immo.quick Serverless Edition
EXECUTION & AUTHORITY · UNIVERSAL CONTROL DOMAIN

A valid login proves access. Not authority.

The Endpoint Authority Boundary separates successful authentication, technical reachability and session validity from the question of whether this exact endpoint is allowed to create this exact effect now. It replaces no existing sector authority. It adds another mandatory closure where applicable.

AUTHENTICATION ≠ AUTHORITY · LINKED DEVICE ≠ UNIVERSALLY TRUSTED DEVICE · EXECUTION_ALLOWED ⇒ SECTOR_CLOSURE_VALID ∧ ENDPOINT_AUTHORITY_VALID
16 EP INVARIANTS12 MSG INVARIANTS56 EXECUTION SURFACES41 LIVE TESTS
FOUR DISTINCT BOUNDARIES

Cryptography, authentication, endpoint security and authority solve different problems.

CRYPTOGRAPHY

Protects the channel

Encryption can remain fully intact while an additional technically valid endpoint is introduced into the communication flow.

AUTHENTICATION

Proves possession or identity signals

Password, OTP, session and device linking are important evidence. They do not automatically create authority for every downstream effect.

ENDPOINT SECURITY

Protects device and session

Attestation and device controls reduce risk. They do not alone determine whether a specific action is legitimately executable.

EXECUTION RIGHTS

Authorizes consequence

Only the current closure of sector authority and endpoint authority determines whether the requested effect may proceed.

ADDITIVE CLOSURE

No dilution of existing sector logic.

Endpoint Authority is an additional condition. Finance, Defence, Healthcare, Government, AEG and all other sector domains retain their own authority, rules and dependencies. Where Endpoint Authority applies, both closures must be valid at the same time.

EXISTING SECTOR CLOSUREANDENDPOINT AUTHORITY CLOSUREPOINT OF EFFECTAUTHORIZED EFFECT
EP-INV-016: ENDPOINT_EXECUTION_SCOPE ⊆ APPLICABLE_SECTOR_EXECUTION_SCOPE. The endpoint layer cannot expand the scope allowed by the applicable sector.
FORMAL REGISTRY

16 Endpoint Authority invariants.

EP-INV-001

AUTHENTICATED_ENDPOINT ≠ AUTHORIZED_ENDPOINT

EP-INV-002

SECTOR_CLOSURE ∧ ENDPOINT_CLOSURE = EXECUTION

EP-INV-003

ENDPOINT_AUTHORITY ⊆ SECTOR_AUTHORITY

EP-INV-004

ENDPOINT_AUTHORITY_CANNOT_REPLACE_SECTOR_AUTHORITY

EP-INV-005

EXECUTION_RIGHT_PRESENT ∧ CURRENT

EP-INV-006

ENROLLMENT_AUTHORITY_VALID

EP-INV-007

CONTINUING_AUTHORITY_AT_EFFECT

EP-INV-008

REVOKED_AUTHORITY = NO_AUTHORITY

EP-INV-009

EXPIRED_AUTHORITY = NO_AUTHORITY

EP-INV-010

SUPERSEDED_AUTHORITY = NO_AUTHORITY

EP-INV-011

SCOPE_VIOLATION = NO_AUTHORITY

EP-INV-012

DEVICE_LINKING ⇒ CURRENT_ENROLLMENT_AUTHORITY

EP-INV-013

AUTHENTICATION_FACTOR ≠ ENROLLMENT_AUTHORITY

EP-INV-014

LINKED_DEVICE ≠ UNIVERSALLY_TRUSTED_DEVICE

EP-INV-015

REASSESSMENT_REQUIRED ⇒ BLOCK_UNTIL_RECOMPILED

EP-INV-016

ENDPOINT_EXECUTION_SCOPE ⊆ APPLICABLE_SECTOR_EXECUTION_SCOPE

VERIFICATION

The boundary is executed against provider and endpoint attack scenarios.

The current suite contains 41 modeled tests. 36 expected negative scenarios were correctly blocked, 5 legitimate positive controls were allowed, and 0 unexpected failures were observed. The suite includes SIM Swap, Account Recovery Abuse, Linked Device Persistence, Session Hijacking, Interoperability Scope Transfer and Lawful Access Scope Drift.

41/41MODELED TESTS PASSED
36ATTACKS BLOCKED
5POSITIVE CONTROLS
0UNEXPECTED FAILURES
Claim boundary: No bypass observed in the 41 modeled tests executed against the current enforcement boundary. This is internal verification within the implemented scope, not a universal security guarantee or external certification.
SECTOR DEPLOYMENT

Universal in the kernel. Mandatory only where the context requires it.

SectorProvisioningTypical use
TelecommunicationsSECTOR_REQUIREDSIM, eSIM, device enrollment, sessions, roaming, network functions, lawful access
Messaging & Social CommunicationsSECTOR_REQUIREDDevice linking, message send, group administration, cloud sync, interoperability
AEGSECTOR_REQUIREDAgent endpoint, tool channel, credential use, network and API effect
Defence / CybersecuritySECTOR_REQUIREDPrivileged, remote, classified and control relevant endpoints
Finance / Healthcare / Government / EnergySECTOR_REQUIRED for sensitive effectTransactional, clinical, administrative or OT relevant endpoints
Real Estate / Logistics / Heavy IndustryCONDITIONALLY_REQUIREDOnly when activity, risk or deployment makes the endpoint boundary applicable
FAQ

What the boundary does not claim.

Does a receipt prove that a device was secure?

No. The receipt binds evaluated state, rule version, authority and result. It is a forensic artifact, not proof that the device was uncompromised.

Does Endpoint Authority make a stolen OTP harmless?

No. Endpoint Authority does not claim to eliminate phishing or SMS interception. Within the implemented boundary, possession of an authentication factor is not treated as enrollment authority.

Does Endpoint Authority replace MFA or device security?

No. These controls are complementary. Endpoint Authority answers a different question: may this exact endpoint create this exact effect now?

DEEN