CLAIM-24 tested stale cached grants.
CLAIM-25 tested signed responses that were authentic but not fresh.
Both were runtime authorization problems. The question was: should the agent be allowed to act right now?
CLAIM-26 moves one layer later.
After the action is taken, can an auditor reconstruct exactly what authority justified it?






