the path by which data may now reach send-email, and record what may travel it."
    },
    {
      "review_id": "destructive-action-review:send-customer-email",
      "change_id": "destructive_action_added:send-customer-email",
      "role": "Head of Customer Operations Engineering",
      "what": "Approve the addition of an action that act, and record its compensating action."
    },
    {
      "review_id": "destructive-action-review:send-email",
      "change_id": "destructive_action_added:send-email",
      "role": "Head of Customer Operations Engineering",
      "what": "Approve the addition of an action that transmit to recipients, and record its compensating action."
    }
  ],
  "volatile": {
    "computed_at": "2026-08-06T14:08:37.092Z"
  },
  "canonical_hash": "5da7de95baf97971d9a917beb0b2eaeb17091fd57e0a69836fabc7495f2af23b",
  "risk_profile": [
    {
      "dimension_id": "authority_surface",
      "question": "What can this agent do to the world, at the widest point of its declared tool set?",
      "level": "spends_or_destroys",
      "explain": "At least one tool moves money or destroys records. Both are irreversible in the sense that matters to a review board: there is no undo, only a compensating action somebody has to perform.",
      "because": [
        {
          "path": "tools/4",
          "value": "issue-refund: spend, gated human_approval, as end_user"
        }
      ],
      "evaluated": true
    },
    {
      "dimension_id": "transmission_reach",
      "question": "How far outside the trust boundary can content this agent handles travel?",
      "level": "named_external",
      "explain": "At least one declared destination is outside the platform, and the contract names it. A named external destination is reviewable.",
      "because": [
        {
          "path": "data_sinks/2",
          "value": "inbound-ticket-content: inbound, external, carries [personal_data, internal], permits [helpdesk.acme.example/tickets]"
        },
        {
          "path": "data_sinks/3",
          "value": "customer-mailbox: outbound, external, carries [personal_data], permits [mail-relay.internal.acme.example/transactional, notifications.vendor.example/dispatch]"
        },
        {
          "path": "tools/5",
          "value": "send-email transmits outward"
        }
      ],
      "evaluated": true
    },
    {
      "dimension_id": "data_sensitivity",
      "question": "What is the most sensitive class of data the declaration says this agent handles?",
      "level": "confidential_or_personal",
      "explain": "Personal, financial or confidential material is in scope, so a disclosure has a subject who can be harmed by it and usually a regulator who has an opinion about it.",
      "because": [
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data, confidential"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        }
      ],
      "evaluated": true
    },
    {
      "dimension_id": "delegated_authority",
      "question": "Whose authority do the downstream calls actually carry?",
      "level": "end_user",
      "explain": "Every declared tool acts as the calling user, so downstream authorisation is evaluated against the person who asked.",
      "because": [
        {
          "path": "",
          "value": "unconditional"
        }
      ],
      "evaluated": true
    },
    {
      "dimension_id": "autonomous_triggering",
      "question": "Can this agent act without a person asking it to, and how much of the loop is a person in?",
      "level": "scheduled_or_event",
      "explain": "A schedule or an event can start a run. Nobody is necessarily watching when it does.",
      "because": [
        {
          "path": "autonomy/trigger_modes",
          "value": "human_initiated, event_driven"
        }
      ],
      "evaluated": true
    },
    {
      "dimension_id": "blast_radius",
      "question": "How far does the worst plausible outcome of one bad run reach?",
      "level": "single_customer",
      "explain": "One customer's data or money is reachable in one run.",
      "because": [
        {
          "path": "autonomy/maximum_plausible_blast_radius/scope",
          "value": "single_customer"
        }
      ],
      "evaluated": true
    },
    {
      "dimension_id": "containment_declared",
      "question": "How much of what stops a runaway run is written down rather than left to the runtime?",
      "level": "fully_bounded",
      "explain": "Every containment field carries a declared value. The floor here is the GOOD state, deliberately: this dimension measures what is missing.",
      "because": [
        {
          "path": "",
          "value": "unconditional"
        }
      ],
      "evaluated": true
    }
  ],
  "applicable_controls": {
    "applicable": [
      "ARS-01",
      "ARS-02",
      "ARS-03",
      "ARS-04",
      "ARS-05",
      "ARS-06",
      "ARS-07",
      "ARS-08",
      "ARS-09",
      "ARS-10",
      "ARS-11",
      "ARS-12",
      "ARS-13",
      "ARS-14",
      "ARS-15",
      "ARS-16",
      "ARS-17",
      "ARS-18",
      "ARS-19",
      "ARS-20",
      "ARS-21",
      "ARS-22",
      "ARS-23",
      "ARS-24",
      "ARS-25",
      "ARS-26",
      "ARS-27",
      "ARS-28",
      "ARS-29",
      "ARS-30",
      "ARS-31",
      "ARS-32",
      "ARS-33",
      "ARS-34",
      "ARS-35",
      "ARS-36",
      "ARS-37",
      "ARS-38",
      "ARS-39",
      "ARS-40",
      "ARS-41"
    ],
    "not_applicable": [],
    "not_evaluated": [],
    "note": "not_applicable is excluded from both the numerator and the denominator. not_evaluated stays visible: a predicate that could not run has established nothing, and establishing nothing must not shrink the applicable set."
  },
  "newly_applicable_controls": [
    {
      "control_id": "ARS-29",
      "previously": false,
      "because": [
        {
          "path": "tools/0/required_scopes/2",
          "value": "lookup-customer holds customers.read.all"
        }
      ]
    }
  ],
  "affected_controls": [
    {
      "control_id": "ARS-01",
      "citation_id": "ARS-1.0-01",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/0",
          "value": "lookup-customer authenticates by workload_identity_federation"
        },
        {
          "path": "tools/1",
          "value": "search-tickets authenticates by workload_identity_federation"
        },
        {
          "path": "tools/2",
          "value": "update-ticket authenticates by workload_identity_federation"
        },
        {
          "path": "tools/3",
          "value": "draft-reply authenticates by workload_identity_federation"
        },
        {
          "path": "tools/4",
          "value": "issue-refund authenticates by workload_identity_federation"
        },
        {
          "path": "tools/5",
          "value": "send-email authenticates by workload_identity_federation"
        }
      ],
      "via_changes": [
        "permission_expanded:lookup-customer",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Identity propagation is proven over the set of downstream call paths, so the set growing invalidates it and the set shrinking does not: tool_added is listed and tool_removed is not. permission_expanded is listed because the criterion covers the authorization decision as well as the identity carried into it, and environment_expanded because a path evidenced in staging is commonly a different principal in production."
