{
  "changes": [
    {
      "after": {
        "level": "write",
        "origin": "workflow",
        "scope": "id-token"
      },
      "before": null,
      "category": "workflow_permission",
      "changeId": "CGPD-073DE666252629F71D72F8B4",
      "classification": "privilege_added",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "Workflow permission id-token expanded to write.",
      "policyStatus": "unacknowledged",
      "severity": "critical"
    },
    {
      "after": {
        "identityClass": "federated_oidc",
        "writeCapable": true
      },
      "before": null,
      "category": "identity",
      "changeId": "CGPD-09C4B2688462199CA3F9D478",
      "classification": "identity_inherited",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "A workflow gained a production-capable federated OIDC identity declaration.",
      "policyStatus": "unacknowledged",
      "severity": "critical"
    },
    {
      "after": false,
      "before": true,
      "category": "handoff_authority",
      "changeId": "CGPD-0F0EE9D1284BB181883D57A1",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": "agents.yml",
        "surfaceId": null,
        "surfaceKind": "handoff"
      },
      "message": "An agent handoff lost its declared authority boundary.",
      "policyStatus": "unacknowledged",
      "severity": "critical"
    },
    {
      "after": {
        "additionalPropertiesState": "open",
        "inputPropertyCount": 1,
        "inputSchemaPresent": true,
        "outputSchemaPresent": false,
        "sideEffectClass": "financial"
      },
      "before": null,
      "category": "tool",
      "changeId": "CGPD-2A90ACFC4C7B178E61979A18",
      "classification": "privilege_added",
      "direction": "expansion",
      "location": {
        "path": ".mcp.json",
        "surfaceId": "cgasc-tool-907043e380514910d24b",
        "surfaceKind": "tool"
      },
      "message": "A new financial tool entered the declared agent surface.",
      "policyStatus": "unacknowledged",
      "severity": "critical"
    },
    {
      "after": {
        "additionalPropertiesState": "unknown",
        "inputPropertyCount": 0,
        "inputSchemaPresent": false,
        "outputSchemaPresent": false,
        "sideEffectClass": "financial"
      },
      "before": null,
      "category": "tool",
      "changeId": "CGPD-2C1C4AFE96D8893FF8352016",
      "classification": "privilege_added",
      "direction": "expansion",
      "location": {
        "path": "agents.yml",
        "surfaceId": "cgasc-tool-07547ee52123778dd00b",
        "surfaceKind": "tool"
      },
      "message": "A new financial tool entered the declared agent surface.",
      "policyStatus": "unacknowledged",
      "severity": "critical"
    },
    {
      "after": "approval_bypass",
      "before": null,
      "category": "approval_requirement",
      "changeId": "CGPD-8D01B3FE2ACD2814069BA508",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": "AGENTS.md",
        "surfaceId": "cgasc-instruction-a54ff182c7e8acf56acf",
        "surfaceKind": "instruction"
      },
      "message": "An instruction source gained an approval-bypass signal.",
      "policyStatus": "unacknowledged",
      "severity": "critical"
    },
    {
      "after": "open",
      "before": "closed",
      "category": "tool_schema_control",
      "changeId": "CGPD-03DC94780E93BEEDB9DCB8FD",
      "classification": "control_weakened",
      "direction": "expansion",
      "location": {
        "path": "agents.yml",
        "surfaceId": "cgasc-tool-9aa7a3dd5aefb1616d0e",
        "surfaceKind": "tool"
      },
      "message": "A tool input schema became more open.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "unowned",
      "before": "explicit",
      "category": "ownership_control",
      "changeId": "CGPD-0FE6C0F6438DC42883779C25",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": "agents.yml",
        "surfaceId": "cgasc-agent-076610424f41b7b56c8e",
