Authenticated request
A request signed with the expected control key was accepted for its exact active session.
Managed-session stop path
In this synthetic test run, every declared stop-path assertion matched before any external action could occur.
The result covers only sessions created through the tested managed path. It is not a customer-environment audit or a guarantee that every agent can be stopped.
Download Test SummaryCase-level summary
A request signed with the expected control key was accepted for its exact active session.
An altered request was rejected before termination was attempted.
An expired request was rejected before termination was attempted.
A request targeting a different managed session was rejected.
Two concurrent uses of one request produced one accepted response and one replay rejection.
The synthetic broker-close callback completed before process termination was signalled.
A non-responsive synthetic process received the bounded termination sequence.
The test recorded a lifecycle event without exposing the raw test actor identifier.
Altered response or state evidence failed verification.
A synthetic launch failure closed the broker path and did not leave a managed process running.
State and socket tests rejected unsafe symlink boundary conditions.
A normal synthetic completion recorded closure without a stop request.
Generated request, state, and response fields matched their strict public contracts.
The supervisor claim boundary states that it cannot stop agents launched outside its managed path.
The run used test doubles only: no customer systems, production keys, or external agents were executed.
Use it before an incident
Define who may stop a job, which exact session the request can target, how replay is rejected, what gets shut down first, how long termination may take, and where privacy-reduced evidence is retained.
Open the pre-flight checklistPrimary sources checked 2026-07-31
These sources support control-design and risk-management principles. They do not certify this test summary or CapitalGuard.