{
  "evidence_id": "evi:apeiris:PA-02:2026-07-15-9f3c1a20",
  "schema_version": "v1",
  "subject": {
    "type": "deployment",
    "id": "agt_accounts_payable_ops@production",
    "display_name": "Accounts-Payable Operations Agent (production)",
    "version": "2026.07.15"
  },
  "producer_verifier": "apeiris-control-core@authority-evaluator",
  "consumer_verifiers": [
    "finance-controls-plane",
    "enterprise-approval-gateway"
  ],
  "control_refs": ["apeiris://authority/controls/PA-02"],
  "evidence_type": "automated-test-result",
  "scope": "Single action pay_a1b2c3 (payments.ach.create, USD 18,500 to newly-added payee vendor_northwind_ltd) evaluated against the agent's delegated approval limit.",
  "collected_at": "2026-07-15T13:52:04Z",
  "valid_until": "2026-07-15T14:52:04Z",
  "collection_method": "Deterministic authorization check: compare the action amount and payee-novelty against the principal's delegated approval-limit policy for this agent.",
  "integrity": {
    "hash": "sha256:0a9f1c7d2e5b8a34c6f0d1e2b3a4c5d6e7f8091a2b3c4d5e6f708192a3b4c5d6",
    "signature": "MEUCIQ-illustrative-detached-ed25519-signature-not-a-real-key",
    "signing_key_id": "ed25519-authority-evaluator-01"
  },
  "result": "fail",
  "confidence": "high",
  "findings": [
    {
      "finding_id": "F-01",
      "severity": "high",
      "description": "The action amount (USD 18,500) to a newly-added payee exceeds the agent's delegated approval limit (USD 5,000 for payees added within 30 days). PA-02 requires the action to fall within the delegated limit or carry a higher-authority approval; neither condition is met.",
      "remediation": "Obtain a human-in-the-loop approval (AO-04) from a higher approval authority and bind it to this exact action (PA-11 approval-object binding) before settlement. Splitting the payment to stay under the limit does not satisfy PA-02 for a newly-added payee."
    }
  ]
}
