01 / Attack path
How the boundary is crossed
An agent inserts a forged approval identifier into a payment request after the finance reviewer denied it.
- 01Lower-trust input
- 02Attempted instruction
- 03Protected action
- 04Enforced decision
02 / Containment
Where bounded authority limits the effect
Validate issuer, integrity, subject, exact action, target, expiry and consumption state at the payment boundary.
03 / Failure and evidence
The attacker’s opportunity and the defender’s record
The executor accepts a syntactically plausible approval ID without resolving its trusted issuer and scope.
Retain presented grant reference, validation failure, attempted transfer and actual bank state.
04 / Canonical scope
Why this reference stands alone
Chain tampering changes an existing delegation path; this threat fabricates an authority artifact.
Protocol or attack trace
Forged approval trace
Payment agent submits a fabricated approval ID after the reviewer denied the transfer.
Resolve ID from trusted issuer, verify subject, payee, amount and unused state; reject unknown ID.
Primary references