Revoked or expired delegation → DENY
If the authority lineage is no longer current, the request fails even when identity and credentials remain valid. Access cannot resurrect expired power.
Authority Lab · Interactive synthetic environment
The Authority Lab is a browser-local way to explore how consequential AI-agent decisions should change when delegation, scope, approvals, targets, consequence capacity, and evidence change. Nothing here touches a customer system. Nothing here creates authority.
Public truth: every scenario, decision, permit state, credential state, intervention state, and proof state on this page is synthetic. The Lab makes the governing rules inspectable without promoting a simulation into production evidence.
Identity can remain valid while authority disappears, narrows, requires a human, or fails closed.
No model decides the result. The public rule order is fixed and visible.
Interactive laboratory
01 / CHANGE THE STATE
Choose a synthetic scenario, alter the authority facts, and inspect the resulting ActionGate decision, permit eligibility, credential posture, Guardian posture, and evidence result. The simulation runs entirely in your browser and sends no scenario data anywhere.
These controls do not represent a connected environment. They are a deterministic teaching model of StableMind's public constitutional rules.
PERMIT
Every selected precondition remains inside the synthetic delegated-authority and consequence boundary.
PERMIT · VALID delegation · EXACT scope · SATISFIED approval · UNCHANGED target · SUFFICIENT consequence capacity · synthetic evidence MATCHED → VERIFIED
browser_local=true · network_calls=0 · authority_effects=0 · execution_effects=0 · external_proof_effects=0
Deterministic rule order
02 / WHY THE RESULT CHANGES
It applies a public precedence order. A hard absence of authority is resolved before softer questions about narrowing or evidence. The point is not that every enterprise will use these exact sample rules; the point is that consequential authorization can be deterministic, attributable, and explainable. Authority Cloud supplies the delegated-authority lineage, while Execution Fabric keeps technical capability downstream of an exact permit.
If the authority lineage is no longer current, the request fails even when identity and credentials remain valid. Access cannot resurrect expired power.
A request beyond the resource, action, destination, purpose, or other granted boundary cannot become authorized because the executor happens to be capable of performing it.
When required reserve is frozen, the public model fails closed. A favorable model forecast, apparent urgency, or available credential cannot waive the missing capacity.
When a consequential target changes after the known authority context, or a required human approval is absent, the machine is routed for fresh authority rather than allowed to infer consent.
If a smaller action remains inside valid authority and reserve, the model demonstrates an explicit narrowed boundary rather than silently expanding the original grant.
Only then is an exact synthetic Action Permit shown as eligible. Even in the Lab, permit eligibility is separate from credential release, execution, evidence, and consequence proof.
Four laboratories
03 / SAME CONSTITUTION, DIFFERENT CONSEQUENCE
Explore amount and destination scope, approval, reserve, JIT payment capability, intervention posture, and synthetic consequence evidence. The full changed-beneficiary narrative arrives in SIO12.
Move a production restart outside scope, freeze recovery capacity, or revoke delegation and watch technical reach remain inert behind the authority boundary.
Role changes, data access, workflow approvals, procurement actions, and records can be bounded even when the underlying SaaS API exposes broad administrator capability.
Partner capability, bilateral trust, and a reachable endpoint do not create the other enterprise's acceptance authority. The corridor must remain explicit and bounded.
What this demonstrates
The useful part of the Lab is not the green PERMIT state. It is watching one changed fact produce a smaller, human-routed, or denied action while the rest of the technical stack remains available.
The public output separates what the agent asked to do from what the synthetic authority state permits. NARROW is not a friendly warning; it is a different executable boundary.
The Lab shows credential eligibility only after a PERMIT or NARROW outcome. It never treats an existing token, vault secret, cloud role, or integration as evidence of authority.
Guardian posture is displayed separately from ActionGate's decision. The intervention plane can preserve or reduce authority effects; it cannot upgrade a denied request into an authorized one.
The synthetic evidence selector teaches VERIFIED, PARTIAL, MISMATCHED, and UNVERIFIABLE states and points toward Proof of Consequence. A favorable proof state does not grant authority, and missing evidence never silently becomes verified.
For evaluators
04 / INTERACTIVE MACHINE AUTHORITY
Public truth boundary
The Authority Lab is intentionally vivid, but every value is synthetic and every decision remains inside the browser. It does not prove that StableMind has authorized, executed, interrupted, verified, or settled a customer action. It does not manufacture named customers, production evidence, recognized revenue, or realized customer value.
From understanding to adoption
SIO11 lets a visitor manipulate synthetic authority facts without connecting infrastructure. Commercial account bootstrap is introduced in SIO19; SIO21 remains the first governed-action experience. Until then, the Lab is deliberately powerless in the real world.
website_session_creates_authority=false · lab_network_effects=0 · public_signup_active=falseFollow the outcome
After experimenting with synthetic authorization, open the Proof Explorer to see why a successful execution receipt still does not self-certify the consequence.