        "surfaceKind": "ownership"
      },
      "message": "A control surface lost proven ownership coverage.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "unowned",
      "before": "explicit",
      "category": "ownership_control",
      "changeId": "CGPD-113EA26573E62B0F79734077",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": ".mcp.json",
        "surfaceId": "cgasc-mcp-70fef42dad9486974d4d",
        "surfaceKind": "ownership"
      },
      "message": "A control surface lost proven ownership coverage.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "pull_request_target",
      "before": null,
      "category": "deployment_or_trust_entry",
      "changeId": "CGPD-1BF7BFFD813CC5CDCE5FB84A",
      "classification": "privilege_added",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "Workflow gained the pull_request_target trigger.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "automatic_release",
      "before": null,
      "category": "instruction_risk_signal",
      "changeId": "CGPD-23D49DB1361CFFE7D8B4EDB3",
      "classification": "privilege_expanded",
      "direction": "expansion",
      "location": {
        "path": "AGENTS.md",
        "surfaceId": "cgasc-instruction-a54ff182c7e8acf56acf",
        "surfaceKind": "instruction"
      },
      "message": "An instruction source gained the automatic_release risk signal.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": 2,
      "before": 0,
      "category": "supply_chain_control",
      "changeId": "CGPD-3E8AF5021D6A4E916F82ECC1",
      "classification": "control_weakened",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "A workflow gained unpinned external action dependencies.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": {
        "identityClass": "github_action",
        "local": false,
        "pinClass": "mutable_ref",
        "pinned": false
      },
      "before": {
        "identityClass": "github_action",
        "local": false,
        "pinClass": "commit_digest",
        "pinned": true
      },
      "category": "supply_chain_control",
      "changeId": "CGPD-4223385D312707C5D4D3C39E",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-external-dependency-5ad03aa009d991ae3ed5",
        "surfaceKind": "external_dependency"
      },
      "message": "An external dependency lost its immutable pin.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "remote_https",
      "before": "local_stdio",
      "category": "network_destination",
      "changeId": "CGPD-4365EC41C9EAEE67DC29BA64",
      "classification": "privilege_expanded",
      "direction": "expansion",
      "location": {
        "path": ".mcp.json",
        "surfaceId": "cgasc-mcp-70fef42dad9486974d4d",
        "surfaceKind": "mcp_server"
      },
      "message": "An MCP server moved to a more exposed transport class.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": {
        "errorClass": "invalid_json",
        "status": "parse_error"
      },
      "before": null,
      "category": "evidence_coverage",
      "changeId": "CGPD-7A09C211D52CB5BA38C09EC2",
      "classification": "evidence_degraded",
      "direction": "expansion",
      "location": {
        "path": "ai.config.json",
        "surfaceId": null,
        "surfaceKind": "evidence"
      },
      "message": "A supported configuration input can no longer be parsed.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "not_declared",
      "before": "immutable_version",
      "category": "mcp_package_integrity",
      "changeId": "CGPD-85AB88F2173A08C45AC8F4AF",
      "classification": "control_weakened",
      "direction": "expansion",
      "location": {
        "path": ".mcp.json",
        "surfaceId": "cgasc-mcp-70fef42dad9486974d4d",
        "surfaceKind": "mcp_server"
      },
      "message": "An MCP package integrity pin was weakened.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "unowned",
