# CHQ-SC-2026-001

- **Artifact ID:** CHQ-SC-2026-001
- **Status:** RATIFIED
- **Public record:** https://record.cybersecurityhq.com/conditions/chq-sc-2026-001
- **Machine-record SHA-256:** `de4d84c7014eb0ffd9e3b3db5d95899979a240fd623823511e749b42a2ecc36e`

## Complete structured record

```json
{
  "id": "CHQ-SC-2026-001",
  "name": "Trust Boundary Inversion",
  "domain": "Identity",
  "status": "RATIFIED",
  "persistence": "REINFORCING",
  "first_observed": "2026-02-26",
  "reinforcement": {
    "date": "2026-05-04",
    "evidence": "CHQ-EX-2026-019",
    "basis": "The exhibit expressly references SC-001 and records an additional trusted-channel authority boundary failure."
  },
  "definition": "Systems designed to separate trusted from untrusted actors increasingly allow adversaries to operate through the trusted channel itself.",
  "linked_positions": [
    "CHQ-P-2026-006",
    "CHQ-P-2026-009"
  ],
  "linked_evidence": [
    "CHQ-EX-2026-019",
    "CHQ-P-2026-006",
    "CHQ-P-2026-009"
  ],
  "falsification_condition": "Across two consecutive quarters, no confirmed campaign or incident shows an adversary operating through an authenticated or otherwise trusted channel, AND independently evaluated controls prevent trusted-channel abuse at scale across the identity, integration, and management surfaces in scope.",
  "evidence_count": 3,
  "last_reinforced": "2026-05-04",
  "linked_assumptions": [],
  "linked_constraints": [],
  "rating": "NOT RATED",
  "outlook": "n/a",
  "watch": "n/a",
  "escalation_criterion": "Not on the weekly board",
  "deescalation_criterion": "n/a",
  "rating_as_of": "2026-09-22",
  "rating_source": "Structural Condition Report Issue 39"
}
```
