{
  "kind": "curated-recorded-observations",
  "recordedAt": "2026-09-30",
  "checkedAt": "2026-10-03",
  "application": "Synthetic Express acceptance fixture",
  "trustClass": "customer-ci",
  "release": "0.1.0-beta.4",
  "treeDigest": "f6de3b78cac43873e872e23b246a6854ea8db589a03743b37adead6ce8e141ec",
  "scope": "Internal rehearsal; not a customer deployment or independent attestation",
  "results": [
    {
      "pr": 10,
      "run": "36728291544",
      "verdict": "FAIL",
      "commit": "87ba7fce9bffd22d92978ae2321d67f30085c3a0",
      "executed": 6,
      "reason": "At least one protection observed behaviour that violates its approved rule.",
      "observations": [
        "POST /payments created a synthetic payment: observed HTTP 201.",
        "GET /payments/{paymentId} read the refunded total: 0.",
        "POST /payments/{paymentId}/refunds with a valid partial amount 5000 of 10000: observed HTTP 201.",
        "GET /payments/{paymentId} read the refunded total: 5000.",
        "POST /payments/{paymentId}/refunds with 5001, which exceeds the remaining 5000: observed HTTP 201.",
        "GET /admin/refunds without credentials: observed HTTP 401; denied, as required."
      ],
      "logSha256": "d918f0c5b9e9c450b31f2caa3a95f3644a2ed4659d69c8e1a4e9f06b6d01f3be",
      "rules": [
        {
          "id": "refund-cap",
          "template": "refund.amount-cap v1",
          "approvedRevision": "303b54929ac2bb99",
          "expected": "After refunding 5000 of a captured 10000, reject a second refund of 5001 with a client error and keep the refunded total at 5000.",
          "verdict": "FAIL"
        },
        {
          "id": "admin-auth",
          "template": "http.auth-required v1",
          "approvedRevision": "1bfdc3a3a658c10e",
          "expected": "Deny GET /admin/refunds without credentials; never return a success status.",
          "verdict": "PASS"
        }
      ],
      "selectionReason": "server.js changed and matched the protected paths. Rules were read from the base commit."
    },
    {
      "pr": 9,
      "run": "36728284777",
      "verdict": "PASS",
      "commit": "ee6fdd3d1bf22b3386d25d981fc57c91a0d59633",
      "executed": 7,
      "reason": "Every selected protection executed its scenario and every observed behaviour satisfied its rule.",
      "observations": [
        "POST /payments created a synthetic payment: observed HTTP 201.",
        "GET /payments/{paymentId} read the refunded total: 0.",
        "POST /payments/{paymentId}/refunds with a valid partial amount 5000 of 10000: observed HTTP 201.",
        "GET /payments/{paymentId} read the refunded total: 5000.",
        "POST /payments/{paymentId}/refunds with 5001, which exceeds the remaining 5000: observed HTTP 422.",
        "GET /payments/{paymentId} read the refunded total: 5000.",
        "GET /admin/refunds without credentials: observed HTTP 401; denied, as required."
      ],
      "logSha256": "974d44e060e2c9e52dbc5a90b48425867fd5be1a2dbfb9604e93a96b3e375b1f",
      "rules": [
        {
          "id": "refund-cap",
          "template": "refund.amount-cap v1",
          "approvedRevision": "303b54929ac2bb99",
          "expected": "After refunding 5000 of a captured 10000, reject a second refund of 5001 with a client error and keep the refunded total at 5000.",
          "verdict": "PASS"
        },
        {
          "id": "admin-auth",
          "template": "http.auth-required v1",
          "approvedRevision": "1bfdc3a3a658c10e",
          "expected": "Deny GET /admin/refunds without credentials; never return a success status.",
          "verdict": "PASS"
        }
      ],
      "selectionReason": "server.js changed and matched the protected paths. Rules were read from the base commit."
    },
    {
      "pr": 13,
      "run": "36728627644",
      "verdict": "UNKNOWN",
      "commit": "61c3eabe4ba692f0e7bfa6ddae1f83d167b3b692",
      "executed": 0,
      "reason": "The tested commit is outside the supported beta profile.",
      "observations": [
        "No behavior executed. The runtime was not started. Neither express nor @nestjs/core was a dependency."
      ],
      "logSha256": "033afa0c5f1611fc1229452ad8c6198e6b2717814574e809e9ebfa8f6b5e3312",
      "rules": [
        {
          "id": "refund-cap",
          "template": "refund.amount-cap v1",
          "approvedRevision": "303b54929ac2bb99",
          "expected": "After refunding 5000 of a captured 10000, reject a second refund of 5001 with a client error and keep the refunded total at 5000.",
          "verdict": "NOT RUN"
        },
        {
          "id": "admin-auth",
          "template": "http.auth-required v1",
          "approvedRevision": "1bfdc3a3a658c10e",
          "expected": "Deny GET /admin/refunds without credentials; never return a success status.",
          "verdict": "NOT RUN"
        }
      ],
      "selectionReason": "server.js changed and matched the protected paths. Rules were read from the base commit."
    }
  ]
}