{
  "report_type": "ERI_AUDIT_SUITE_REPORT",
  "report_version": "1.0.0",
  "generated_at": "2026-08-31T22:10:34.657Z",
  "system": "immo.quick Serverless Edition — Execution Rights Infrastructure",
  "leitsatz": "ATTACK · MUTATE · BREAK · RACE · REPLAY · REVOKE · POISON · FORGE · DRIFT",
  "audit_version": "eri-audit-v1.0.0",
  "run_at": "2026-08-31T22:10:31.056Z",
  "summary": {
    "total_suites": 6,
    "total_tests": 74,
    "total_passed": 74,
    "total_failed": 0,
    "overall_pass": true,
    "verdict": "ERI LAYER HOLDS — all attack vectors blocked"
  },
  "suites": [
    {
      "suite": "CAPABILITY_FORGERY",
      "total": 14,
      "passed": 14,
      "failed": 0,
      "tests": [
        {
          "test_id": "FORGERY-ACTION_TYPE",
          "description": "Forge action_type: FACTOR_RECEIVABLE → WIRE_TRANSFER",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-SUBJECT_REF",
          "description": "Forge subject_ref: different invoice",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-INTENDED_EXECUTOR",
          "description": "Forge intended_executor: unauthorized executor",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-VALID_UNTIL",
          "description": "Forge valid_until: extend expiry by 1 year",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-AUTHORITY_STATE_REF",
          "description": "Forge authority_state_ref: fake authority",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-RULE_STATE_REF",
          "description": "Forge rule_state_ref: fake rule",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-JURISDICTION_STATE_REF",
          "description": "Forge jurisdiction_state_ref: different jurisdiction",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-TEMPORAL_STATE_REF",
          "description": "Forge temporal_state_ref: fake temporal state",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-PERMITTED_SCOPE",
          "description": "Forge permitted_scope: TREASURY → ADMIN (privilege escalation)",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-MAX_USES",
          "description": "Forge max_uses: 1 → 999 (replay enablement)",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-ENVIRONMENT",
          "description": "Forge environment: PRODUCTION → SIMULATION (downgrade)",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-DETERMINATION_HASH",
          "description": "Forge determination_hash: fake determination",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected: INVALID_CAPABILITY_BINDING"
        },
        {
          "test_id": "FORGERY-NO_HASH",
          "description": "Capability with no hash at all",
          "expected": "NO_HASH",
          "actual": "NO_HASH",
          "pass": true,
          "detail": "NO_HASH"
        },
        {
          "test_id": "FORGERY-POSITIVE_CONTROL",
          "description": "Unmodified capability must pass integrity check",
          "expected": "VALID",
          "actual": "VALID",
          "pass": true,
          "detail": "Unmodified capability verified correctly."
