Authority
Who can approve, whether approval is specific, and whether the governed actor can approve itself.
Answer eight questions to identify possible execution-boundary weaknesses. The self-test runs entirely in this browser and does not submit your answers.
Who can approve, whether approval is specific, and whether the governed actor can approve itself.
Whether the exact approved action can change silently before execution.
Whether required facts and conditions are rechecked when the action occurs.
Whether old approvals or payloads can be reused outside their intended window.
Whether another path can route around the intended decision boundary.
Whether the system can prove approval, action, and result without reconstructing the story.
The result is a prompt for investigation, not authorization to execute.
Fewer obvious issues were selected. Technical verification is still required.
One or more boundaries appear incomplete or insufficiently verified.
A meaningful authority, payload, replay, bypass, or evidence risk is present.
The reviewed workflow should not execute until the unresolved boundary is redesigned.
No. Green means fewer obvious risks were selected in this limited questionnaire. It does not verify implementation or authorize execution.
No. The self-test runs locally in your browser. There is no submission endpoint in this site package.
No. It is an educational boundary-screening tool, not a security audit, legal review, compliance certification, or technical assessment.
Stop execution planning for the affected workflow, identify the exact risk driver, and require technical evidence before reconsidering the action.