# A-021

- **Artifact ID:** A-021
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-021
- **Machine-record SHA-256:** `9053d4a80c88b742efcc029540d06c7d810e7dbca42baa8c155bca19234e5634`

## Complete structured record

```json
{
  "id": "A-021",
  "statement": "Security authority persists through delegation chains",
  "status": "ACTIVE",
  "category": "Under Pressure",
  "ledger_references": [
    "2026-03-25 — CHQ-P-2026-015: Execution pipelines delegate authority through dependency resolution, action references, and build tool invocation. None of these delegation points verify that the delegated authority is still valid or that the delegatee is the expected entity. TeamPCP campaign demonstrated five delegation boundary crossings without verification.",
    "2026-07-24 — July 2026 npm campaign and third-party integration exfiltration (source: CHQ-AMD-001 evidence): Multiple OIDC publishing identities carried publishing authority in parallel through several legitimate release pipelines without re-verification at any delegation point. Separately, a corporate data plane was exfiltrated through a third-party integration's standing API authority — access granted once, never re-verified at any subsequent use. Both instances demonstrate that delegated authority persists at its original grant value across time and organizational boundaries with no expiry or re-verification primitive."
  ],
  "evidence_count": 2,
  "last_updated": "2026-07-24",
  "related_positions": [
    "CHQ-P-2026-015"
  ]
}
```