        }
      ]
    },
    {
      "suite": "CLOSURE_BYPASS",
      "total": 15,
      "passed": 15,
      "failed": 0,
      "tests": [
        {
          "test_id": "CLOSURE-AUTH-001",
          "description": "Authority SUSPENDED → no capability",
          "expected": "OPEN — no capability [failed: authority,scope]",
          "actual": "OPEN [failed: authority,scope]",
          "pass": true,
          "detail": "Blocked dimensions: authority, scope — reasons: AUTHORITY_MISSING, SCOPE_INVALID"
        },
        {
          "test_id": "CLOSURE-AUTH-002",
          "description": "Action not permitted → no capability",
          "expected": "OPEN — no capability [failed: authority]",
          "actual": "OPEN [failed: authority]",
          "pass": true,
          "detail": "Blocked dimensions: authority — reasons: ACTION_NOT_PERMITTED"
        },
        {
          "test_id": "CLOSURE-RULE-001",
          "description": "Rule SUPERSEDED → no capability",
          "expected": "OPEN — no capability [failed: rule]",
          "actual": "OPEN [failed: rule]",
          "pass": true,
          "detail": "Blocked dimensions: rule — reasons: RULE_STATE_INVALID"
        },
        {
          "test_id": "CLOSURE-JUR-001",
          "description": "Jurisdiction SUPERSEDED → no capability",
          "expected": "OPEN — no capability [failed: jurisdiction]",
          "actual": "OPEN [failed: jurisdiction]",
          "pass": true,
          "detail": "Blocked dimensions: jurisdiction — reasons: JURISDICTION_UNRESOLVED"
        },
        {
          "test_id": "CLOSURE-TIME-001",
          "description": "Temporal state EXPIRED → no capability",
          "expected": "OPEN — no capability [failed: time]",
          "actual": "OPEN [failed: time]",
          "pass": true,
          "detail": "Blocked dimensions: time — reasons: EXPIRED"
        },
        {
          "test_id": "CLOSURE-DEP-001",
          "description": "Dependency STALE → no capability",
          "expected": "OPEN — no capability [failed: dependencies]",
          "actual": "OPEN [failed: dependencies]",
          "pass": true,
          "detail": "Blocked dimensions: dependencies — reasons: DEPENDENCY_CHANGED"
        },
        {
          "test_id": "CLOSURE-DEP-002",
          "description": "Dependency SUPERSEDED → no capability",
          "expected": "OPEN — no capability [failed: dependencies]",
          "actual": "OPEN [failed: dependencies]",
          "pass": true,
          "detail": "Blocked dimensions: dependencies — reasons: DEPENDENCY_CHANGED"
        },
        {
          "test_id": "CLOSURE-COMB-4of5-AUTH",
          "description": "4/5 closed (Authority open) → no capability",
          "expected": "OPEN — no capability [failed: authority,scope]",
          "actual": "OPEN [failed: authority,scope]",
          "pass": true,
          "detail": "Blocked dimensions: authority, scope — reasons: AUTHORITY_MISSING, SCOPE_INVALID"
        },
        {
          "test_id": "CLOSURE-COMB-4of5-RULE",
          "description": "4/5 closed (Rule open) → no capability",
          "expected": "OPEN — no capability [failed: rule]",
          "actual": "OPEN [failed: rule]",
          "pass": true,
          "detail": "Blocked dimensions: rule — reasons: RULE_STATE_INVALID"
        },
        {
          "test_id": "CLOSURE-COMB-4of5-JUR",
          "description": "4/5 closed (Jurisdiction open) → no capability",
          "expected": "OPEN — no capability [failed: jurisdiction]",
          "actual": "OPEN [failed: jurisdiction]",
          "pass": true,
          "detail": "Blocked dimensions: jurisdiction — reasons: JURISDICTION_UNRESOLVED"
        },
        {
          "test_id": "CLOSURE-COMB-4of5-TIME",
          "description": "4/5 closed (Time open) → no capability",
          "expected": "OPEN — no capability [failed: time]",
          "actual": "OPEN [failed: time]",
          "pass": true,
          "detail": "Blocked dimensions: time — reasons: EXPIRED"
        },
        {
          "test_id": "CLOSURE-COMB-4of5-DEP",
          "description": "4/5 closed (Dependency open) → no capability",
          "expected": "OPEN — no capability [failed: dependencies]",
          "actual": "OPEN [failed: dependencies]",
          "pass": true,
          "detail": "Blocked dimensions: dependencies — reasons: DEPENDENCY_CHANGED"
        },
        {
          "test_id": "CLOSURE-POSITIVE",
          "description": "All 5 dimensions closed → capability possible",
          "expected": "CLOSED (capability possible)",
          "actual": "CLOSED",
          "pass": true,
          "detail": "All 5 dimensions closed."
