# A-030

- **Artifact ID:** A-030
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-030
- **Machine-record SHA-256:** `a0a62d87e88a3e5f847d2b4b851f82f7857fda75b5ddf366b95a78e12a8f657f`

## Complete structured record

```json
{
  "id": "A-030",
  "statement": "The identity provider boundary constitutes the identity perimeter",
  "status": "ACTIVE",
  "category": "Under Pressure",
  "ledger_references": [
    "2026-03-16 — Match Group SSO bypass. Identity trust extended beyond IdP boundary through federated SSO without downstream verification.",
    "2026-03-16 — OAuth redirect abuse. Authorization flow manipulation allowed identity assertion outside the governing IdP's verification surface.",
    "2026-03-16 — OAuth consent token misbinding. Consent tokens issued under one identity context were accepted under a different identity context, breaking the IdP boundary assumption."
  ],
  "related_positions": []
}
```
