CLAIM-24 tested stale cached grants.

CLAIM-25 tested signed responses that were authentic but not fresh.

Both were runtime authorization problems. The question was: should the agent be allowed to act right now?

CLAIM-26 moves one layer later.

After the action is taken, can an auditor reconstruct exactly what authority justified it?