An agent whose memory passes every check can still be made to act against its own purpose.

Not because the memory was stale. Not because the grant expired. Not because the principal

was unauthorized. Not because the signature failed. All of those gates can pass cleanly

and the agent can still execute an instruction it should have refused.

That is the gap CLAIM-28 tests.