F.1 Start with a bounded claim
Synthetic claim: For deployment D-47 and mandate W-47, a payment can execute only to the approved beneficiary, for the approved amount and currency, using current authority, exactly-scope-bound approval, and a controlled idempotency key. Claimed completion requires independent reconciliation. This is a proposed assurance argument, not an established enterprise result.
| Argument element | What the case should show | Evidence required | Remaining challenge |
|---|---|---|---|
| Context | The workflow can prepare and execute approved payments; beneficiary changes are excluded. | Mandate, affected resources, action classes, and configuration manifest. | Hidden effect routes or opaque serving changes. |
| Authority mechanism | Resource gateway checks current subject, grant, scope, policy, limits, and revocation. | Route inventory, implementation version, denied and accepted calls. | Subprocess, raw API, background queue, or child bypass. |
| Approval integrity | Reviewed and executed payloads have the same normalized meaning. | Action fields, digest, reviewer rights, expiry, and execution comparison. | Omitted fields, ambiguous normalization, stale or reused consent. |
| Duplicate prevention | Timeout and retry do not create another unintended payment. | Idempotency behavior and independently queried state. | Key expiry, resource-specific semantics, partial and asynchronous outcomes. |
| Outcome verification | Reported completion matches actual resource state. | Receipt and independently observed beneficiary, amount, currency, and status. | Missing records, eventual consistency, compensating actions. |
| Operating response | Revocation stops covered authority and descendants; uncertainty holds retries. | Fault and halt drills, queue state, grant withdrawal, effect reconciliation. | Untested route or recovery dependency. |
| Decision | Requested action class is permitted only within the demonstrated envelope. | Independent challenge, residual gaps, exceptions, scope, owner, and expiry. | Generalization beyond the sampled tasks or revised configuration. |
F.2 State the evidence conclusion precisely
A proposed wording after successful local testing would identify the tested configuration, routes, case population, prohibited-effect definition, observed outcomes, and unresolved gaps. It would avoid a general assertion that the agent is safe. If a critical route remains untested, the release authority should either restrict that route or record a scoped exception with a compensating mechanism.
This handbook does not supply a completed local assurance case. It supplies the structure, proposed tests, example events, and challenge questions needed to assemble one.
F.3 Challenge the case with counterexamples
Try the wrong tenant, wrong beneficiary, payload drift, revoked grant, stale approval, child budget reset, raw API, delayed injection, missing receipt, and lost response after effect. Then test ordinary authorized work and peak review load. Preserve failures and new routes as evidence that reopens the relevant claim.