Object binding
Does the action still target the exact customer, order, booking, account or resource it was authorized for?
The Entry Audit is the smallest paid BitEvo engagement. We test one action chain and one primary control or failure hypothesis in staging/test by default, preserve the evidence, and return a bounded owner decision.
Examples include refunds, order changes, reservations, CRM writes, account updates, external messages, deployment changes and other actions whose result matters outside the agent itself.
Does the action still target the exact customer, order, booking, account or resource it was authorized for?
Does confirmation remain tied to the exact material action parameters rather than a generic approval state?
Did the intended downstream change actually happen, and can the resulting state be read back?
Can timeout, retry or replay duplicate a consequential effect or continue under stale state?
Is the acting identity and credential narrower than the total capability exposed by the tool?
A useful result may be PASS, FAIL, PARTIAL, REJECTED HYPOTHESIS or BLOCKED. Success is not defined as finding a vulnerability.
Not included: full penetration testing, certification, legal/compliance opinion, unrestricted production exploitation, system-wide safety claims or open-ended implementation. Broader remediation is separately scoped only when the evidence justifies it.
Prepare the bounded scope