    },
    {
      "control_id": "ARS-02",
      "citation_id": "ARS-1.0-02",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/0",
          "value": "lookup-customer authenticates by workload_identity_federation"
        },
        {
          "path": "tools/1",
          "value": "search-tickets authenticates by workload_identity_federation"
        },
        {
          "path": "tools/2",
          "value": "update-ticket authenticates by workload_identity_federation"
        },
        {
          "path": "tools/3",
          "value": "draft-reply authenticates by workload_identity_federation"
        },
        {
          "path": "tools/4",
          "value": "issue-refund authenticates by workload_identity_federation"
        },
        {
          "path": "tools/5",
          "value": "send-email authenticates by workload_identity_federation"
        }
      ],
      "via_changes": [
        "permission_expanded:lookup-customer",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Scope evidence is invalidated by anything that adds authority or adds a holder of it: a widened scope, a new tool or skill declaring its own permissions, a shift to a shared principal whose scope becomes the union of every user's need, and a tool admitted to production on scopes reviewed for staging. permission_reduced is deliberately absent — a smaller grant cannot be more than the minimum, so the finding that no wildcard was present survives it intact."
    },
    {
      "control_id": "ARS-04",
      "citation_id": "ARS-1.0-04",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/0",
          "value": "lookup-customer authenticates by workload_identity_federation"
        },
        {
          "path": "tools/1",
          "value": "search-tickets authenticates by workload_identity_federation"
        },
        {
          "path": "tools/2",
          "value": "update-ticket authenticates by workload_identity_federation"
        },
        {
          "path": "tools/3",
          "value": "draft-reply authenticates by workload_identity_federation"
        },
        {
          "path": "tools/4",
          "value": "issue-refund authenticates by workload_identity_federation"
        },
        {
          "path": "tools/5",
          "value": "send-email authenticates by workload_identity_federation"
        },
        {
          "path": "autonomy/trigger_modes",
          "value": "human_initiated, event_driven"
        }
      ],
      "via_changes": [
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Lifetime evidence is about a specific credential and the session holding it. A new tool brings a new credential; a shift to a shared principal changes both who holds the token and what its theft costs; an agent that can start its own runs holds sessions nobody closes; and a withdrawn containment ceiling includes session_budget.max_wall_clock_ms, which was one of the bounds. Scope changes are absent — a wider grant is ARS-02's subject and does not change when the token dies."
    },
    {
      "control_id": "ARS-06",
      "citation_id": "ARS-1.0-06",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools",
          "value": "6 tools declared"
        }
      ],
      "via_changes": [
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Two things reopen a closed registry: permission for a tool name to be computed at run time, and a tool arriving in the set. tool_removed and tool_renamed are deliberately absent — a tool leaving does not reopen the registry, and a rename declared through aliases is one continuous capability, so the evidence about the dispatcher's behaviour survives both."
    },
    {
      "control_id": "ARS-07",
      "citation_id": "ARS-1.0-07",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools",
          "value": "6 tools declared"
        }
      ],
      "via_changes": [
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "This is the one control whose subject is the schema text itself, so any change to that text makes the previous read stale — a narrowing as well as a broadening, because the document that was read is not the document that runs. tool_schema_narrowed is listed here and nowhere else for that reason. A declared rename is not listed at all: an alias carries the same schema."
    },
    {
      "control_id": "ARS-08",
      "citation_id": "ARS-1.0-08",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/2",
          "value": "update-ticket = write"
        },
        {
          "path": "tools/3",
          "value": "draft-reply = write"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        },
        {
          "path": "skills/1/side_effects",
          "value": "ticket-triage does write"
        },
        {
          "path": "skills/2/side_effects",
          "value": "reply-drafting does write"
        },
        {
          "path": "skills/3/side_effects",
          "value": "goodwill-refund does spend"
        },
        {
          "path": "skills/4/side_effects",
          "value": "customer-correspondence does send"
        }
      ],
      "via_changes": [
        "approval_weakened:draft-reply",
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The inventory is a mapping from actions to classifications to gating policies, so it goes stale when an action appears or when a gate moves. A new tool or skill with a side effect has to be enumerated; a newly destructive action has to be classified; and a weakened or removed approval breaks the classification-to-policy half of the criterion. tool_removed is absent: the coverage direction that matters runs from the registry into the inventory, and an inventory naming one action too many has no gap in it."
    },
    {
      "control_id": "ARS-09",
      "citation_id": "ARS-1.0-09",
      "applicable": true,
      "applicability_because": [
        {
          "path": "autonomy/destructive_action_inventory/1",
          "value": "draft-customer-reply is reversible_with_effort"
        },
        {
          "path": "autonomy/destructive_action_inventory/2",
          "value": "issue-customer-refund is irreversible"
        },
        {
          "path": "autonomy/destructive_action_inventory/3",
          "value": "send-customer-email is irreversible"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        }
      ],
      "via_changes": [
        "approval_weakened:draft-reply",
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Anything that moves the gate, or moves what passes through it, invalidates the evidence: an approval weakened or removed, a new high-impact action, a new tool, and both forms of the human stepping back — a higher autonomy level and a trigger that no longer needs a person to start the run. approval_strengthened is deliberately absent. A gate that got heavier does not falsify evidence that a gate exists, and re-evidencing it would teach a review board that improving the system costs them a review."
    },
    {
      "control_id": "ARS-10",
      "citation_id": "ARS-1.0-10",
      "applicable": true,
      "applicability_because": [
        {
          "path": "autonomy/approval_classes",
          "value": "2 approval class(es)"
        },
        {
          "path": "tools/3",
          "value": "draft-reply gated at human_approval_conditional"
        },
        {
          "path": "tools/4",
          "value": "issue-refund gated at human_approval"
        },
        {
          "path": "tools/5",
          "value": "send-email gated at human_approval_conditional"
        }
      ],
      "via_changes": [
        "approval_strengthened:class_customer-facing-send",
        "approval_weakened:draft-reply",
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "This is the one control where approval_strengthened invalidates evidence: a heavier gate raises the volume the measurement was taken against, and a measurement is stale the moment its population changes. Weakening and removal move the same number the other way and are listed for the same reason. New tools and new destructive actions add traffic to the queue, and an agent that can start its own runs multiplies it without any person asking for the work."
