Identity remains valid
The payment agent can still authenticate successfully. Authentication answers who the machine is, not whether a newly changed beneficiary lies inside delegated authority.
Changed Beneficiary · Interactive synthetic story
A payment agent is authorized to pay an approved supplier. The agent is still authenticated. Its service credential still exists. The amount is still inside policy. Then the beneficiary account changes. That single fact changes the authority question.
Synthetic scenario: every organization, supplier, account, payment, decision, permit, credential, intervention, and proof state below is fictional. The story runs entirely in your browser and creates no payment or machine authority.
One mutation. Six control moments.
Use the controls to compare the original approved beneficiary with a changed destination. The decision is deterministic and browser-local. The point is not that every beneficiary change must always be denied; the point is that a destination mutation cannot inherit authority merely because surrounding controls remain green.
Enterprise identity resolves the workload and authenticated principal. That matters, but identity does not answer whether this machine may send this payment to this destination.
Identity is an input to authority, never a substitute for it.
browser_local=true · network_calls=0 · payment_effects=0 · authority_effects=0
The trap
The payment agent can still authenticate successfully. Authentication answers who the machine is, not whether a newly changed beneficiary lies inside delegated authority.
A payment API token or vault secret may still be technically retrievable. StableMind treats capability as downstream of authority, so the credential is withheld when permit eligibility disappears.
$428,000 may fit every familiar amount threshold. Destination continuity is a separate consequential dimension; one green limit cannot cancel a changed target.
A recognizable supplier label does not prove the receiving account is the authorized destination. The authority object must bind the consequential target precisely enough to detect the mutation.
The machine-authority response
StableMind does not need to claim the new account is malicious. It only needs to recognize that the known delegation no longer proves permission for the changed destination. That distinction makes the control explainable and fail-closed without pretending certainty about intent.
Normalize the consequential action: send $428,000 USD from the governed account to the exact beneficiary destination associated with SUPPLIER_42.
Resolve who delegated payment power, the permitted supplier and destination, limits, approvals, validity window, and inherited constraints.
Compare the requested destination with the destination bound into the current authority context. A material mismatch prevents silent inheritance.
With the original destination, a narrow Action Permit may be eligible. With the changed destination, fresh human authority is required before a permit can exist.
Execution Fabric does not release a JIT payment credential merely because one exists in a vault. Capability follows the current Action Permit.
If no execution occurs, Evidence records the governed decision path. A synthetic story is not external Proof of Consequence, settlement evidence, or customer production proof.
Identity ≠ authority
Why this scenario matters
To an integration, the change can look like one field in a payment payload. To the enterprise, that field determines where money leaves the organization. Machine Authority Infrastructure treats semantic consequence, not payload size, as the control boundary.
The identity system is not wrong when it says the agent authenticated. The vault is not wrong when it says a credential exists. The payment policy is not wrong when it says the amount is below a threshold. Those systems answer narrower questions. StableMind exists because none of those answers establishes delegated permission for the changed destination.
A machine-authority decision can be conservative without claiming omniscience. StableMind can require fresh human authority because the consequential target changed, even when it has no basis to call the account suspicious, compromised, or fraudulent. The control remains explainable because it rests on authority discontinuity rather than a hidden suspicion score.
The underlying control problem appears whenever the target of an action changes: a new production cluster, a different SaaS tenant, a changed contractual counterparty, a new data destination, or a substituted recipient. The exact policy differs, but the invariant survives: old authority must not silently expand to a materially different consequential target.
Constitutional boundaries
A changed beneficiary can be legitimate. StableMind's public story does not label a person, account, supplier, or transaction fraudulent; it shows that authority must be re-established for the changed consequential target.
The page never calls a payment rail, bank, processor, ERP, vault, or customer system. The fictional accounts exist only in browser state.
“Eligible” is a teaching state. Only governed ActionGate infrastructure operating over real validated authority can issue a real permit.
The scenario does not establish a named customer, blocked loss, prevented fraud, live production action, external Proof of Consequence, recognized revenue, or realized customer value.
A usable secret, token, or payment capability remains insufficient. StableMind's architecture requires the authorization boundary before technical capability is materialized.
A user clicking a story control cannot grant authority. Website sessions, marketing entitlements, signup state, and browser interactions create zero downstream machine power.
Evaluator questions
Public Truth boundary
SIO12 is an architecture-and-product education surface with a browser-local synthetic payment narrative. StableMind.io does not use this interaction to imply customer deployment, a prevented loss, a production payment, financial custody, settlement, recognized revenue, realized value, or external certification.
From one payment to the control plane
Use the Authority Lab to manipulate other consequential facts, or continue into ActionGate to understand the deterministic decision boundary underneath this story. Commercial account bootstrap is introduced in SIO19; SIO21 remains the first governed-action experience.
story_creates_authority=false · story_executes_payment=false · public_signup_active=false