      "before": "explicit",
      "category": "ownership_control",
      "changeId": "CGPD-94A9578FAC3B771191EB36CF",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "ownership"
      },
      "message": "A control surface lost proven ownership coverage.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "unowned",
      "before": "explicit",
      "category": "ownership_control",
      "changeId": "CGPD-958ED8040B5D27E7186447F5",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": "AGENTS.md",
        "surfaceId": "cgasc-instruction-a54ff182c7e8acf56acf",
        "surfaceKind": "ownership"
      },
      "message": "A control surface lost proven ownership coverage.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": {
        "level": "write",
        "origin": "workflow",
        "scope": "contents"
      },
      "before": {
        "level": "read",
        "origin": "workflow",
        "scope": "contents"
      },
      "category": "workflow_permission",
      "changeId": "CGPD-A9334F7015D7E326FFECA41D",
      "classification": "privilege_expanded",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "Workflow permission contents expanded to write.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "unowned",
      "before": "explicit",
      "category": "ownership_control",
      "changeId": "CGPD-B1DE53BEA7A4C51F322E5929",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": ".mcp.json",
        "surfaceId": "cgasc-repository-root",
        "surfaceKind": "ownership"
      },
      "message": "A control surface lost proven ownership coverage.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": {
        "identityClass": "github_action",
        "pinClass": "mutable_ref",
        "pinned": false
      },
      "before": null,
      "category": "deployment_path",
      "changeId": "CGPD-CBFD2CA8F78F3737A8372BB7",
      "classification": "privilege_added",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-external-dependency-5b1ccc6c2f35d1ef8069",
        "surfaceKind": "external_dependency"
      },
      "message": "A deployment-like external dependency entered the workflow graph.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": 2,
      "before": 1,
      "category": "agent_tool_authority",
      "changeId": "CGPD-D760B77F19E4270DBCCE9B4F",
      "classification": "privilege_expanded",
      "direction": "expansion",
      "location": {
        "path": "agents.yml",
        "surfaceId": "cgasc-agent-a15ea33d7dab04b48ca4",
        "surfaceKind": "agent"
      },
      "message": "An agent gained declared tool references.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "persistent_memory",
      "before": null,
      "category": "instruction_risk_signal",
      "changeId": "CGPD-DA5CA213F6D9AADDFDFB57A2",
      "classification": "privilege_expanded",
      "direction": "expansion",
      "location": {
        "path": "AGENTS.md",
        "surfaceId": "cgasc-instruction-a54ff182c7e8acf56acf",
        "surfaceKind": "instruction"
      },
      "message": "An instruction source gained the persistent_memory risk signal.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": 1,
      "before": 0,
      "category": "command_execution",
      "changeId": "CGPD-E5B56B71FC686018C3F04F8C",
      "classification": "privilege_expanded",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "A workflow gained declared shell command steps.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "external_egress",
      "before": null,
      "category": "instruction_risk_signal",
      "changeId": "CGPD-E610E48775308ABD2DB7A8AD",
      "classification": "privilege_expanded",
      "direction": "expansion",
      "location": {
        "path": "AGENTS.md",
        "surfaceId": "cgasc-instruction-a54ff182c7e8acf56acf",
        "surfaceKind": "instruction"
      },
      "message": "An instruction source gained the external_egress risk signal.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "unowned",