    },
    {
      "control_id": "ARS-11",
      "citation_id": "ARS-1.0-11",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools",
          "value": "6 tools declared"
        }
      ],
      "via_changes": [
        "permission_expanded:lookup-customer",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "A server-side policy is a list, so evidence about it dies when the list changes: a tool added, a scope widened, a principal weakened so the pairing loses its user half, a tool admitted to an environment the policy was not written for. dynamic_loading_enabled is listed because a gateway allowlist cannot cover a tool name computed at run time — the enforced set stops being the reviewed set."
    },
    {
      "control_id": "ARS-12",
      "citation_id": "ARS-1.0-12",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools",
          "value": "6 tools declared"
        },
        {
          "path": "tools/5",
          "value": "send-email transmits outward"
        },
        {
          "path": "data_sinks/2",
          "value": "inbound-ticket-content is external (inbound)"
        },
        {
          "path": "data_sinks/3",
          "value": "customer-mailbox is external (outbound)"
        },
        {
          "path": "tools/2",
          "value": "update-ticket = write"
        },
        {
          "path": "tools/3",
          "value": "draft-reply = write"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        }
      ],
      "via_changes": [
        "approval_weakened:draft-reply",
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "outbound_transmission_added:send-email",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The policy governs a graph, so the graph changing is what invalidates it: a new tool is a new node, a tool that can now transmit outward is a new edge out, a new external destination is a new endpoint, and a prompt that now carries content the agent did not author is a new untrusted source. A widened classification means a permitted flow carries data the policy was not written for, and a weakened approval removes the human review the policy's exceptions usually rest on."
    },
    {
      "control_id": "ARS-13",
      "citation_id": "ARS-1.0-13",
      "applicable": true,
      "applicability_because": [
        {
          "path": "",
          "value": "unconditional"
        }
      ],
      "via_changes": [
        "permission_expanded:lookup-customer"
      ],
      "evidence_invalidated": [
        "ev-audit-plane-immutable",
        "ev-exfiltration-channels-enumerated",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Two halves, and both are permission-shaped. Coverage of the plane is invalidated by a tool added, because a new action may never have been wired into the write path. Immutability is invalidated by a widened permission or a weakened principal, because the way this control fails is the agent's identity acquiring rights over the store that holds the evidence about it. ⚠️ tool_added was removed from this list after assembly: append-only-ness is a property of the audit store. A new writer does not make an immutable store mutable. It was listed by 36 of 41 controls, which meant one new tool invalidated almost every evidence item in a ledger — and a delta that invalidates everything says nothing."
    },
    {
      "control_id": "ARS-14",
      "citation_id": "ARS-1.0-14",
      "applicable": true,
      "applicability_because": [
        {
          "path": "",
          "value": "unconditional"
        }
      ],
      "via_changes": [
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The chain breaks at new call sites and new endpoints. A tool added is a call site that may log without the identifier; an external destination added is a record the identifier may not reach; dynamic loading means the call sites are not enumerable at all. trigger_changed_human_to_autonomous is listed because the chain's root is the user request, and a run nobody asked for needs a root the earlier evidence never covered."
    },
    {
      "control_id": "ARS-15",
      "citation_id": "ARS-1.0-15",
      "applicable": true,
      "applicability_because": [
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data, internal"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data, internal"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data, confidential"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles internal, personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        },
        {
          "path": "prompts/0",
          "value": "system-triage interpolates user and external content"
        }
      ],
      "via_changes": [
        "model_changed:primary-reasoner",
        "skill_added:customer-correspondence"
      ],
      "evidence_invalidated": [
        "ev-cost-attribution",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-supply-chain-pinned",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Trace content is the subject, so the changes that matter are the ones that change what lands in a trace: a sink or skill carrying a more sensitive class than the policy was written for, a prompt that now carries content an outsider controls, a new skill with its own data classes, and a different model, whose intermediate output is a different record. lifecycle_promoted is listed because a retention policy adequate for pilot data becomes a compliance obligation over production records."
    },
    {
      "control_id": "ARS-16",
      "citation_id": "ARS-1.0-16",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        },
        {
          "path": "identity/criticality",
          "value": "high"
        }
      ],
      "via_changes": [
        "model_changed:primary-reasoner",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Everything the criterion names as part of a run record is listed: the model, the model's version policy, the prompt, and the tool set in both directions. tool_removed appears here and almost nowhere else — a run that invoked a tool the system no longer has cannot be replayed, and the evidence that replay works was gathered against the old set. Dynamic loading is listed because a tool resolved by a computed name cannot be pinned in a run record at all."
    },
    {
      "control_id": "ARS-18",
      "citation_id": "ARS-1.0-18",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/2",
          "value": "update-ticket = write"
        },
        {
          "path": "tools/3",
          "value": "draft-reply = write"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        },
        {
          "path": "autonomy/trigger_modes",
          "value": "human_initiated, event_driven"
        }
      ],
      "via_changes": [
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The control's own subject is the blast radius, so a widened one invalidates it directly. The rest change what has to be stopped and how quickly: a higher autonomy level, a trigger that starts runs with nobody watching, a new tool whose in-flight disposition was never defined, and a newly destructive action that needs a rollback answer where an abort used to be enough."
    },
    {
      "control_id": "ARS-19",
      "citation_id": "ARS-1.0-19",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/2",
          "value": "update-ticket = write"
        },
        {
          "path": "tools/3",
          "value": "draft-reply = write"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        },
        {
          "path": "skills/1/side_effects",
          "value": "ticket-triage does write"
        },
        {
          "path": "skills/2/side_effects",
          "value": "reply-drafting does write"
        },
        {
          "path": "skills/3/side_effects",
          "value": "goodwill-refund does spend"
        },
        {
          "path": "skills/4/side_effects",
          "value": "customer-correspondence does send"
        }
      ],
      "via_changes": [
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email",
        "outbound_transmission_added:send-email",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Duplicate execution is a function of what the operation does and how often it is repeated. A new tool or a newly destructive action is an effect nothing was keyed for; a raised retry ceiling multiplies every side effect an attempt has already had; and a tool that can now transmit outward is one whose duplicate leaves the trust boundary a second time and cannot be recalled."