        },
        {
          "test_id": "CLOSURE-NULL-AUTH",
          "description": "Null authority → no capability (fail closed)",
          "expected": "OPEN — no capability [failed: authority,scope]",
          "actual": "OPEN [failed: authority,scope]",
          "pass": true,
          "detail": "Blocked dimensions: authority, scope — reasons: AUTHORITY_MISSING, SCOPE_INVALID"
        },
        {
          "test_id": "CLOSURE-NULL-STATES",
          "description": "Null bound states → no capability (fail closed)",
          "expected": "OPEN — no capability [failed: rule,jurisdiction,time]",
          "actual": "OPEN [failed: rule,jurisdiction,time]",
          "pass": true,
          "detail": "Blocked dimensions: rule, jurisdiction, time — reasons: RULE_STATE_MISSING, JURISDICTION_STATE_MISSING, TEMPORAL_STATE_MISSING"
        }
      ]
    },
    {
      "suite": "REVOCATION_RACE",
      "total": 9,
      "passed": 9,
      "failed": 0,
      "tests": [
        {
          "test_id": "RACE-001-STEP1",
          "description": "Step 1: Capability is VALID at T1",
          "expected": "VALID",
          "actual": "VALID",
          "pass": true,
          "detail": "consumption_state=ISSUED"
        },
        {
          "test_id": "RACE-001-STEP2",
          "description": "Step 2: PoE Revalidation VALID at T2 (authority still active)",
          "expected": "VALID",
          "actual": "VALID",
          "pass": true,
          "detail": "checks: {\"authority_valid\":true,\"rule_current\":true,\"jurisdiction_valid\":true,\"dependencies_valid\":true,\"capability_not_revoked\":true,\"capability_not_expired\":true,\"capability_not_consumed\":true}"
        },
        {
          "test_id": "RACE-001-STEP4",
          "description": "Step 4: Atomic Check after authority revoked → EXECUTION_ABORTED_STATE_CHANGED",
          "expected": "EXECUTION_ABORTED_STATE_CHANGED",
          "actual": "EXECUTION_ABORTED_STATE_CHANGED",
          "pass": true,
          "detail": "execute=false, checks: {\"capability_valid\":true,\"capability_not_consumed\":true,\"capability_not_revoked\":true,\"authority_still_active\":false,\"authority_version_matches\":true,\"rule_still_active\":true,\"rule_version_matches\":true,\"dependencies_still_active\":true,\"dependency_versions_match\":true}"
        },
        {
          "test_id": "RACE-002",
          "description": "Authority revoked, NO expectedVersions → must still block (AUDIT FIX)",
          "expected": "EXECUTION_ABORTED_STATE_CHANGED",
          "actual": "EXECUTION_ABORTED_STATE_CHANGED",
          "pass": true,
          "detail": "authority_still_active=false, execute=false"
        },
        {
          "test_id": "RACE-003",
          "description": "Capability REVOKED → atomic check must block",
          "expected": "EXECUTION_ABORTED_STATE_CHANGED",
          "actual": "EXECUTION_ABORTED_STATE_CHANGED",
          "pass": true,
          "detail": "capability_not_revoked=false"
        },
        {
          "test_id": "RACE-004",
          "description": "Capability CONSUMED → atomic check must block",
          "expected": "EXECUTION_ABORTED_STATE_CHANGED",
          "actual": "EXECUTION_ABORTED_STATE_CHANGED",
          "pass": true,
          "detail": "capability_not_consumed=false"
        },
        {
          "test_id": "RACE-005-STEP1",
          "description": "Step 1: PoE revalidation VALID (deps fresh)",
          "expected": "VALID",
          "actual": "VALID",
          "pass": true,
          "detail": ""
        },
        {
          "test_id": "RACE-005-STEP2",
          "description": "Step 2: Dep becomes stale → atomic check must block",
          "expected": "EXECUTION_ABORTED_STATE_CHANGED",
          "actual": "EXECUTION_ABORTED_STATE_CHANGED",
          "pass": true,
          "detail": "dependencies_still_active=false"
        },
        {
          "test_id": "RACE-006-POSITIVE",
          "description": "All valid → atomic check must pass",
          "expected": "EXECUTE",
          "actual": "EXECUTE",
          "pass": true,
          "detail": "All checks passed: {\"capability_valid\":true,\"capability_not_consumed\":true,\"capability_not_revoked\":true,\"authority_still_active\":true,\"authority_version_matches\":true,\"rule_still_active\":true,\"rule_version_matches\":true,\"dependencies_still_active\":true,\"dependency_versions_match\":true}"
        }
      ]
    },
    {
      "suite": "GRAPH_POISONING",
      "total": 9,
      "passed": 9,
      "failed": 0,
      "tests": [
        {
          "test_id": "GRAPH-001-VALID",
          "description": "Valid complete graph → VALID",
          "expected": "VALID",
          "actual": "VALID",
          "pass": true,
          "detail": "Graph is valid."