      "before": "explicit",
      "category": "ownership_control",
      "changeId": "CGPD-F8341D2E66E3032A155A02EA",
      "classification": "control_removed",
      "direction": "expansion",
      "location": {
        "path": "agents.yml",
        "surfaceId": "cgasc-agent-a15ea33d7dab04b48ca4",
        "surfaceKind": "ownership"
      },
      "message": "A control surface lost proven ownership coverage.",
      "policyStatus": "unacknowledged",
      "severity": "high"
    },
    {
      "after": "30b8ee63c0f64d8538e500a29168d2294b509c12cc3ba693c4c66a5c9b336b47",
      "before": "ce76021d18b557f1b9d9622c9fe82df95eb2009e398de8a763c059700094852a",
      "category": "instruction_content",
      "changeId": "CGPD-3D508506E0076C64704F7AF8",
      "classification": "informational",
      "direction": "neutral",
      "location": {
        "path": "AGENTS.md",
        "surfaceId": "cgasc-instruction-a54ff182c7e8acf56acf",
        "surfaceKind": "instruction"
      },
      "message": "An instruction source changed content.",
      "policyStatus": "unacknowledged",
      "severity": "medium"
    },
    {
      "after": 2,
      "before": 1,
      "category": "tool_input_scope",
      "changeId": "CGPD-43034007DA3187891AA18FF2",
      "classification": "privilege_expanded",
      "direction": "expansion",
      "location": {
        "path": "agents.yml",
        "surfaceId": "cgasc-tool-9aa7a3dd5aefb1616d0e",
        "surfaceKind": "tool"
      },
      "message": "A tool gained declared input fields.",
      "policyStatus": "unacknowledged",
      "severity": "medium"
    },
    {
      "after": {
        "category": "api_token_or_secret",
        "count": 2,
        "surfaceClass": "workflow"
      },
      "before": null,
      "category": "credential_access",
      "changeId": "CGPD-4324A23E55F1B8787F8A1311",
      "classification": "privilege_added",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "secret_category"
      },
      "message": "A surface gained references to the api_token_or_secret credential category.",
      "policyStatus": "unacknowledged",
      "severity": "medium"
    },
    {
      "after": {
        "providerClass": "google",
        "routeClass": "primary"
      },
      "before": null,
      "category": "model_route",
      "changeId": "CGPD-72D332379D64011B4350FE7E",
      "classification": "surface_added",
      "direction": "expansion",
      "location": {
        "path": "agents.yml",
        "surfaceId": "cgasc-model-6f90c26df2de95da3f91",
        "surfaceKind": "model"
      },
      "message": "A new model route entered the declared surface.",
      "policyStatus": "unacknowledged",
      "severity": "medium"
    },
    {
      "after": "workflow_dispatch",
      "before": null,
      "category": "workflow_trigger",
      "changeId": "CGPD-96A19E820A078F30AA6842E7",
      "classification": "privilege_added",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "Workflow gained the workflow_dispatch trigger.",
      "policyStatus": "unacknowledged",
      "severity": "medium"
    },
    {
      "after": 2,
      "before": 1,
      "category": "external_dependency",
      "changeId": "CGPD-FDAE1B84645A370D4B8E063C",
      "classification": "privilege_added",
      "direction": "expansion",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "A workflow gained external action dependencies.",
      "policyStatus": "unacknowledged",
      "severity": "medium"
    },
    {
      "after": "none",
      "before": "package_runner",
      "category": "mcp_command",
      "changeId": "CGPD-0DF1FB1B51578C301802AC3A",
      "classification": "risk_reduced",
      "direction": "reduction",
      "location": {
        "path": ".mcp.json",
        "surfaceId": "cgasc-mcp-70fef42dad9486974d4d",
        "surfaceKind": "mcp_server"
      },
      "message": "An MCP server reduced its command-launch class.",