    },
    {
      "control_id": "ARS-21",
      "citation_id": "ARS-1.0-21",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        },
        {
          "path": "identity/criticality",
          "value": "high"
        },
        {
          "path": "autonomy/maximum_plausible_blast_radius/scope",
          "value": "single_customer"
        },
        {
          "path": "tools/2",
          "value": "update-ticket = write"
        },
        {
          "path": "tools/3",
          "value": "draft-reply = write"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        }
      ],
      "via_changes": [
        "model_changed:primary-reasoner",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "A fallback is written against a named set of dependencies. Adding a skill or a tool creates a path nobody has rehearsed a fallback for; removing one voids the drill that exercised it; changing the model changes the dependency the 'the model is down' plan was written against. Reclassifying criticality changes which functions owe a fallback at all, and promotion toward production turns an advisory plan into a binding one. Prompt edits and budget changes are excluded: they alter what the agent does, not what it depends on."
    },
    {
      "control_id": "ARS-22",
      "citation_id": "ARS-1.0-22",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/2",
          "value": "update-ticket = write"
        },
        {
          "path": "tools/3",
          "value": "draft-reply = write"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        },
        {
          "path": "skills/1/side_effects",
          "value": "ticket-triage does write"
        },
        {
          "path": "skills/2/side_effects",
          "value": "reply-drafting does write"
        },
        {
          "path": "skills/3/side_effects",
          "value": "goodwill-refund does spend"
        },
        {
          "path": "skills/4/side_effects",
          "value": "customer-correspondence does send"
        },
        {
          "path": "autonomy/destructive_action_inventory/0",
          "value": "modify-ticket-state is reversible"
        },
        {
          "path": "autonomy/destructive_action_inventory/1",
          "value": "draft-customer-reply is reversible_with_effort"
        },
        {
          "path": "autonomy/destructive_action_inventory/2",
          "value": "issue-customer-refund is irreversible"
        },
        {
          "path": "autonomy/destructive_action_inventory/3",
          "value": "send-customer-email is irreversible"
        }
      ],
      "via_changes": [
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email",
        "outbound_transmission_added:send-email",
        "permission_expanded:lookup-customer",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Compensation evidence is per action class, so a new action class — a new destructive action, a new tool, a new skill, a newly outbound tool whose send cannot be unsent — leaves a class with no tested reversal. A broadened tool schema matters because the reversal was tested over the inputs the tool then accepted, and a wider blast radius matters because compensation is what bounds the cost of a bad action, so a bad action that now reaches further may exceed the remediation that was tested. Approval changes are excluded on purpose: a gate changes how often a bad action happens, not whether the reversal for it works."
    },
    {
      "control_id": "ARS-23",
      "citation_id": "ARS-1.0-23",
      "applicable": true,
      "applicability_because": [
        {
          "path": "",
          "value": "unconditional"
        }
      ],
      "via_changes": [
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Deliberately short. A timeout that was removed, or a default ceiling that was removed, directly contradicts the evidence. A new tool is a new boundary that nothing has been read for. Dynamic loading defeats the evidence in a different way: if a tool can be resolved by a name computed at run time, the set of boundaries is no longer the set that was checked. Retry and loop increases are excluded — more attempts inside a bound is still bounded — and a model swap is excluded, because changing an identifier does not remove a timeout from a call site."
    },
    {
      "control_id": "ARS-24",
      "citation_id": "ARS-1.0-24",
      "applicable": true,
      "applicability_because": [
        {
          "path": "prompts/0",
          "value": "system-triage: assembled_untrusted"
        },
        {
          "path": "prompts/0",
          "value": "system-triage interpolates user and external content"
        },
        {
          "path": "data_sinks/2",
          "value": "inbound-ticket-content: inbound, external, carries [personal_data, internal], permits [helpdesk.acme.example/tickets]"
        }
      ],
      "via_changes": [
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The evidence is a property of the assembly code, so it dies when the assembly changes or when a new source of untrusted content is wired into it. A trust-boundary change is the direct case; a prompt edit is the near case, because the separation is a few lines of that same code. A new tool or skill is a new result that lands somewhere in the assembly, and dynamic loading means results can arrive from tools that were never reviewed. A model change is excluded on purpose: whether the model honours the separation is ARS-25, which is tested rather than read."
    },
    {
      "control_id": "ARS-25",
      "citation_id": "ARS-1.0-25",
      "applicable": true,
      "applicability_because": [
        {
          "path": "prompts/0",
          "value": "system-triage interpolates user and external content"
        },
        {
          "path": "data_sinks/2",
          "value": "inbound-ticket-content is external (inbound)"
        },
        {
          "path": "data_sinks/3",
          "value": "customer-mailbox is external (outbound)"
        },
        {
          "path": "tools/2",
          "value": "update-ticket = write"
        },
        {
          "path": "tools/3",
          "value": "draft-reply = write"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        },
        {
          "path": "tools/5",
          "value": "send-email transmits outward"
        },
        {
          "path": "tools/0/required_scopes/2",
          "value": "lookup-customer holds customers.read.all"
        },
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data, confidential"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        }
      ],
      "via_changes": [
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "model_changed:primary-reasoner",
        "outbound_transmission_added:send-email",
        "permission_expanded:lookup-customer",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "This is the longest list in the range and it earns its length: an adversarial result is a measurement of one configuration, and the configuration is the model, the prompt, the tool surface, the authority and the set of places data can go. A model or version-policy change re-rolls the behaviour; a prompt or trust-boundary change moves the target; a new tool, a broadened schema or an expanded permission means the suite tested a smaller surface than the one that now exists; and a new outbound path or destination means the exfiltration chains that were tried are no longer the chains that exist. Containment and budget changes are excluded — they bound a successful injection, they do not change whether one lands."
    },
    {
      "control_id": "ARS-26",
      "citation_id": "ARS-1.0-26",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/5",
          "value": "send-email transmits outward"
        },
        {
          "path": "data_sinks/2",
          "value": "inbound-ticket-content is external (inbound)"
        },
        {
          "path": "data_sinks/3",
          "value": "customer-mailbox is external (outbound)"
        },
        {
          "path": "skills/1/side_effects",
          "value": "ticket-triage does write"
        },
        {
          "path": "skills/2/side_effects",
          "value": "reply-drafting does write"
        },
        {
          "path": "skills/4/side_effects",
          "value": "customer-correspondence does send"
        }
      ],
      "via_changes": [
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "outbound_transmission_added:send-email",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The evidence is a set of paths from model output to sinks, each with an encoding step on it. Every category here creates a path that was not on that list: a new destination, a newly outbound tool, a new tool, a new skill, or a tool that now accepts inputs it refused and so can carry output into states nothing was checked against. Model and prompt changes are excluded: they change what the output says, and the control is about what happens to it afterwards."
