The engine holds no knowledge of any domain. It compares the action arriving at execution against the action that was authorized and refuses the difference, which is why one check covers a payment, a machine dispatch, a claim or a hiring decision.
Each row is one authorized action, the action that reached execution, and what the boundary did with it.
| Action | Authorized | What arrived | The refusal |
|---|---|---|---|
| Release a payment | GBP 1,800 to account 4821 | the same payment to account 9137 | MAY_NOT_CHANGE on parameters.payee_account |
| Dispatch a machine | pallet P1842 to aisle 4, max 1.5 m/s | aisle 7, max 2.0 m/s | MAY_NOT_CHANGE and MAY_NOT_INCREASE on destination and speed |
| Call a tool on your behalf | refund order ACME-4471, up to USD 200 | refund order ACME-4471 at USD 1,850 | MAY_ONLY_SHRINK on the amount |
| Reject or advance a candidate | reject 88-402 on a reason inside the authorized screening set | question 4 was never asked | MAY_NOT_CHANGE on the stated reason |
| Change infrastructure | drop table sessions_archive in staging | the same drop in production | MAY_NOT_CHANGE on parameters.target_environment |
| Settle a claim | claim C-2291 at USD 4,200, clause 7.2 | the same claim at USD 12,400 | MAY_NOT_INCREASE on the amount |
| Determine a prior authorization | deny PA-77310 on the documented criteria set | criterion not evaluated on the record | MAY_NOT_CHANGE on the stated basis |
| Change a vendor account | remittance account for supplier 4471 to 4821, verified by call-back | the same change to 9137, no call-back recorded | MAY_NOT_CHANGE on the account and the verification step |
The engine holds no knowledge of any domain. One check covers all eight.
The sandbox runs one action class on the live service with synthetic data. Nothing needs installing, and no money moves. Humsana holds none of your policy and sits outside the agent's trust domain.