      "policyStatus": "unacknowledged",
      "severity": "low"
    },
    {
      "after": null,
      "before": {
        "additionalPropertiesState": "closed",
        "inputPropertyCount": 1,
        "inputSchemaPresent": true,
        "outputSchemaPresent": false,
        "sideEffectClass": "read"
      },
      "category": "tool",
      "changeId": "CGPD-47CE0A1186AA9304B93474C6",
      "classification": "surface_removed",
      "direction": "reduction",
      "location": {
        "path": ".mcp.json",
        "surfaceId": "cgasc-tool-4a6ea5080477171b40a8",
        "surfaceKind": "tool"
      },
      "message": "A tool left the declared agent surface.",
      "policyStatus": "unacknowledged",
      "severity": "low"
    },
    {
      "after": null,
      "before": "pull_request",
      "category": "workflow_trigger",
      "changeId": "CGPD-6C971332A024085008BBE605",
      "classification": "risk_reduced",
      "direction": "reduction",
      "location": {
        "path": ".github/workflows/agent.yml",
        "surfaceId": "cgasc-workflow-415e16004e27bf2dc86e",
        "surfaceKind": "workflow"
      },
      "message": "Workflow removed the pull_request trigger.",
      "policyStatus": "unacknowledged",
      "severity": "low"
    },
    {
      "after": null,
      "before": {
        "providerClass": "openai",
        "routeClass": "primary"
      },
      "category": "model_route",
      "changeId": "CGPD-C7605CB91357747BBDA57C64",
      "classification": "surface_removed",
      "direction": "reduction",
      "location": {
        "path": "agents.yml",
        "surfaceId": "cgasc-model-18fe55beaabdf9d2e770",
        "surfaceKind": "model"
      },
      "message": "A model route left the declared surface.",
      "policyStatus": "unacknowledged",
      "severity": "low"
    }
  ],
  "claimBoundary": "CapitalGuard Privilege Diff 0.1 compares two exact, signed private Agent Surface Compiler 0.1 snapshots. It detects declared capability and control changes represented by the published compiler support matrix without executing repository code, workflows, commands, tools, models, MCP servers, or network requests. A reported change does not prove runtime behavior, exploitation, complete discovery, or protection, and unchanged configuration is not proof of safety.",
  "comparison": {
    "baseline": {
      "generatedAt": "2026-07-27T13:30:00.000Z",
      "inventorySha256": "04793789557a7f16dcf49c6ca42f0a4d153bdc964bf43b78e8315dff33fd157d",
      "receiptSha256": "ffabcd033cf65da9e62dee7b46348776203b3f95880bd3a9fc6d1cda4529a91a",
      "repositoryFingerprintSha256": "b7b4da0edfaa772b8c6e1cd0ca0b502486aeded333441cfe7375140af9e6750e",
      "semanticDigestSha256": "0d79039956f974972492fbfaed925b7fda00c6f937415e638712c73f882a93c6"
    },
    "candidate": {
      "generatedAt": "2026-07-27T13:35:00.000Z",
      "inventorySha256": "a07cb778acb0cd7d1e7ec530167aeb3d8a416ecc68ba165125e4ebe42d5757d5",
      "receiptSha256": "e3957a6f3a7fa2f8cc3d05cf2f66b558fe89d5d9e11e1fb731b65ce303f073c7",
      "repositoryFingerprintSha256": "acc2994db2b79917d9d1dc6b8697a7262ebe16bcf67e7d2ef84ec877f10c2c7e",
      "semanticDigestSha256": "25298c3c2987e77ce83f9fbb4a9ef78dc9543097629e7b59fb81d0db8486de42"
    },
    "compilerSignerKeySha256": "503d8ee46d581c649966569ae095e27041de83322e8e0480e5539e00d2d5d874",
    "subjectBindingSha256": "bb4fbf4a5343f2ab2595bd22f022a36f59baf47dc194f19ae304147ca6d4e530"
  },
  "decision": {
    "blockingChangeIds": [
      "CGPD-03DC94780E93BEEDB9DCB8FD",
      "CGPD-073DE666252629F71D72F8B4",
      "CGPD-09C4B2688462199CA3F9D478",
      "CGPD-0F0EE9D1284BB181883D57A1",
      "CGPD-0FE6C0F6438DC42883779C25",
      "CGPD-113EA26573E62B0F79734077",
      "CGPD-1BF7BFFD813CC5CDCE5FB84A",
      "CGPD-23D49DB1361CFFE7D8B4EDB3",
      "CGPD-2A90ACFC4C7B178E61979A18",
      "CGPD-2C1C4AFE96D8893FF8352016",
      "CGPD-3E8AF5021D6A4E916F82ECC1",
