Human decision for this release
The release evidence is current, but no human has approved this exact release yet.
Release control for AI agents
If the release manager revokes approval or corrects the evidence behind it, that WebMCP capability disappears. The AI cannot approve itself, and stale authority is rejected again at execution time.
Product rule: Capability follows current authority.
Human decision for this release
The release evidence is current, but no human has approved this exact release yet.
Agent
The release tool must stay absent until a human approval matches the current release evidence.
Release inputs
candidateHuman only
These controls are deliberately not WebMCP tools. The agent may inspect the release and request approval; it cannot grant, restore, correct, or revoke its own authority.
60-second judge path
execute_authorized_release, appears.externalSideEffect=false.Why WebMCP is load-bearing
EvidenceBound does not merely hide a denial inside a permanently exposed action. Current human authority changes the tool surface the agent can discover. Execution then revalidates that authority so a stale capability cannot succeed after the decision changes.
Human + agent timeline
Execution evidence
Receipt fingerprints identify this controlled state. They are not claimed as independently anchored or externally durable audit records.
What is actually demonstrated
The judge path is intentionally narrow: one release manager, one exact release, one consequential WebMCP capability. Internally, EvidenceBound distinguishes AUTHORIZED, HUMAN_REQUIRED, STALE, INVALIDATED, and BLOCKED so changed evidence and changed human decisions fail closed.
This WebMCP integration was added during the challenge over pre-existing EvidenceBound control primitives. It does not claim that human approval, provenance, revocation, invalidation, receipts, or dynamic tools were invented here.