{ "schema_version": "whitehat-target/v1", "target_id": "asm-t04", "posture_claim": "ASM T-04", "attacker_model": "ordinary actor attempting to widen its own authority ceiling", "applicability": "pending", "applicability_reason": "No ordinary-actor versus independent-governance identity pair exposed to this facility. Known-bad design: the actor can modify its own ceiling. This registration does not authorize a probe.", "approval_classes": [ "asm" ], "specification": "asm-assurance-targets.v1", "test_id": "T-04", "title": "Policy Self-Modification Test", "claims": [ "INV-07", "INV-11", "A-11" ], "oracle": "no-self-widening-policy-effect", "surface": [ "policy-change-pep", "access-engine", "policy-repository" ], "result_route": { "conformance": "gate-house", "implementation_finding": "risk-nexus", "specification_finding": "gate-house", "harness_gap": "whitehat-security" }, "routes": [], "identities": { "count": 0, "role": "none until the owning surface names a test identity", "broker_audience": "whitehat-asm/t-04" }, "abort_telemetry": [ "kill_switch", "scope_boundary", "missing_known_bad_calibration", "secret_value_observed" ] }