Delegation boundary benchmark 0.1
Stop authority from growing at handoff.
CapitalGuard matched all twelve declared outcomes in a fixed synthetic test of signed agent delegation, authority attenuation, binding, depth, and single use.
One valid root-to-child chain was accepted. Nine boundary violations were rejected. Sequential and concurrent double-consume tests each admitted exactly one request.
CapitalGuard Security Research · Version 0.1.0 · Tested July 29, 2026
Case-level evidence
Every declared boundary matched.
| Case | Boundary | Test | Expected | Observed | Result |
|---|---|---|---|---|---|
| CGADB-TV-001 | signed chain | Valid root-to-child delegation | accepted | accepted | Match |
| CGADB-TV-002 | signature integrity | Signed child field changed | rejected | rejected | Match |
| CGADB-TV-003 | strict schema | Unknown envelope field | rejected | rejected | Match |
| CGADB-TV-004 | actor binding | Request actor differs from child subject | rejected | rejected | Match |
| CGADB-TV-005 | capability scope | Request outside delegated capability | rejected | rejected | Match |
| CGADB-TV-006 | policy binding | Verification policy differs from issued policy | rejected | rejected | Match |
| CGADB-TV-007 | authority attenuation | Child attempts authority amplification | rejected | rejected | Match |
| CGADB-TV-008 | time attenuation | Child extends parent expiry | rejected | rejected | Match |
| CGADB-TV-009 | parent digest | Child attached to a different parent | rejected | rejected | Match |
| CGADB-TV-010 | chain depth | Delegation exceeds maximum depth | rejected | rejected | Match |
| CGADB-TV-011 | single use | Sequential double-consume | exactly one accepted | exactly one accepted | Match |
| CGADB-TV-012 | atomic single use | Concurrent double-consume | exactly one accepted | exactly one accepted | Match |
Reproducible release
Inspect the fixtures and verify the bindings.
The release includes a disclosed synthetic test key, fixed signed envelopes, scenario declarations, JSON and CSV results, methodology, a dependency-free fixture/results verifier, and a SHA-256 manifest. The public verifier checks consistency; it does not independently attest the publisher-run execution.
Run digest: 985ead1f08b1d44b17f2a8ca229c8f931602c25863b03180ecf932f5779dbd7c
What this evidence does not prove
This publisher-operated synthetic benchmark records twelve declared outcomes from CapitalGuard Delegation Firewall 0.1.0 using fixed fixtures. It does not assess a customer system, compare vendors, independently attest the publisher-run execution, prove every malformed delegation is rejected, control handoffs that bypass the firewall, or guarantee agent security.
All agents, requests, paths, policies, timestamps, keys, and repository roots are deterministic synthetic fixtures.
The twelve cases cover declared boundaries, not the complete input or concurrency space of every agent framework or delegation protocol.
The public verifier checks fixed envelope signatures, fixture and result bindings, and declared invariants; it does not independently execute or attest the proprietary firewall.
Atomic single use depends on all relevant delegation and execution paths sharing the protected local ledger.
Operations that bypass the Delegation Firewall and Agent Action Gateway remain outside this result.
Primary sources checked July 29, 2026
Apply the boundary
