{
  "packVersion": "1.0.0",
  "published": "2026-08-17",
  "license": "CC-BY-4.0",
  "purpose": "Implementation-neutral negative fixtures for a request-bound AI agent authorization boundary.",
  "decisionContract": {
    "results": ["allow", "deny", "approval_required", "uncertain"],
    "requiredObservations": [
      "result",
      "reasonCodes",
      "domainCallCount",
      "transactionState"
    ],
    "rule": "An exception, missing dependency or malformed decision must never be mapped to allow."
  },
  "baselineContext": {
    "version": 1,
    "transactionId": "txn:fixture:0001",
    "agent": {
      "id": "agent:finance:ap-worker-3",
      "organizationId": "org:buyer:eu-1",
      "passportDigest": "sha256:passport-active-001",
      "proofKeyId": "key:agent:2026-08"
    },
    "mandate": {
      "id": "mandate:finance:ap-442",
      "digest": "sha256:mandate-active-442",
      "parentDigest": "sha256:mandate-parent-100"
    },
    "request": {
      "action": "supplier-payment.create",
      "resource": "invoice:INV-8841",
      "counterparty": "supplier:northwind",
      "purpose": "settle-approved-supplier-invoice",
      "destination": "bank-destination:northwind:primary",
      "amountMinor": 2500000,
      "currency": "EUR",
      "bodyDigest": "sha256:normalized-request-0001"
    },
    "control": {
      "audience": "https://payments.internal.example",
      "policyDigest": "sha256:policy-2026-08-17",
      "approvalDigest": "sha256:approval-for-request-0001",
      "idempotencyKey": "idem:fixture:0001",
      "issuedAt": "2026-08-17T12:00:00Z",
      "expiresAt": "2026-08-17T12:05:00Z"
    }
  },
  "baselineState": {
    "evaluationTime": "2026-08-17T12:01:00Z",
    "agentStatus": "active",
    "mandateStatus": "active",
    "mandateNotBefore": "2026-08-17T11:55:00Z",
    "mandateExpiresAt": "2026-08-17T12:10:00Z",
    "mandateUsesRemaining": 1,
    "maximumAmountMinor": 2500000,
    "allowedCurrency": "EUR",
    "approvalStatus": "active",
    "approvalContextDigest": "sha256:normalized-request-0001",
    "expectedOrganizationId": "org:buyer:eu-1",
    "expectedAudience": "https://payments.internal.example",
    "trustCacheAgeSeconds": 5,
    "maximumTrustCacheAgeSeconds": 30,
    "policyService": "available",
    "replayStore": "available",
    "transactionClaimed": false,
    "protectedSystemBehavior": "accept"
  },
  "cases": [
    {
      "id": "AUTHZ-REQ-001",
      "controlIds": ["AUTH-01", "AUTH-03", "AUTH-04", "AUTH-16"],
      "kind": "single_request",
      "title": "Valid request at the amount boundary",
      "mutation": null,
      "expected": {"result": "allow", "reasonCodes": [], "domainCallCount": 1, "transactionState": "succeeded"}
    },
    {
      "id": "AUTHZ-REQ-002",
      "controlIds": ["AUTH-01"],
      "kind": "single_request",
      "title": "Revoked agent",
      "mutation": {"target": "state", "op": "replace", "path": "/agentStatus", "value": "revoked"},
      "expected": {"result": "deny", "reasonCodes": ["AGENT_REVOKED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-003",
      "controlIds": ["AUTH-02"],
      "kind": "single_request",
      "title": "Organization binding mismatch",
      "mutation": {"target": "context", "op": "replace", "path": "/agent/organizationId", "value": "org:other:eu-9"},
      "expected": {"result": "deny", "reasonCodes": ["ORGANIZATION_MISMATCH"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-004",
      "controlIds": ["AUTH-03", "AUTH-24"],
      "kind": "single_request",
      "title": "Expired mandate",
      "mutation": {"target": "state", "op": "replace", "path": "/mandateExpiresAt", "value": "2026-08-17T11:59:59Z"},
      "expected": {"result": "deny", "reasonCodes": ["MANDATE_EXPIRED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-005",
      "controlIds": ["AUTH-03", "AUTH-24"],
      "kind": "single_request",
      "title": "Mandate not active yet",
      "mutation": {"target": "state", "op": "replace", "path": "/mandateNotBefore", "value": "2026-08-17T12:02:00Z"},
      "expected": {"result": "deny", "reasonCodes": ["MANDATE_NOT_ACTIVE"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-006",
      "controlIds": ["AUTH-04"],
      "kind": "single_request",
      "title": "Action outside delegated authority",
