# A-016

- **Artifact ID:** A-016
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-016
- **Machine-record SHA-256:** `8cdfb047760b4ae22469592c95a24dfbfd629fdd5b3fde642b634cc4474ea7eb`

## Complete structured record

```json
{
  "id": "A-016",
  "statement": "Governance authority boundaries align with execution authority boundaries",
  "status": "ACTIVE",
  "category": "Under Pressure",
  "ledger_references": [
    "2026-03-24 — CHQ-P-2026-014 evidence set: Management plane compromise collapses governance and execution authority boundaries at the management layer. An attacker with management plane access has both the authority to define policy and the execution capability to enforce it. Cisco FMC root access pushes policy to all managed firewalls; Oracle OIM compromise redefines what identity means across the enterprise.",
    "2026-03-25 — CHQ-P-2026-015: Execution pipelines exercise governance authority (code selection, credential exposure, distribution) but are not governed as control planes. Governance boundary does not recognize execution pipelines as authority surfaces."
  ],
  "related_positions": []
}
```
