LayerCodeMeaningTerminalExposurePrimary tests
MandateVAGP_MANDATE_REVOCATION_REQUIREMENT_INVALIDA mandate lacks an acceptable status channel or finite freshness requirement.YesExternal summary safevagp-0.2-revocation-latency
MandateVAGP_MANDATE_FINANCIAL_APPLICABILITY_INVALIDFinancial applicability declaration is malformed or outside the mandate authority.YesExternal summary safevagp-0.2-financial-applicability
AttenuationVAGP_ATTENUATION_REVOCATION_LATENCY_WIDENEDA child authority tries to loosen the parent freshness ceiling.YesExternal summary safevagp-0.2-revocation-latency
AttenuationVAGP_ATTENUATION_FINANCIAL_APPLICABILITY_REMOVEDA child authority tries to remove an issuer-required financial classification.YesExternal summary safevagp-0.2-financial-applicability
PathVAGP_PATH_STATUS_FRESHNESS_PROFILE_EXCEEDEDObserved mandate status is older than the applicable freshness ceiling.YesExternal summary safevagp-0.2-revocation-latency
RESOLVEVAGP_RESOLVE_FINANCIAL_CONTEXT_REQUIREDIssuer-required financial evaluation was applicable but trusted financial context was absent.YesExternal summary safevagp-0.2-financial-applicability
BINDVAGP_BINDING_PATH_SELECTION_MISMATCHThe bound path does not match the canonical selected qualifying path.YesExternal summary safebound-authority-decision, vagp-0.2-one-grant-per-decision
BINDVAGP_REQUEST_IDENTITY_CONFLICTOne Request Identity was reused with changed closed semantic fields.YesExternal summary safevagp-0.2-one-grant-per-decision
DERIVEVAGP_DERIVE_REQUEST_ALREADY_USEDA second semantic grant was attempted for the same consumed Request Identity.YesExternal summary safevagp-0.2-one-grant-per-decision
VERIFYVAGP_VERIFY_REQUEST_ALREADY_USEDA second successful VERIFY was attempted for the same Request Identity.YesExternal summary safevagp-0.2-one-grant-per-decision
VERIFYVAGP_VERIFY_REQUEST_IDENTITY_MISMATCHThe execution attempt does not carry the same Request Identity as the grant.YesExternal summary safevagp-0.2-trusted-input-versioning
VERIFYVAGP_VERIFY_PARAMETERS_DIGEST_MISMATCHProvider-submitted parameters differ from the BIND-fixed digest.YesExternal summary safevagp-0.2-trusted-input-versioning
VERIFYVAGP_VERIFY_TRUSTED_CONTEXT_MISMATCHExecution-time trusted context differs from the bound authority decision.YesExternal summary safevagp-0.2-execution-time-trusted-context
VERIFYVAGP_VERIFY_VERSION_MISMATCHThe artifact version at verification does not match v0.2 processing rules.YesExternal summary safevagp-0.2-trusted-input-versioning
Trusted inputVAGP_TRUSTED_INPUT_IDENTITY_NOT_AUTHENTICIdentity provenance was missing, forged or not accepted by the trusted binder.YesExternal summary safevagp-0.2-trusted-input-versioning
Trusted inputVAGP_TRUSTED_INPUT_IDENTITY_MISMATCHTrusted identity does not match the agent/request identity being evaluated.YesExternal summary safevagp-0.2-trusted-input-versioning
ClockVAGP_CLOCK_INVALIDAccepted time input is missing, malformed or unauthentic.YesExternal summary safevagp-0.2-trusted-input-versioning
ClockVAGP_CLOCK_BACKDATEDA trusted-time value moves behind an accepted high-water mark.YesExternal summary safevagp-0.2-trusted-input-versioning
StatusVAGP_STATUS_EVIDENCE_NOT_AUTHENTICMandate lifecycle/status evidence lacks acceptable trusted provenance.YesExternal summary safevagp-0.2-revocation-latency
CorpusVAGP_MANDATE_CORPUS_NOT_AUTHENTICThe mandate corpus source is unauthenticated, unattested or ambiguous.YesExternal summary safevagp-0.2-trusted-input-versioning
VersionVAGP_VERSION_MISMATCHArtifacts from another protocol version reached a v0.2 boundary.YesExternal summary safevagp-0.2-trusted-input-versioning
VersionVAGP_MIXED_VERSION_PATHOne authority path combines artifacts from incompatible semantic versions.YesExternal summary safevagp-0.2-trusted-input-versioning
MigrationVAGP_MIGRATION_AGENT_VERSION_CONFLICTOne agent is not pinned to exactly one runtime version during migration.YesExternal summary safevagp-0.2-trusted-input-versioning
MigrationVAGP_MIGRATION_REQUEST_VERSION_CONFLICTOne Request Identity is presented under more than one semantic version.YesExternal summary safevagp-0.2-trusted-input-versioning
ExecutionVAGP_EXECUTION_REQUEST_ALREADY_SUBMITTEDThe provider submission boundary was reached more than once for one consumed request.YesExternal summary safevagp-0.2-one-grant-per-decision
WitnessVAGP_WITNESS_INVALID_INPUTWitness construction or projection received unauthentic, malformed or over-broad input.YesExternal summary safevagp-0.2-authority-witness