At 10am, an agent gets authorization to send data to a partner. The grant expires at noon. Plenty of time. At 11am, that partner loses access. Role revoked, scope changed, authorization gone. At 11:30, the agent tries to send. It checks the clock. Grant still valid. It proceeds. Nothing caught it. Not because the system failed. Because the system was only checking the clock — and the clock had no idea the world had changed underneath it. That is the gap CLAIM-24 is testing. Where we are honestly We do not have external claim evidence yet. We want to be clear about that upfront. What we have is a harness with seven locked scenarios, a confirmed baseline failure, and a validated code path. What we do not have is an external source — a real memory store, policy registry, or permission layer that the agent did not author — to run the full claim against. That matters because running a gate against data you wrote yourself is just self-description with extra steps. So this article is not a result.…