      "mutation": {"target": "context", "op": "replace", "path": "/request/action", "value": "supplier-payment.cancel"},
      "expected": {"result": "deny", "reasonCodes": ["ACTION_DENIED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-007",
      "controlIds": ["AUTH-04"],
      "kind": "single_request",
      "title": "Resource outside delegated authority",
      "mutation": {"target": "context", "op": "replace", "path": "/request/resource", "value": "invoice:INV-9999"},
      "expected": {"result": "deny", "reasonCodes": ["RESOURCE_DENIED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-008",
      "controlIds": ["AUTH-05"],
      "kind": "single_request",
      "title": "Purpose substitution",
      "mutation": {"target": "context", "op": "replace", "path": "/request/purpose", "value": "accelerate-unapproved-supplier-payment"},
      "expected": {"result": "deny", "reasonCodes": ["PURPOSE_DENIED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-009",
      "controlIds": ["AUTH-06"],
      "kind": "single_request",
      "title": "Counterparty substitution",
      "mutation": {"target": "context", "op": "replace", "path": "/request/counterparty", "value": "supplier:contoso"},
      "expected": {"result": "deny", "reasonCodes": ["COUNTERPARTY_DENIED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-010",
      "controlIds": ["AUTH-06", "AUTH-15"],
      "kind": "single_request",
      "title": "Destination substitution after approval",
      "mutation": {"target": "context", "op": "replace", "path": "/request/destination", "value": "bank-destination:attacker:new"},
      "expected": {"result": "deny", "reasonCodes": ["DESTINATION_DENIED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-011",
      "controlIds": ["AUTH-07"],
      "kind": "single_request",
      "title": "Amount one minor unit above the limit",
      "mutation": {"target": "context", "op": "replace", "path": "/request/amountMinor", "value": 2500001},
      "expected": {"result": "deny", "reasonCodes": ["AMOUNT_EXCEEDED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-012",
      "controlIds": ["AUTH-07"],
      "kind": "single_request",
      "title": "Currency substitution",
      "mutation": {"target": "context", "op": "replace", "path": "/request/currency", "value": "USD"},
      "expected": {"result": "deny", "reasonCodes": ["CURRENCY_DENIED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-013",
      "controlIds": ["AUTH-08"],
      "kind": "single_request",
      "title": "Child delegation widens the action set",
      "mutation": {"target": "state", "op": "add", "path": "/delegationViolation", "value": "action_widened"},
      "expected": {"result": "deny", "reasonCodes": ["DELEGATION_ACTION_WIDENED"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-014",
      "controlIds": ["AUTH-09"],
      "kind": "single_request",
      "title": "Unknown request field",
      "mutation": {"target": "context", "op": "add", "path": "/request/overrideDestination", "value": "bank-destination:attacker:new"},
      "expected": {"result": "deny", "reasonCodes": ["UNKNOWN_FIELD"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-015",
      "controlIds": ["AUTH-10", "AUTH-11"],
      "kind": "single_request",
      "title": "Protected body field changes without a new digest",
      "mutation": {"target": "context", "op": "replace", "path": "/request/bodyDigest", "value": "sha256:digest-for-different-body"},
      "expected": {"result": "deny", "reasonCodes": ["BODY_DIGEST_MISMATCH"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-016",
      "controlIds": ["AUTH-12"],
      "kind": "single_request",
      "title": "Credential presented to the wrong audience",
      "mutation": {"target": "context", "op": "replace", "path": "/control/audience", "value": "https://admin.internal.example"},
      "expected": {"result": "deny", "reasonCodes": ["AUDIENCE_MISMATCH"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-017",
      "controlIds": ["AUTH-13"],
      "kind": "single_request",
      "title": "Policy service timeout for a material action",
      "mutation": {"target": "state", "op": "replace", "path": "/policyService", "value": "timeout"},