    },
    {
      "control_id": "ARS-27",
      "citation_id": "ARS-1.0-27",
      "applicable": true,
      "applicability_because": [
        {
          "path": "data_sinks/2",
          "value": "inbound-ticket-content is external (inbound)"
        },
        {
          "path": "data_sinks/3",
          "value": "customer-mailbox is external (outbound)"
        },
        {
          "path": "tools/5",
          "value": "send-email transmits outward"
        },
        {
          "path": "skills/4/side_effects",
          "value": "customer-correspondence does send"
        },
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data, internal"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data, internal"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data, confidential"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles internal, personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        }
      ],
      "via_changes": [
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "outbound_transmission_added:send-email",
        "permission_expanded:lookup-customer",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "An inventory is invalidated by a channel it does not name and by a policy that no longer matches what flows. New outbound transmission, a new external destination, a new tool or a new skill each add a channel; a widened classification changes what may flow through a channel already listed; an expanded permission changes what the agent can pull into one. Dynamic loading is here because a tool resolved at run time cannot be enumerated in advance, which is the one change that makes the inventory unmaintainable rather than merely stale. Removing a destination is excluded: an inventory that lists a channel that no longer exists is over-broad, not wrong."
    },
    {
      "control_id": "ARS-28",
      "citation_id": "ARS-1.0-28",
      "applicable": true,
      "applicability_because": [
        {
          "path": "",
          "value": "unconditional"
        }
      ],
      "via_changes": [
        "model_changed:primary-reasoner"
      ],
      "evidence_invalidated": [
        "ev-cost-attribution",
        "ev-injection-suite-run",
        "ev-supply-chain-pinned",
        "ev-trace-retention-acl"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Four categories, each a direct contradiction of what was read. A loosened version policy is the control's subject. A model change means the pinned identifier is not the one the pin was verified against. A new tool is new third-party code and a new dependency to pin and review. Dynamic loading is the sharpest of the four: a tool resolved by a computed name cannot be pinned at all, so it defeats the evidence rather than dating it. Prompt, permission, approval and containment changes are all excluded — none of them moves a version. ⚠️ tool_added was removed from this list after assembly: a tool addition does not unpin a model or a dependency. This control is about what is pinned, and the pinning did not move. It was listed by 36 of 41 controls, which meant one new tool invalidated almost every evidence item in a ledger — and a delta that invalidates everything says nothing."
    },
    {
      "control_id": "ARS-29",
      "citation_id": "ARS-1.0-29",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/0/required_scopes/2",
          "value": "lookup-customer holds customers.read.all"
        }
      ],
      "via_changes": [
        "permission_expanded:lookup-customer",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Isolation evidence is about which channels exist between one user's context and another's. A weakened effective principal creates that channel directly, an expanded permission widens what a shared identity reaches, and a wider blast radius is the owner's own statement that a single bad run now reaches further. A new tool or skill is a new store or a new context path that no isolation test has covered. Prompt and model changes are excluded: a leak between tenants is a property of the data plane, not of what the model was told."
    },
    {
      "control_id": "ARS-31",
      "citation_id": "ARS-1.0-31",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        },
        {
          "path": "identity/criticality",
          "value": "high"
        },
        {
          "path": "autonomy/trigger_modes",
          "value": "human_initiated, event_driven"
        }
      ],
      "via_changes": [
        "model_changed:primary-reasoner",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The evidence is an attribution scheme plus the figure it produced. A new skill is a new task type with no attribution key; a new tool is a new line of spend; a model change makes the recorded cost per completed unit of work wrong even where the scheme still holds. The two sharp ones are the identity categories: a weakened effective principal collapses per-user attribution into one shared identity, and a trigger that no longer requires a person means there is no user for per-user spend to attribute to. Budget and containment changes are excluded — they cap spend, they do not attribute it."
    },
    {
      "control_id": "ARS-32",
      "citation_id": "ARS-1.0-32",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools",
          "value": "6 tools declared"
        },
        {
          "path": "autonomy/trigger_modes",
          "value": "human_initiated, event_driven"
        }
      ],
      "via_changes": [
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "A quota is per downstream system and sized against a worst-case call volume, so both halves can break. A new tool or a new permitted destination is a system with no quota; a raised retry or loop ceiling and a removed containment ceiling all raise the volume the existing quota was sized against; a trigger that no longer needs a person removes the natural pacing the sizing assumed; and an environment expansion points a limit sized for staging at production capacity. There is deliberately no hard blocker on this control: rate limiting frequently lives in infrastructure the contract does not describe, so a null in containment does not settle it."
    },
    {
      "control_id": "ARS-33",
      "citation_id": "ARS-1.0-33",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        }
      ],
      "via_changes": [
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Four categories, and the exclusions are the point. A prompt change or a model change does not invalidate this evidence — those are the events the gate is supposed to fire on, so they exercise the control rather than expire it. What does invalidate it is a capability the suite does not cover, which is a new skill or tool, or a removed tool whose cases now prove nothing. Model_version_policy_loosened is here for a specific reason: with a floating model the version can change with no release at all, so a gate that runs on every model change has no event left to hang on. Two categories were added after the fact, on the first author's own recommendation: a declared rename and a removed skill both leave eval cases referencing an action by a name that no longer resolves, so the suite still runs and covers less than it claims to. A rename is continuous for the capability and discontinuous for anything that names it."
    },
    {
      "control_id": "ARS-34",
      "citation_id": "ARS-1.0-34",
      "applicable": true,
      "applicability_because": [
        {
          "path": "autonomy/destructive_action_inventory/0",
          "value": "modify-ticket-state is reversible"
        },
        {
          "path": "autonomy/destructive_action_inventory/1",
          "value": "draft-customer-reply is reversible_with_effort"
        },
        {
          "path": "autonomy/destructive_action_inventory/2",
          "value": "issue-customer-refund is irreversible"
        },
        {
          "path": "autonomy/destructive_action_inventory/3",
          "value": "send-customer-email is irreversible"
        }
      ],
      "via_changes": [
        "approval_weakened:draft-reply",
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-review-board-package",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "A coverage mapping breaks when the set on the left grows: a new destructive action, a new tool or a new skill each add a class with no eval case pointing at it. The two approval categories are here because the criterion asks for a refusal case as well as an execution case, and a refusal case tests that the agent stops at a gate — so weakening or removing that gate makes the refusal half describe a configuration that no longer exists. Removing a tool is deliberately excluded: a class disappearing cannot create a coverage gap in the classes that remain. tool_renamed was added after the fact: eval cases reference actions by name, so a rename that is entirely benign for the capability breaks every case that points at it, and a mapping that silently stops resolving is worse than one that is visibly short."
