{
  "checks": [
    {
      "test": "HTTPS catalog links route to isolated product origins; private and anonymous APIs denied",
      "pass": true,
      "detail": null
    },
    {
      "test": "six real OIDC sign-ins; Protocol \u2192 Task Hub \u2192 catalog SSO without another password",
      "pass": true,
      "detail": null
    },
    {
      "test": "legacy password bypass is disabled",
      "pass": true,
      "detail": null
    },
    {
      "test": "host-only HttpOnly sessions are bound to a product; copying a cookie to another product fails",
      "pass": true,
      "detail": null
    },
    {
      "test": "Protocol creates a real persisted Draft instance; duplicate submission does not start another process",
      "pass": true,
      "detail": null
    },
    {
      "test": "record ownership, task ownership, CSRF, Origin and actor spoofing checks enforce access",
      "pass": true,
      "detail": null
    },
    {
      "test": "Protocol attachment upload and download work with the new session authentication",
      "pass": true,
      "detail": null
    },
    {
      "test": "central submission runs the Java delegate through the integration service and creates parallel review/sign tasks",
      "pass": true,
      "detail": null
    },
    {
      "test": "decline requires a comment; a declined reviewer can later approve",
      "pass": true,
      "detail": null
    },
    {
      "test": "engine and platform restart preserve process/task IDs and authenticated sessions",
      "pass": true,
      "detail": null
    },
    {
      "test": "chairman signing completes BPMN and cancels pending review tasks; replay cannot complete twice",
      "pass": true,
      "detail": null
    },
    {
      "test": "active substitute can sign; original chairman cannot bypass the existing business rule",
      "pass": true,
      "detail": null
    },
    {
      "test": "central product-access revocation is enforced by the business API without waiting for token expiry",
      "pass": true,
      "detail": null
    },
    {
      "test": "expired access tokens refresh server-side with rotated refresh tokens",
      "pass": true,
      "detail": null
    },
    {
      "test": "independent full-stack NextJS product starts BPMN through shared integration and receives its completed review result",
      "pass": true,
      "detail": null
    },
    {
      "test": "a user without a product grant cannot enter the starter through its direct URL",
      "pass": true,
      "detail": null
    },
    {
      "test": "integration execution audit records confirm actual Protocol callback routing",
      "pass": true,
      "detail": {
        "completedCallbacks": 6
      }
    },
    {
      "test": "service credentials cannot impersonate another product or bypass authentication",
      "pass": true,
      "detail": null
    },
    {
      "test": "platform sign-out invalidates every product session including copied cookies",
      "pass": true,
      "detail": null
    },
    {
      "test": "auth and product database credentials cannot connect to another service database",
      "pass": true,
      "detail": null
    }
  ],
  "evidence": {
    "protocolId": "cmu81ogyg0000ml24sg8xkeor",
    "instanceId": "bcc27df0-b3f8-11f1-b511-f2c58560c183",
    "starterRequestId": "843d5730-146a-4fed-b1ec-949db964642a"
  }
}