      "expected": {"result": "deny", "reasonCodes": ["POLICY_UNAVAILABLE"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-018",
      "controlIds": ["AUTH-14"],
      "kind": "single_request",
      "title": "Policy digest changes after approval",
      "mutation": {"target": "context", "op": "replace", "path": "/control/policyDigest", "value": "sha256:policy-unreviewed-new"},
      "expected": {"result": "deny", "reasonCodes": ["POLICY_DIGEST_MISMATCH"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-019",
      "controlIds": ["AUTH-15"],
      "kind": "single_request",
      "title": "Approval digest does not match the request",
      "mutation": {"target": "state", "op": "replace", "path": "/approvalContextDigest", "value": "sha256:normalized-request-other"},
      "expected": {"result": "approval_required", "reasonCodes": ["EXACT_APPROVAL_REQUIRED"], "domainCallCount": 0, "transactionState": "awaiting_approval"}
    },
    {
      "id": "AUTHZ-SEQ-001",
      "controlIds": ["AUTH-16"],
      "kind": "sequence",
      "title": "Transaction replay",
      "steps": [
        {"call": 1, "mode": "ordered", "expected": {"result": "allow", "domainCallCount": 1}},
        {"call": 2, "mode": "ordered", "reuse": ["transactionId", "idempotencyKey"], "expected": {"result": "deny", "reasonCodes": ["REPLAY_DETECTED"], "additionalDomainCallCount": 0}}
      ],
      "expected": {"result": "deny", "reasonCodes": ["REPLAY_DETECTED"], "domainCallCount": 1, "transactionState": "succeeded"}
    },
    {
      "id": "AUTHZ-SEQ-002",
      "controlIds": ["AUTH-07", "AUTH-17"],
      "kind": "sequence",
      "title": "Two concurrent requests consume one remaining use",
      "steps": [
        {"call": 1, "mode": "concurrent", "uniqueTransactionId": true},
        {"call": 2, "mode": "concurrent", "uniqueTransactionId": true}
      ],
      "expected": {"result": "allow_one", "reasonCodes": ["USAGE_EXHAUSTED"], "domainCallCount": 1, "transactionState": "one_succeeded_one_rejected"}
    },
    {
      "id": "AUTHZ-REQ-020",
      "controlIds": ["AUTH-19"],
      "kind": "single_request",
      "title": "Replay state unavailable for a material write",
      "mutation": {"target": "state", "op": "replace", "path": "/replayStore", "value": "unavailable"},
      "expected": {"result": "deny", "reasonCodes": ["REPLAY_STATE_UNAVAILABLE"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-SEQ-003",
      "controlIds": ["AUTH-18", "AUTH-20", "AUTH-22"],
      "kind": "sequence",
      "title": "Protected system accepts the request but its response is lost",
      "steps": [
        {"call": 1, "mode": "ordered", "protectedSystemBehavior": "accept_and_drop_response", "expected": {"result": "uncertain", "domainCallCount": 1}},
        {"call": 2, "mode": "reconcile", "reuse": ["idempotencyKey"], "expected": {"result": "allow", "additionalDomainCallCount": 0}}
      ],
      "expected": {"result": "uncertain", "reasonCodes": ["EXECUTION_OUTCOME_UNKNOWN"], "domainCallCount": 1, "transactionState": "reconciliation_required"}
    },
    {
      "id": "AUTHZ-REQ-021",
      "controlIds": ["AUTH-21", "AUTH-22"],
      "kind": "single_request",
      "title": "Evidence record omits the policy digest",
      "mutation": {"target": "state", "op": "add", "path": "/evidenceMutation", "value": "remove_policy_digest"},
      "expected": {"result": "deny", "reasonCodes": ["EVIDENCE_INCOMPLETE"], "domainCallCount": 0, "transactionState": "verification_failed"}
    },
    {
      "id": "AUTHZ-REQ-022",
      "controlIds": ["AUTH-23"],
      "kind": "single_request",
      "title": "Trust cache exceeds the material-action stale window",
      "mutation": {"target": "state", "op": "replace", "path": "/trustCacheAgeSeconds", "value": 31},
      "expected": {"result": "deny", "reasonCodes": ["TRUST_STATE_STALE"], "domainCallCount": 0, "transactionState": "rejected"}
    },
    {
      "id": "AUTHZ-REQ-023",
      "controlIds": ["AUTH-24"],
      "kind": "single_request",
      "title": "Proof uses a retired key after its overlap window",
      "mutation": {"target": "state", "op": "add", "path": "/proofKeyStatus", "value": "retired_outside_overlap"},
      "expected": {"result": "deny", "reasonCodes": ["KEY_RETIRED"], "domainCallCount": 0, "transactionState": "rejected"}
    }
  ]
}
