# A-010

- **Artifact ID:** A-010
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-010
- **Machine-record SHA-256:** `1e969a747375a45b68d660c3ce583d5fdc813ce1ac0bbe6e12b7952e2b11b874`

## Complete structured record

```json
{
  "id": "A-010",
  "statement": "Operational delegation preserves local verification authority within the governed perimeter",
  "status": "ACTIVE",
  "category": "Closure & Governance Signals",
  "ledger_references": [
    "2026-02-18 — Daily Pressure Record. Delegation identified as sovereignty transfer. Execution layer is vendor-sovereign; liability layer is consumer-sovereign. No revocation primitives at delegation boundary.",
    "2026-03-11 — SN-2026-03-11-01. CVE-2026-26144 — Excel runtime delegated network egress to Copilot Agent without local verification boundary. Zero-click exfiltration via runtime delegation bypass."
  ],
  "related_positions": []
}
```