        },
        {
          "test_id": "GRAPH-002-ORPHAN_CAP",
          "description": "Orphan capability (no determination dep) → INVALID",
          "expected": "INVALID (DEPENDENCY_GRAPH_INCOMPLETE)",
          "actual": "INVALID [ORPHAN_CAPABILITY, MISSING_EDGE]",
          "pass": true,
          "detail": "Issues: ORPHAN_CAPABILITY(CRITICAL); MISSING_EDGE(CRITICAL)"
        },
        {
          "test_id": "GRAPH-003-ORPHAN_DET",
          "description": "Orphan determination (no state dep) → INVALID",
          "expected": "INVALID (DEPENDENCY_GRAPH_INCOMPLETE)",
          "actual": "INVALID [ORPHAN_DETERMINATION]",
          "pass": true,
          "detail": "Issues: ORPHAN_DETERMINATION(CRITICAL)"
        },
        {
          "test_id": "GRAPH-004-CIRCULAR",
          "description": "Circular dependency → INVALID",
          "expected": "INVALID (DEPENDENCY_GRAPH_INCOMPLETE)",
          "actual": "INVALID [CIRCULAR_DEPENDENCY, CIRCULAR_DEPENDENCY, CIRCULAR_DEPENDENCY]",
          "pass": true,
          "detail": "Issues: CIRCULAR_DEPENDENCY(CRITICAL); CIRCULAR_DEPENDENCY(CRITICAL); CIRCULAR_DEPENDENCY(CRITICAL)"
        },
        {
          "test_id": "GRAPH-005-STALE",
          "description": "Stale node (SUPERSEDED state) → INVALID (warn)",
          "expected": "INVALID (DEPENDENCY_GRAPH_INCOMPLETE)",
          "actual": "INVALID [STALE_NODE]",
          "pass": true,
          "detail": "Issues: STALE_NODE(CRITICAL)"
        },
        {
          "test_id": "GRAPH-006-MISSING_EDGE",
          "description": "Missing edge (CAP references missing DET) → INVALID",
          "expected": "INVALID (DEPENDENCY_GRAPH_INCOMPLETE)",
          "actual": "INVALID [MISSING_EDGE]",
          "pass": true,
          "detail": "Issues: MISSING_EDGE(CRITICAL)"
        },
        {
          "test_id": "GRAPH-007-DUPLICATE",
          "description": "Duplicate edge (Set handles it) → VALID",
          "expected": "VALID",
          "actual": "VALID",
          "pass": true,
          "detail": "Graph is valid."
        },
        {
          "test_id": "GRAPH-008-ORPHAN_EXEC",
          "description": "Orphan execution (no capability dep) → INVALID",
          "expected": "INVALID (DEPENDENCY_GRAPH_INCOMPLETE)",
          "actual": "INVALID [ORPHAN_EXECUTION]",
          "pass": true,
          "detail": "Issues: ORPHAN_EXECUTION(CRITICAL)"
        },
        {
          "test_id": "GRAPH-009-EMPTY",
          "description": "Empty graph → VALID (trivially)",
          "expected": "VALID",
          "actual": "VALID",
          "pass": true,
          "detail": "Graph is valid."
