Exact-action mismatch
Change a material field between evidence and effect. The expected result is refusal, even when the original artifact remains valid.
A free, open reference self-test for the last control point before a consequential action. It is format-neutral across a receipt, permit, token, credential, or mandate—and tests whether your boundary keeps each artifact's meaning intact.
AEB does not turn every artifact into an AEB object. The relying party verifies each input under its own rules, joins only verified facts to the exact action, makes a separate local authorization decision, and takes custody of the outcome.
Keep each artifact under its own signature, issuer, audience, freshness, and status rules.
Compare verified evidence to the executor-owned, frozen material action without guessing equivalence.
Evidence satisfaction does not collapse identity, policy, human authority, or local authorization into one verdict.
Atomically consume or reserve one-time authority before dispatch so concurrent replay cannot win twice.
Keep provider outcome separate from observed effect, and reconcile the same operation before any later attempt.
VERIFIED ≠ MATCHED ≠ SATISFIED ≠ AUTHORIZED ≠ RESERVED ≠ INVOKING ≠ PROVIDER OUTCOME ≠ OBSERVED EFFECT
The pack targets the places where valid-looking evidence can still produce an unsafe effect. Every case has a bounded expected result that can be compared across implementations.
Change a material field between evidence and effect. The expected result is refusal, even when the original artifact remains valid.
Present stale or revoked authority—or make a required status source unavailable. Ambiguity must never become permission.
Try to use workload identity as a permit, machine policy as named-human authorization, or another artifact in the wrong evidence slot.
Race or replay the same authority. The reference contract allows one atomic consume or reserve transition, never two effects.
Lose the result after invocation may have begun. Provider outcome and observed effect remain INDETERMINATE, and the original authority stays closed to retry.
Resolve uncertainty only with an authenticated source matched to the same action, operation, provider environment, audience, and target.
A receipt, permit, token, credential, or mandate can enter through a pinned native verifier and adapter. The pack tests consequence-admission behavior at the common boundary; it does not redefine the artifact, its issuer, or what it proves.
Does verified evidence satisfy the requirements for this exact action now, can local policy authorize it once, and can the boundary retain custody when provider outcome or observed effect is unknown?
A deterministic reference pack for checking your implementation's verdicts against the published AEB-1 consequence-admission cases. Run it locally, inspect the vectors, and report the exact scope you tested.
AEB is an individual Internet-Draft. A passing reference run says only that the tested implementation produced the expected results for the tested vectors under the stated configuration. Deployment topology, bypass paths, durable state, trust inputs, and operational controls remain separate evidence. A local atomicity result applies only inside the consequence owner's demonstrated transaction domain; it is not a claim of atomicity across a remote or federated boundary.
npx @emilia-protocol/verify aeb-conformance --reference