Where Authorization Stops: Effect-Bound Containment, Independent Evidence and the Limits of Preview
Aditya Pratap Singh
Containment for evaluated models usually names a permitted route but not the effects allowed through it. That is the gap the July 2026 incident exploited.
We test three controls on synthetic backends (native Git, an isolated HTTP gateway, API twins) which check authority for the exact effect at the component that executes it, keep backend evidence the actor and broker cannot forge and treat a pre-execution preview as advisory, not proof.
Execution-time checks prevented every tested violation that upstream approval missed (Git 0/6 vs 3/6; HTTP 0/12 vs 8/12) with no loss of legitimate work, and independent backend evidence detected 6/6 executed attacks that intent logs missed.
Our adaptive-quarantine hypothesis was only partly supported: preview missed execution-only faults, so we designed an execution-time effect gate (state and data flow) that closes that gap. We release a nine-control containment standard, every run including negatives, and a one-command offline verifier so a third party can check it without a lab's network.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Where Authorization Stops: Effect-Bound Containment, Independent Evidence and the Limits of Preview
},
author={
Aditya Pratap Singh
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