    },
    {
      "control_id": "ARS-35",
      "citation_id": "ARS-1.0-35",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        }
      ],
      "via_changes": [
        "approval_weakened:draft-reply",
        "model_changed:primary-reasoner",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-supply-chain-pinned",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The evidence here is not only that monitoring exists but that baselines were measured, and a baseline is measured against a configuration. A model change, a loosened version policy and a prompt change all move the behaviour the baselines describe — the loosened policy worst of all, because the model can then move without a release and the baseline ages with nothing to mark it. A new tool or skill is a series with no baseline. The two approval categories are here because approval rejection rate is one of the four named series, and a gate that is weakened or gone takes its baseline with it."
    },
    {
      "control_id": "ARS-36",
      "citation_id": "ARS-1.0-36",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        },
        {
          "path": "autonomy/trigger_modes",
          "value": "human_initiated, event_driven"
        },
        {
          "path": "data_sinks/2",
          "value": "inbound-ticket-content is external (inbound)"
        },
        {
          "path": "data_sinks/3",
          "value": "customer-mailbox is external (outbound)"
        },
        {
          "path": "tools/5",
          "value": "send-email transmits outward"
        },
        {
          "path": "skills/4/side_effects",
          "value": "customer-correspondence does send"
        }
      ],
      "via_changes": [
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "skill_added:customer-correspondence"
      ],
      "evidence_invalidated": [
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The evidence is a capture mechanism on the surfaces where output appears, plus a route from it into the evals. A new skill, tool or external destination is a surface with no flag path on it. The two autonomy categories matter for a different reason: when runs stop being initiated by people, and when people are further from each run, the in-flow half of the mechanism loses the human it assumed, and a feedback loop that captured nothing is indistinguishable from one that had nothing to capture. Model and prompt changes are excluded — they change what gets flagged, not whether anything can be. ⚠️ tool_added was removed from this list after assembly: the feedback instrumentation is unchanged. A new tool gives users something else to give feedback about; it does not remove the channel by which they do. It was listed by 36 of 41 controls, which meant one new tool invalidated almost every evidence item in a ledger — and a delta that invalidates everything says nothing."
    },
    {
      "control_id": "ARS-37",
      "citation_id": "ARS-1.0-37",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        },
        {
          "path": "tools/2",
          "value": "update-ticket = write"
        },
        {
          "path": "tools/3",
          "value": "draft-reply = write"
        },
        {
          "path": "tools/4",
          "value": "issue-refund = spend"
        },
        {
          "path": "tools/5",
          "value": "send-email = send"
        },
        {
          "path": "data_sinks/2",
          "value": "inbound-ticket-content is external (inbound)"
        },
        {
          "path": "data_sinks/3",
          "value": "customer-mailbox is external (outbound)"
        },
        {
          "path": "autonomy/maximum_plausible_blast_radius/scope",
          "value": "single_customer"
        },
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data, confidential"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        }
      ],
      "via_changes": [
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email",
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "outbound_transmission_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-correlation-ids",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-review-board-package"
      ],
      "accepted_evidence_kinds": [
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": true,
      "invalidation_note": "A severity taxonomy is a mapping from what can go wrong to how badly, so it expires when either side moves. A new destructive action is a new 'wrong action taken' class; a new outbound path or external destination is a new data-exposure route; a widened data classification changes how bad an exposure is. A widened blast radius, a changed criticality and a promotion into production all re-rate severities that were assigned against a smaller worst case. Tool renames, prompt edits and budget changes are excluded: they do not add an incident class or change what one costs."
    },
    {
      "control_id": "ARS-38",
      "citation_id": "ARS-1.0-38",
      "applicable": true,
      "applicability_because": [
        {
          "path": "tools/0",
          "value": "lookup-customer = read"
        },
        {
          "path": "tools/1",
          "value": "search-tickets = read"
        },
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data, internal"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data, internal"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data, confidential"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles internal, personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        }
      ],
      "via_changes": [
        "permission_expanded:lookup-customer",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Enforcement evidence is about which identity the retrieval runs as and what that identity may see. A weakened effective principal removes the identity the ACL is evaluated against; an expanded permission widens what it reaches; a widened classification means the store now holds a class the enforcement was never reviewed for. A new tool or skill is a new retrieval path. Model and prompt changes are excluded: an access-control bypass at the retrieval layer is not fixed or caused by what the model was told."
    },
    {
      "control_id": "ARS-39",
      "citation_id": "ARS-1.0-39",
      "applicable": true,
      "applicability_because": [
        {
          "path": "prompts",
          "value": "1 prompt(s) declared"
        },
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data, confidential"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        }
      ],
      "via_changes": [
        "permission_expanded:lookup-customer",
        "skill_added:customer-correspondence",
        "tool_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-audit-plane-immutable",
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-idempotency-keys",
        "ev-identity-propagation-trace",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-server-side-authz-probe",
        "ev-timeout-discipline",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "The evidence is a specific assembly path with a specific allowlist on it, so a prompt change is the direct invalidation and a trust-boundary change is the case where material the agent did not author starts arriving in the window. A widened classification, a new skill and a new tool each put a class or a result into the context that the allowlist was not written against, and an expanded permission means a query on the same code path can now return more fields than it could. Model and containment changes are excluded: they do not alter what is selected into the window."
    },
    {
      "control_id": "ARS-40",
      "citation_id": "ARS-1.0-40",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        },
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data, confidential"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        }
      ],
      "via_changes": [
        "external_destination_added:mail-relay.internal.acme.example/transactional",
        "external_destination_added:notifications.vendor.example/dispatch",
        "skill_added:customer-correspondence"
      ],
      "evidence_invalidated": [
        "ev-correlation-ids",
        "ev-cost-attribution",
        "ev-cross-tool-flow-policy",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-eval-suite-versioned",
        "ev-exfiltration-channels-enumerated",
        "ev-feedback-loop-instrumented",
        "ev-incident-taxonomy",
        "ev-injection-suite-run",
        "ev-retention-covers-artifacts",
        "ev-scope-minimality-review",
        "ev-scope-static-scan",
        "ev-trace-retention-acl",
        "ev-untrusted-segregation"
      ],
      "accepted_evidence_kinds": [
        "automatically_verified",
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "Deletion evidence is a list of stores that a request provably reaches, so anything that creates a store or changes the obligation invalidates it: a widened classification changes the retention rule, a new external destination puts artifacts somewhere outside the workflow, a new skill or tool produces traces nobody has checked, and promotion into production changes the retention schedule that applies. One limit, stated rather than hidden: the contract has no field naming where traces and embeddings live, so a new internal store will arrive at the delta as an uncategorised change rather than under any name on this list. ⚠️ tool_added was removed from this list after assembly: retention and deletion cover CLASSES of artifact — prompts, traces, tool-call records. A new tool produces more records of classes already covered, not a class nobody thought about. It was listed by 36 of 41 controls, which meant one new tool invalidated almost every evidence item in a ledger — and a delta that invalidates everything says nothing."
