Model intent is not authority
An agent may plan and request tools. Execution authority remains outside the model.

immo.quick Serverless Edition is an independent infrastructure for institutional execution rights. Before a protected action takes effect, it brings together authority, rule state, jurisdiction, purpose, time and mandatory dependencies. A valid Execution Right can form the basis for a narrowly scoped capability, whose validity is checked again at the point of execution.
Determination is not authorization. Admin is not authority. Break glass is not a bypass. Simulation is not production.
Banking applications, enterprise platforms, AI agents, workflows and operational systems may already be technically capable of acting. Serverless Edition does not replace their business logic. It evaluates whether the institutional conditions required for that exact protected effect are currently complete.
Integration can use APIs, workflow hooks, event pipelines, AI-agent interlocks or structured data and file intake. What matters is that the Serverless Edition is coupled to the real point of effect and cannot be bypassed by an alternative technical path.
The Serverless Edition is hardware-independent. Its primary control boundary is formed by current execution rights, tightly bound capabilities, point-of-effect revalidation and forensic evidence.
Actor, action, resource and purpose are made explicit.
Authority must be legitimate, active, scope-bound and traceably originated.
Rule, jurisdiction, time, purpose, dependencies and other mandatory domains must all match.
The capability is narrower than the right, time-bound and not freely reusable.
Before productive effect, current authority and state are validated again.
Evidence binds what was allowed or blocked and the current state on which that decision rested.
An agent may plan and request tools. Execution authority remains outside the model.
An API, vehicle, endpoint or service can be reachable and still be blocked at the point of effect.
If mandate, jurisdiction, revocation or dependency changes, the effect must be reassessed.
immo.quick separates admission from execution authority. A request must first pass the relevant admission boundary; even successful access does not itself authorize a production effect.
Core places a fail-closed Access Guardian before the governed compliance pipeline. A request that fails a required validation condition does not reach the downstream governance logic.
The Serverless Edition requires a registered client to establish valid attestation before the request reaches the downstream gate path.
Access is not authority. A productive effect requires a valid, current and scope-bound Execution Right and an executable capability.
Claim boundary: only the architecture of the immo.quick Serverless Edition was demonstrably submitted to the BSI on 28 July 2026. Core was not submitted. Submission is not a BSI audit, certification, endorsement or confirmation.
Execution Rights Infrastructure is not a new label for monitoring. The category defines a technical boundary between “conditions look acceptable” and “this exact action may now become technically executable.”
A positive gate result is not enough. Only rights closure can produce a valid Execution Right.
A right does not directly cause effect. It may only produce a tightly bound technical capability.
The actual execution is bound to right, capability, surface, time and evidence.
Each stage has a different meaning. Determinations establish facts about modeled conditions. Rights closure decides whether a right can close. Capability makes the permitted action technically executable. Enforcement checks directly at the boundary of effect.
The first moat controls the institution’s own productive environment. The goal is not merely to check, but to prevent capability-free bypass paths within the registered scope.
Mandatory conditions must fully close. No confidence scores, no AI recommendation path.
Subject, action, resource, purpose, scope, environment and validity remain tightly bound.
Productive API, event, queue, batch, admin, recovery and break-glass paths must be registered and enforced.
Right, revocation, freshness, context and capability class are revalidated immediately before effect.
Persistent atomic nonce state prevents reuse and race-condition-based double consumption.
Emergency execution requires its own authority, closure, capability and enhanced evidence.
Interoperability moves trust from assertion to independent verification. A counterparty does not have to believe that another system was authorized. It can verify the portable Execution Rights proof and then apply its own acceptance policy.
Remote acceptance creates neither local authority nor a local Execution Right.
Each institution decides under its own policy. The same valid proof can be accepted by A and rejected by B.
For sensitive transactions, both sides can prove their rights and independently accept the other party.
An admin role alone must not authorize productive execution.
Previously valid authority is not trusted indefinitely.
A capability for resource A or purpose X cannot be widened to resource B or purpose Y.
A consumed capability cannot cause effect again.
An alternate productive surface must not bypass central capability enforcement.
Counterfactual or simulated rights must never reach production capability issuance.
Portable Execution Rights Proofs make the binding between right, capability and execution externally verifiable. The current frozen proof path binds its actual crypto profile and rejects unknown or inconsistent protocol, schema, canonicalization and algorithm states.
Publicly verifiable attribution and integrity. No blanket claim of universal legal non-repudiation.
ERI-INV-017 separates authoritative state, observation, physical reality and ground truth. For physical dependencies, the applicable provenance, freshness, independence and attestation conditions must close at the Execution Cut. Unresolved divergence results in DENY or REASSESSMENT, not a majority vote on truth.
Sensors, monitoring or external evidence can reveal divergence. They do not rewrite governance state by themselves.
A majority is not proof of truth. Conflicting independent sources produce STATE_DIVERGENCE and prevent dependency closure.
Machine Law does not claim to manufacture unobserved reality. It prevents unresolved uncertainty from silently becoming execution permission.