        }
      ]
    },
    {
      "suite": "INVARIANT_MUTATION",
      "total": 12,
      "passed": 12,
      "failed": 0,
      "tests": [
        {
          "test_id": "MUT-INV-001",
          "invariant": "INV-001",
          "description": "Gate verdict = EXECUTE → must be rejected",
          "expected": "(r) => !r.valid && r.violation === 'DOMAIN_LOGIC_DEFINED_EXECUTION_SEMANTICS'",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "{\"valid\":false,\"violation\":\"DOMAIN_LOGIC_DEFINED_EXECUTION_SEMANTICS\",\"message\":\"Gate verdict 'EXECUTE' defines execution-rights semantics. Domain logic may determine conditions but shall not authoriz"
        },
        {
          "test_id": "MUT-INV-002",
          "invariant": "INV-002",
          "description": "Authority suspended → closure must be open → no capability",
          "expected": "(r) => !r.closed",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "{\"closed\":false,\"dimensions\":{\"authority\":{\"closed\":false,\"value\":\"AUTH:DE:DE:BANK01:INSTITUTIONAL:231055\",\"reason\":\"AUTHORITY_MISSING\"},\"rule\":{\"closed\":true,\"value\":\"STATE:DE:INST:RULE_STATE:231055\""
        },
        {
          "test_id": "MUT-INV-004",
          "invariant": "INV-004",
          "description": "Null authority → closure must fail closed",
          "expected": "(r) => !r.closed",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "{\"closed\":false,\"dimensions\":{\"authority\":{\"closed\":false,\"value\":null,\"reason\":\"AUTHORITY_MISSING\"},\"rule\":{\"closed\":false,\"value\":null,\"reason\":\"RULE_STATE_MISSING\"},\"jurisdiction\":{\"closed\":false,\""
        },
        {
          "test_id": "MUT-INV-005",
          "invariant": "INV-005",
          "description": "Override creates new state, original must be unchanged",
          "expected": "true",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "true"
        },
        {
          "test_id": "MUT-INV-007",
          "invariant": "INV-007",
          "description": "Capability valid_until must not exceed dependency valid_until",
          "expected": "false",
          "actual": "Dependency expires before capability — derivation must use MIN",
          "pass": true,
          "detail": "false"
        },
        {
          "test_id": "MUT-INV-008",
          "invariant": "INV-008",
          "description": "Stale dependency → closure must be open",
          "expected": "(r) => !r.closed",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "{\"closed\":false,\"dimensions\":{\"authority\":{\"closed\":true,\"value\":\"AUTH:DE:DE:BANK01:INSTITUTIONAL:231055\",\"reason\":null},\"rule\":{\"closed\":true,\"value\":\"STATE:DE:INST:RULE_STATE:231055\",\"reason\":null},"
        },
        {
          "test_id": "MUT-INV-011",
          "invariant": "INV-011",
          "description": "Simulation capability must be SUSPENDED, not executable",
          "expected": "true",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "true"
        },
        {
          "test_id": "MUT-INV-012",
          "invariant": "INV-012",
          "description": "Consumed capability → second consume must fail",
          "expected": "(r) => !r.success && r.reason === 'REPLAY_DETECTED'",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "{\"success\":false,\"reason\":\"REPLAY_DETECTED\",\"detail\":\"Idempotency key mismatch for an already-attempted capability.\",\"capability\":{\"capability_id\":\"CAP:XX:INST:FACTOR_RECEIVABLE:231055\",\"action_id\":\"A"
        },
        {
          "test_id": "MUT-INV-013",
          "invariant": "INV-013",
          "description": "Revoked capability → atomic check must block",
          "expected": "(r) => !r.execute",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "{\"execute\":false,\"checks\":{\"capability_valid\":false,\"capability_not_consumed\":true,\"capability_not_revoked\":false,\"authority_still_active\":true,\"authority_version_matches\":true,\"rule_still_active\":tru"
        },
        {
          "test_id": "MUT-INV-014",
          "invariant": "INV-014",
          "description": "Authority revoked at PoE → atomic check must block",
          "expected": "(r) => !r.execute && r.failure === 'EXECUTION_ABORTED_STATE_CHANGED'",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "{\"execute\":false,\"checks\":{\"capability_valid\":true,\"capability_not_consumed\":true,\"capability_not_revoked\":true,\"authority_still_active\":false,\"authority_version_matches\":true,\"rule_still_active\":true"