    },
    {
      "control_id": "ARS-41",
      "citation_id": "ARS-1.0-41",
      "applicable": true,
      "applicability_because": [
        {
          "path": "identity/lifecycle_state",
          "value": "production"
        },
        {
          "path": "identity/criticality",
          "value": "high"
        },
        {
          "path": "data_sinks/0/data_classifications",
          "value": "support-database carries personal_data"
        },
        {
          "path": "data_sinks/1/data_classifications",
          "value": "billing-service carries financial, personal_data"
        },
        {
          "path": "data_sinks/2/data_classifications",
          "value": "inbound-ticket-content carries personal_data"
        },
        {
          "path": "data_sinks/3/data_classifications",
          "value": "customer-mailbox carries personal_data"
        },
        {
          "path": "skills/0/data_classes",
          "value": "customer-lookup handles personal_data"
        },
        {
          "path": "skills/1/data_classes",
          "value": "ticket-triage handles personal_data"
        },
        {
          "path": "skills/2/data_classes",
          "value": "reply-drafting handles personal_data"
        },
        {
          "path": "skills/3/data_classes",
          "value": "goodwill-refund handles financial, personal_data"
        },
        {
          "path": "skills/4/data_classes",
          "value": "customer-correspondence handles personal_data"
        }
      ],
      "via_changes": [
        "destructive_action_added:send-customer-email",
        "destructive_action_added:send-email"
      ],
      "evidence_invalidated": [
        "ev-approval-gate-enforced",
        "ev-approval-volume-measured",
        "ev-destructive-inventory-complete",
        "ev-eval-covers-destructive",
        "ev-idempotency-keys",
        "ev-incident-taxonomy",
        "ev-review-board-package"
      ],
      "accepted_evidence_kinds": [
        "manually_verified",
        "attested"
      ],
      "attestation_alone_sufficient": false,
      "invalidation_note": "This list is deliberately drawn at the profile level rather than the mechanism level. Every change to every implementing mechanism arguably dates the package, but a control that fires on tool renames and prompt edits produces noise, and a review board turns noise off. What is listed instead is the set of changes that alter which controls apply to this agent at all — criticality, lifecycle, blast radius, autonomy, a new destructive action class, a widened data classification — because those change the shape of the document rather than one row of it. A client who wants the stricter reading should say so; this is the trade being made."
    }
  ],
  "verdict": {
    "verdict": "BLOCK",
    "rules_fired": [
      {
        "rule_id": "methodology-hard-blocker",
        "level": "BLOCK",
        "says": "A hard-blocker condition declared in the methodology holds on the current contract.",
        "clears_when": "the contract no longer satisfies the blocker condition",
        "why": "ARS-02 / wildcard-or-admin-scope: At least one entry in tools[].required_scopes is a wildcard or a breadth-named grant — *, *:*, or a scope naming all, admin, owner, root, superuser, full access or read-write-all. The standard states that such a grant is conclusive evidence of failure, and no result elsewhere makes it narrower. A read-only summarisation agent holding a write-all scope is a write agent the moment an injection lands.",
        "control_id": "ARS-02",
        "citation_id": "ARS-1.0-02",
        "blocker_id": "wildcard-or-admin-scope",
        "because": [
          {
            "path": "tools/0/required_scopes/2",
            "value": "lookup-customer holds customers.read.all"
          }
        ]
      },
      {
        "rule_id": "critical-authority-expansion",
        "level": "BLOCK",
        "says": "A change of critical severity widens what the agent may do.",
        "clears_when": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "why": "approval_weakened:draft-reply: an action that needed a person now needs less of one, or needs one less often. draft-reply moved from human_approval to human_approval_conditional, required only when: Required only when the draft quotes content the agent did not author.. Outside that condition the action now happens with no human in front of it.",
        "change_id": "approval_weakened:draft-reply",
        "category": "approval_weakened",
        "severity": "critical"
      },
      {
        "rule_id": "critical-authority-expansion",
        "level": "BLOCK",
        "says": "A change of critical severity widens what the agent may do.",
        "clears_when": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "why": "destructive_action_added:send-customer-email: the agent can now create, modify, delete, send or spend where it previously could not. A destructive action send-customer-email on send-email was inventoried, classified irreversible and gated at human_approval.",
        "change_id": "destructive_action_added:send-customer-email",
        "category": "destructive_action_added",
        "severity": "critical"
      },
      {
        "rule_id": "critical-authority-expansion",
        "level": "BLOCK",
        "says": "A change of critical severity widens what the agent may do.",
        "clears_when": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "why": "destructive_action_added:send-email: the agent can now create, modify, delete, send or spend where it previously could not. send-email is classified send, so the agent can now transmit to recipients where it previously could not.",
        "change_id": "destructive_action_added:send-email",
        "category": "destructive_action_added",
        "severity": "critical"
      },
      {
        "rule_id": "critical-authority-expansion",
        "level": "BLOCK",
        "says": "A change of critical severity widens what the agent may do.",
        "clears_when": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "why": "external_destination_added:mail-relay.internal.acme.example/transactional: the agent may send data somewhere it previously could not — a new path out. A new external sink customer-mailbox may reach mail-relay.internal.acme.example/transactional, carrying [personal_data].",
        "change_id": "external_destination_added:mail-relay.internal.acme.example/transactional",
        "category": "external_destination_added",
        "severity": "critical"
      },
      {
        "rule_id": "critical-authority-expansion",
        "level": "BLOCK",
        "says": "A change of critical severity widens what the agent may do.",
        "clears_when": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "why": "external_destination_added:notifications.vendor.example/dispatch: the agent may send data somewhere it previously could not — a new path out. A new external sink customer-mailbox may reach notifications.vendor.example/dispatch, carrying [personal_data].",
        "change_id": "external_destination_added:notifications.vendor.example/dispatch",
        "category": "external_destination_added",
        "severity": "critical"
      },
      {
        "rule_id": "critical-authority-expansion",