ERI-INV-018 makes explicitly verified provenance a prerequisite for trusted execution evidence in physical attestations. A present provenance_root is not sufficient. provenance_verified must explicitly be true. false or absent means PROVENANCE_INCOMPLETE and fail-closed BLOCK.
Authenticity relative to a key, verified origin, and execution-relevant trust are three distinct claims.
0 detected successful bypass paths in the tested scope. This is internal implementation evidence, not a claim of global impossibility or third-party certification.
Agents can present proofs but cannot invent authority. Actions remain bound to verifiable rights and local acceptance.
Critical transfers can be bound to specific rights, scope, purpose, capability and execution evidence.
API, queue, webhook and service calls can be made capability-mandatory before effect.
Admin, recovery and emergency paths remain inside the same rights constitution.
Counterparties can independently verify portable rights proofs and apply their own acceptance policies.
Execution rights for high-criticality administrative, registry or infrastructure actions can be bound before effect.
The Serverless Edition does not start with a product-demo workflow. It starts with a concrete effect: which action must be protected, which authority grounds it, which states must still be valid at the point of effect, and what evidence must remain afterwards?
The new Execution Exposure Assessment translates that architecture into ten clear questions and produces no marketing scorecard, but a gap map for further review.
Serverless Edition is Execution Rights Infrastructure within the umbrella category Institutional Trust Infrastructure. It separates determination, authorization and execution and closes action-specific Execution Rights before productive effect.
A gate PASS is only a determination about one condition. An Execution Right exists only when all mandatory authority, rule, jurisdiction, time, dependency, purpose and scope conditions are closed.
A bounded capability is the technical ability to perform exactly the authorized action for the bound subject, resource, purpose, scope, time and environment context. It cannot be broader than the underlying right.
It allows another institution to independently verify a portable Execution Rights proof and accept or reject it under its own acceptance policy, without creating local authority.
No. Authority must be legitimately grounded externally. The system models and binds that authority; it does not create sovereign or legal authority by itself.
ERI-INV-017 allows reality-linked evidence to invalidate execution without turning observation into authority. If freshness, provenance, independence or required attestations no longer close, the result is DENY or REASSESSMENT. Conflicting sources are not resolved by treating a majority as physical truth.
No. ERI-INV-018 separates signature validity from verified provenance. For physical attestations, provenance must be present and explicitly verified. false or absent verification status remains PROVENANCE_INCOMPLETE and blocks fail-closed.
And when another institution is involved: control what executions from others you are willing to accept.
SRA separates runtime and observed reality from authority and execution. 20 formal invariants, a non-compensable threshold engine and 46/46 modeled scenarios with expected outcomes. Reality may inform authority. It may never create it.
30 primary actions. Attention-first. File-first intake. Permissions, decisions, receipts and integrations in one operating logic – with the authority boundary unchanged.
A receipt records a specific state or event. Assessment therefore depends on more than verifiable integrity: it requires identifying the event that is bound and the sources, rules and execution data available.
A gate establishes whether its formally defined conditions are satisfied. A PASS does not grant an execution right on its own.
Authority, rule state, jurisdiction, time and mandatory dependencies must align for the specific action.
A narrowly bound technical permission may follow from a valid execution right. Issuance does not prove that execution occurred.
Only evidence of the completed action establishes execution. Integrity alone guarantees neither source truth nor legal recognition.
immo.quick separates domain determination, institutional reliance, execution rights, technical capability, actual execution and resulting evidence. This prevents a positive check from becoming execution permission by implication and prevents an earlier valid state from being carried forward without revalidation. Each stage answers a different institutional question and has its own evidentiary boundary.
A regulatory, technical or domain-specific condition is deterministically established.
PASS ≠ EXECUTION PERMISSIONThe receiving institution decides whether an existing artifact may be relied upon for its specific purpose.
EVIDENCE ≠ RELIANCEAuthority, Rule, Jurisdiction, Time and material Dependencies must close for the exact consequence under the current state.
RELIANCE ≠ EXECUTION RIGHTOnly a valid Execution Right may produce a narrowly scoped, bound and, where applicable, single-use Capability.
RIGHT ≠ EXECUTED ACTIONThe authoritative state is revalidated immediately before effect. Material changes before the Execution Cut can prevent execution.
CONTINUING AUTHORITYThe governing state, permitted or refused effect and resulting proof chain are preserved as distinct evidence.
PROOF ≠ SOURCE OF LEGITIMACYA banking domain receipt records a sealed domain state while explicitly stating that no execution permission is created.
View artifactBANKING_SEALED · execution_permission=falseA subsequent receipt records a sanctions match. The earlier positive state remains historical evidence but cannot be carried forward as standing permission.
Open BLOCK receiptBLOCK_SANCTIONS_MATCH · chain_integrity=VALIDA separate Reliance Decision Record shows that an existing proof does not automatically become institutionally usable.
View Reliance artifactdecision=REFUSE · reliance_granted=false