      "CGPD-4223385D312707C5D4D3C39E",
      "CGPD-4365EC41C9EAEE67DC29BA64",
      "CGPD-7A09C211D52CB5BA38C09EC2",
      "CGPD-85AB88F2173A08C45AC8F4AF",
      "CGPD-8D01B3FE2ACD2814069BA508",
      "CGPD-94A9578FAC3B771191EB36CF",
      "CGPD-958ED8040B5D27E7186447F5",
      "CGPD-A9334F7015D7E326FFECA41D",
      "CGPD-B1DE53BEA7A4C51F322E5929",
      "CGPD-CBFD2CA8F78F3737A8372BB7",
      "CGPD-D760B77F19E4270DBCCE9B4F",
      "CGPD-DA5CA213F6D9AADDFDFB57A2",
      "CGPD-E5B56B71FC686018C3F04F8C",
      "CGPD-E610E48775308ABD2DB7A8AD",
      "CGPD-F8341D2E66E3032A155A02EA"
    ],
    "evidenceDegradationChangeIds": [
      "CGPD-7A09C211D52CB5BA38C09EC2"
    ],
    "result": "block",
    "reviewChangeIds": [
      "CGPD-03DC94780E93BEEDB9DCB8FD",
      "CGPD-073DE666252629F71D72F8B4",
      "CGPD-09C4B2688462199CA3F9D478",
      "CGPD-0F0EE9D1284BB181883D57A1",
      "CGPD-0FE6C0F6438DC42883779C25",
      "CGPD-113EA26573E62B0F79734077",
      "CGPD-1BF7BFFD813CC5CDCE5FB84A",
      "CGPD-23D49DB1361CFFE7D8B4EDB3",
      "CGPD-2A90ACFC4C7B178E61979A18",
      "CGPD-2C1C4AFE96D8893FF8352016",
      "CGPD-3D508506E0076C64704F7AF8",
      "CGPD-3E8AF5021D6A4E916F82ECC1",
      "CGPD-4223385D312707C5D4D3C39E",
      "CGPD-43034007DA3187891AA18FF2",
      "CGPD-4324A23E55F1B8787F8A1311",
      "CGPD-4365EC41C9EAEE67DC29BA64",
      "CGPD-72D332379D64011B4350FE7E",
      "CGPD-7A09C211D52CB5BA38C09EC2",
      "CGPD-85AB88F2173A08C45AC8F4AF",
      "CGPD-8D01B3FE2ACD2814069BA508",
      "CGPD-94A9578FAC3B771191EB36CF",
      "CGPD-958ED8040B5D27E7186447F5",
      "CGPD-96A19E820A078F30AA6842E7",
      "CGPD-A9334F7015D7E326FFECA41D",
      "CGPD-B1DE53BEA7A4C51F322E5929",
      "CGPD-CBFD2CA8F78F3737A8372BB7",
      "CGPD-D760B77F19E4270DBCCE9B4F",
      "CGPD-DA5CA213F6D9AADDFDFB57A2",
      "CGPD-E5B56B71FC686018C3F04F8C",
      "CGPD-E610E48775308ABD2DB7A8AD",
      "CGPD-F8341D2E66E3032A155A02EA",
      "CGPD-FDAE1B84645A370D4B8E063C"
    ]
  },
  "evidence": {
    "baseline": {
      "candidateFiles": 25,
      "parseErrorCount": 0,
      "parsedFiles": 5,
      "skippedFileCount": 0
    },
    "baselineIncomplete": false,
    "candidate": {
      "candidateFiles": 25,
      "parseErrorCount": 1,
      "parsedFiles": 5,
      "skippedFileCount": 0
    },
    "candidateIncomplete": true,
    "degraded": true
  },
  "generatedAt": "2026-07-27T13:40:00.000Z",
  "policy": {
    "digestSha256": "246b25f2f5910518ccb595500e5d113edac05078720f6aef3aca68df01e5c087",
    "value": {
      "acknowledgedChangeIds": [],
      "blockAtOrAbove": "high",
      "failClosedOnEvidenceDegradation": true,
      "reviewAtOrAbove": "medium",
      "schemaVersion": "cg-privilege-diff-policy-0.1.0"
    }
  },
  "privacy": {
    "absolutePathsIncluded": false,
    "mode": "private",
    "namesAndPathsIncluded": true,
    "rawCommandsIncluded": false,
    "rawSecretValuesIncluded": false,
    "rawToolArgumentsIncluded": false,
    "repositoryIdentityIncluded": false,
    "sourceContentsIncluded": false,
    "subjectIdentifierIncluded": false
  },
  "schemaVersion": "cg-privilege-diff-0.1.0",
  "semanticDigestAlgorithm": "sha256",
  "semanticDigestSha256": "ba4b4e1f063ef47e1df997e1d0ad95ea270ef7a6a8737014639e00b7c4a8f4c1",
  "summary": {
    "acknowledgedChangeCount": 0,
    "blockingChangeCount": 26,
    "byClassification": {
      "control_removed": 9,
      "control_weakened": 3,
      "evidence_degraded": 1,
      "identity_inherited": 1,
      "informational": 1,
      "privilege_added": 8,
      "privilege_expanded": 8,
      "risk_reduced": 2,
      "surface_added": 1,
      "surface_removed": 2
    },
    "byDirection": {
      "expansion": 31,
      "neutral": 1,
      "reduction": 4
    },
    "bySeverity": {
      "critical": 6,
      "high": 20,
      "low": 4,
      "medium": 6
    },
    "changeCount": 36,
    "evidenceDegradationCount": 1,
    "reviewChangeCount": 32
  },
  "version": "0.1.0"
}