        },
        {
          "test_id": "MUT-INV-015",
          "invariant": "INV-015",
          "description": "SIMULATION capability → isCapabilityValid must be false (SUSPENDED state)",
          "expected": "false",
          "actual": "BLOCKED",
          "pass": true,
          "detail": "false"
        },
        {
          "test_id": "MUT-FORGERY",
          "invariant": "INTEGRITY",
          "description": "Forge subject_ref → integrity check must fail",
          "expected": "INVALID_CAPABILITY_BINDING",
          "actual": "INVALID_CAPABILITY_BINDING",
          "pass": true,
          "detail": "Forgery detected."
        }
      ]
    },
    {
      "suite": "MANIFEST_CONFORMANCE",
      "total": 15,
      "passed": 15,
      "failed": 0,
      "tests": [
        {
          "test_id": "CONF-001",
          "manifest_claim": "Determination ≠ Authorization",
          "description": "Gate verdict EXECUTE must be rejected by validateGateVerdict",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-002",
          "manifest_claim": "Gate PASS ≠ Capability",
          "description": "Gate PASS alone (without closed authority) must not produce a capability",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-003",
          "manifest_claim": "Authority externally grounded",
          "description": "createAuthorityState requires a source (external grounding)",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-004A",
          "manifest_claim": "No capability without 5 closed dimensions",
          "description": "All 5 dimensions closed → closure is closed",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-004B",
          "manifest_claim": "No capability without 5 closed dimensions",
          "description": "4/5 closed (authority suspended) → closure is NOT closed",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-005",
          "manifest_claim": "Capability cannot outlive dependencies",
          "description": "deriveValidUntil must return MIN bound (≤ dependency freshness_valid_until)",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-006A",
          "manifest_claim": "Consumed capability shall not execute",
          "description": "Consumed capability → isCapabilityValid = false",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-006B",
          "manifest_claim": "Revoked capability shall not execute",
          "description": "Revoked capability → isCapabilityValid = false",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-006C",
          "manifest_claim": "Expired capability shall not execute",
          "description": "Expired capability → isCapabilityValid = false",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-007",
          "manifest_claim": "Execution requires current state at boundary",
          "description": "Authority revoked at boundary → atomicExecutionCheck blocks",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-008",
          "manifest_claim": "Simulation cannot create production capability",
          "description": "A SIMULATION capability with SUSPENDED state → isCapabilityValid = false",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-009",
          "manifest_claim": "Override cannot mutate original",
          "description": "Override creates new state; original verdict remains unchanged",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-010",
          "manifest_claim": "Evidence preserves historical state",
          "description": "Revocation does not delete the capability; it marks it REVOKED (history preserved)",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-011",
          "manifest_claim": "Source authenticity ≠ real-world truth",
          "description": "BoundState BOUNDARIES explicitly declare this distinction",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        },
        {
          "test_id": "CONF-012",
          "manifest_claim": "Domain logic cannot define execution-rights semantics",
          "description": "Gate verdicts EXECUTE/AUTHORIZED/PERMISSION_GRANTED are all rejected",
          "expected": "RUNTIME_ENFORCES",
          "actual": "ENFORCED",
          "pass": true,
          "detail": "Manifest claim is enforced by runtime."
        }
      ]
    }
  ]
}