        "level": "BLOCK",
        "says": "A change of critical severity widens what the agent may do.",
        "clears_when": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "why": "outbound_transmission_added:send-email: a tool can now carry content out of the trust boundary — a path by which data leaves. send-email can carry content out of the trust boundary.",
        "change_id": "outbound_transmission_added:send-email",
        "category": "outbound_transmission_added",
        "severity": "critical"
      },
      {
        "rule_id": "high-severity-change",
        "level": "REVIEW",
        "says": "A change of high severity is present.",
        "clears_when": "a human accepts it, or it is withdrawn",
        "why": "3 change(s) of high severity: permission_expanded:lookup-customer, skill_added:customer-correspondence, tool_added:send-email",
        "change_ids": [
          "permission_expanded:lookup-customer",
          "skill_added:customer-correspondence",
          "tool_added:send-email"
        ]
      },
      {
        "rule_id": "authority-expanding-change",
        "level": "REVIEW",
        "says": "A change widens what the agent may do, below critical severity.",
        "clears_when": "a human accepts it, or it is withdrawn",
        "why": "3 change(s) widen what the agent may do: permission_expanded:lookup-customer, skill_added:customer-correspondence, tool_added:send-email",
        "change_ids": [
          "permission_expanded:lookup-customer",
          "skill_added:customer-correspondence",
          "tool_added:send-email"
        ]
      },
      {
        "rule_id": "evidence-invalidated",
        "level": "REVIEW",
        "says": "Prior evidence no longer describes the current system.",
        "clears_when": "the invalidated evidence is re-established by a kind the methodology accepts for that control",
        "why": "24 evidence item(s) no longer describe the current system",
        "evidence_ids": [
          "ev-approval-gate-enforced",
          "ev-approval-volume-measured",
          "ev-audit-plane-immutable",
          "ev-correlation-ids",
          "ev-cost-attribution",
          "ev-cross-tool-flow-policy",
          "ev-destructive-inventory-complete",
          "ev-eval-covers-destructive",
          "ev-eval-suite-versioned",
          "ev-exfiltration-channels-enumerated",
          "ev-feedback-loop-instrumented",
          "ev-idempotency-keys",
          "ev-identity-propagation-trace",
          "ev-incident-taxonomy",
          "ev-injection-suite-run",
          "ev-retention-covers-artifacts",
          "ev-review-board-package",
          "ev-scope-minimality-review",
          "ev-scope-static-scan",
          "ev-server-side-authz-probe",
          "ev-supply-chain-pinned",
          "ev-timeout-discipline",
          "ev-trace-retention-acl",
          "ev-untrusted-segregation"
        ]
      }
    ],
    "rules_available": [
      "delta-incomplete",
      "methodology-hard-blocker",
      "hard-blocker-unevaluated",
      "critical-authority-expansion",
      "undeclared-capability",
      "declaration-conflict",
      "high-severity-change",
      "authority-expanding-change",
      "uncategorised-change",
      "evidence-invalidated",
      "drift-observed"
    ],
    "blocking_changes": [
      "approval_weakened:draft-reply",
      "destructive_action_added:send-customer-email",
      "destructive_action_added:send-email",
      "external_destination_added:mail-relay.internal.acme.example/transactional",
      "external_destination_added:notifications.vendor.example/dispatch",
      "outbound_transmission_added:send-email"
    ],
    "promotion_conditions": [
      {
        "to_reach": "REVIEW",
        "rule_id": "methodology-hard-blocker",
        "condition": "the contract no longer satisfies the blocker condition",
        "currently": "ARS-02 / wildcard-or-admin-scope: At least one entry in tools[].required_scopes is a wildcard or a breadth-named grant — *, *:*, or a scope naming all, admin, owner, root, superuser, full access or read-write-all. The standard states that such a grant is conclusive evidence of failure, and no result elsewhere makes it narrower. A read-only summarisation agent holding a write-all scope is a write agent the moment an injection lands."
      },
      {
        "to_reach": "REVIEW",
        "rule_id": "critical-authority-expansion",
        "condition": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "currently": "approval_weakened:draft-reply: an action that needed a person now needs less of one, or needs one less often. draft-reply moved from human_approval to human_approval_conditional, required only when: Required only when the draft quotes content the agent did not author.. Outside that condition the action now happens with no human in front of it."
      },
      {
        "to_reach": "REVIEW",
        "rule_id": "critical-authority-expansion",
        "condition": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "currently": "destructive_action_added:send-customer-email: the agent can now create, modify, delete, send or spend where it previously could not. A destructive action send-customer-email on send-email was inventoried, classified irreversible and gated at human_approval."
      },
      {
        "to_reach": "REVIEW",
        "rule_id": "critical-authority-expansion",
        "condition": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "currently": "destructive_action_added:send-email: the agent can now create, modify, delete, send or spend where it previously could not. send-email is classified send, so the agent can now transmit to recipients where it previously could not."
      },
      {
        "to_reach": "REVIEW",
        "rule_id": "critical-authority-expansion",
        "condition": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "currently": "external_destination_added:mail-relay.internal.acme.example/transactional: the agent may send data somewhere it previously could not — a new path out. A new external sink customer-mailbox may reach mail-relay.internal.acme.example/transactional, carrying [personal_data]."
      },
      {
        "to_reach": "REVIEW",
        "rule_id": "critical-authority-expansion",
        "condition": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "currently": "external_destination_added:notifications.vendor.example/dispatch: the agent may send data somewhere it previously could not — a new path out. A new external sink customer-mailbox may reach notifications.vendor.example/dispatch, carrying [personal_data]."
      },
      {
        "to_reach": "REVIEW",
        "rule_id": "critical-authority-expansion",
        "condition": "the expansion is withdrawn, or its severity is reduced by narrowing what it grants",
        "currently": "outbound_transmission_added:send-email: a tool can now carry content out of the trust boundary — a path by which data leaves. send-email can carry content out of the trust boundary."
      }
    ],
    "standing_conditions": [],
    "standing_conditions_note": "No hard blocker was already true of the previous version.",
    "note": "BLOCK is not a score. Every condition above must stop being true; no number of clean rules outvotes one that fired."
  }
}
