Logs, reports and telemetry can make activity visible. Visibility is valuable, but it does not itself create or withdraw execution permission.
Observation tells an institution what happened. Prediction estimates what may happen. Intervention changes a trajectory that is already moving. Machine Law introduces a separate control question before a bounded capability exists: does the right to execute this exact action exist now?
Logs, reports and telemetry can make activity visible. Visibility is valuable, but it does not itself create or withdraw execution permission.
Models can estimate risk, drift or consequence. Probability can inform a determination, but probability is not institutional authority.
Escalation, pause and override can preserve governability. An intervention right is still not the same thing as the right behind the original execution.
Machine Law closes the relevant authority state for the exact action. If required closure is absent, no valid bounded capability should follow in the governed execution path.
The Execution Rights architecture is formalized, hardened and frozen. Rights closure, bounded capabilities, registered execution surfaces, current-right revalidation, replay protection, reassessment and portable verification form one fail-closed control chain.
Der zuvor offene Nonce-Reuse-Vektor wurde im zentralen produktiven Enforcement-Pfad geschlossen. Replay-Prüfung, Nonce-Verbrauch, Corruption-Verifikation, globale Conformance und Freeze-Entscheidung verwenden jetzt gebundene, fail-closed Zustände statt unabhängiger grüner Einzelanzeigen.
0 failed · nonce_reuse → EXECUTION_DENIED.
Applicable variants across 10 registered production execution surfaces.
Suites passed · overall_pass = true.
Only when control conditions and binding global conformance both pass.
Interne technische Verifikation des aktuellen implementierten Zustands. Keine Drittzertifizierung, keine Behauptung universeller Unangreifbarkeit und keine Aussage über nicht modellierte Angriffsvektoren.
FINMA, BaFin, NIST, NSA, EU and U.S. government strategies are converging on continuous authorization, Zero Trust, resilience, evidence and enforceable boundaries. See how immo.quick already operationalizes these control properties at the Execution Rights layer.
An enterprise can remain observable, manageable and even interruptible while the authorization question is still unresolved. immo.quick separates those layers instead of treating them as one.
The architecture can process encoded rules and authoritative states, resolve required conditions, bind a capability to the supported authorization state and preserve evidence within explicit claim boundaries.
Institutional authority originates outside the machine. A Gate Judgment is not an Execution Right. Cryptographic integrity is not a legal judgment.
Intervention can stop execution. Execution Rights determine whether a valid capability may exist in the first place.
As agents and automated systems touch payments, regulated workflows, clinical processes, critical infrastructure and public-sector execution, a retrospective explanation becomes less valuable than a provable boundary before action. The institutional problem is no longer only whether software can act. It is whether software can demonstrate the authority under which that action became executable.
Separate responsibility on paper from the technical conditions that create an executable capability.
Trace authority, rule state, dependencies and evidence without asking a model to become the sovereign decision-maker.
Execution failures can become remediation, legal, operational and balance-sheet exposure. The diligence question is whether the control layer is structural, inspectable and difficult to substitute.
immo.quick does not claim that software creates legal or sovereign authority. The architecture binds execution to externally legitimate authority and publishes the boundary of what its evidence can establish.
The Execution Rights Infrastructure was tested beyond the happy path. The audit deliberately attacks capability bindings, closure, state transitions, dependency graphs and runtime invariants. The objective is not probabilistic robustness, but deterministic fail-closed behavior.
39/39 tests passed. 0 bypass paths detected in tested scope. A non-Spine capability is blocked with SPINE_ISSUANCE_REQUIRED.
Manipulating action, subject, executor, validity, state references, scope, max_uses, environment or determination hash → INVALID_CAPABILITY_BINDING.
Four of five closed dimensions are not sufficient. Authority, Rule, Jurisdiction, Time and Dependencies must all close. For physical dependencies, a present measurement or valid signature is also insufficient by itself: ERI-INV-017 and ERI-INV-018 require closed reality-consistency and verified-provenance conditions. Unresolved divergence or provenance that is not explicitly verified blocks fail-closed.
If authority or dependency state changes between revalidation and execution, the Atomic Execution Check blocks.
Re-use of an already consumed capability is deterministically detected and blocked.
Orphan nodes, missing edges, circular dependencies and stale nodes invalidate the dependency graph.
Published architecture claims are checked against actual runtime enforcement.
An already validly consumed capability is presented again for execution. This is not probabilistic repetition and not an AI re-run. The same capability + same idempotency key returns the already known result; a new execution attempt with a different key after consumption is blocked as REPLAY_DETECTED.
Technical conformance evidence for the tested system state. Not third-party certification and not a claim of absolute invulnerability.