One check, applied to eight kinds of action.

The engine holds no knowledge of any domain. It compares the action arriving at execution against the action that was authorized and refuses the difference, which is why one check covers a payment, a machine dispatch, a claim or a hiring decision.

Eight actions, eight refusals.

Each row is one authorized action, the action that reached execution, and what the boundary did with it.

ActionAuthorizedWhat arrivedThe refusal
Release a paymentGBP 1,800 to account 4821the same payment to account 9137MAY_NOT_CHANGE on parameters.payee_account
Dispatch a machinepallet P1842 to aisle 4, max 1.5 m/saisle 7, max 2.0 m/sMAY_NOT_CHANGE and MAY_NOT_INCREASE on destination and speed
Call a tool on your behalfrefund order ACME-4471, up to USD 200refund order ACME-4471 at USD 1,850MAY_ONLY_SHRINK on the amount
Reject or advance a candidatereject 88-402 on a reason inside the authorized screening setquestion 4 was never askedMAY_NOT_CHANGE on the stated reason
Change infrastructuredrop table sessions_archive in stagingthe same drop in productionMAY_NOT_CHANGE on parameters.target_environment
Settle a claimclaim C-2291 at USD 4,200, clause 7.2the same claim at USD 12,400MAY_NOT_INCREASE on the amount
Determine a prior authorizationdeny PA-77310 on the documented criteria setcriterion not evaluated on the recordMAY_NOT_CHANGE on the stated basis
Change a vendor accountremittance account for supplier 4471 to 4821, verified by call-backthe same change to 9137, no call-back recordedMAY_NOT_CHANGE on the account and the verification step

The engine holds no knowledge of any domain. One check covers all eight.

Change one value, and watch it refuse.

The sandbox runs one action class on the live service with synthetic data. Nothing needs installing, and no money moves. Humsana holds none of your policy and sits outside the agent's trust domain.