Nothing crosses into consequence without authority.
CAPPO is the machine-authority kernel: it evaluates whether a requested action fits the identity, capability, policy, budget, time and execution context that were actually granted before a real effect is allowed to proceed.
CAPPO has source, adversarial harnesses and runtime proof paths for authority monotonicity, offline closure, consequence dominance and evidence synchronization. Stronger claims remain scoped to the exact verified deployment profile and consequence paths.
Power stays narrow on purpose.
The surface should tell you where the truth comes from.
Veklom does not promote a configured URL or a code path into a runtime claim. Interfaces are shown so operators can verify the actual boundary themselves.
CAPPO is not a marketing policy dashboard. Its useful claim is narrower and harder: consequence paths that have been brought under the boundary must fail before effect when authority is missing, stale, widened, replayed or exhausted.
