capability-package-secure-payment-webhook-v1Secure Payment Webhook
ForgeLayer intersected platform, workspace, repository, task, policy, approval, verification, expiry, revocation, and budget controls. The result cannot expand platform authority.
- Workspace
- ForgeLayer Guided Beta
- Controlled Task
- controlled-task-secure-payment-webhook
- Repository
- acme-payments/payment-webhook-service
- Branch
- demo/secure-payment-webhook
- Policy snapshot
- policy-snapshot-5cc8bbf1
- Package version
- task-capability-package-v1
- Expiry
- Not Expired
- Revocation
- Not Revoked
Allowed preview scope
exact:app/api/payments/webhook.ts exact:tests/payment-webhook.test.ts
Blocked scope
directory:lib/auth directory:config glob:**/.env* glob:**/secrets/**
Evidence
- missingsecurity_review_evidence
- missingrollback_plan
Verification
- missingpayment_webhook_security
- missingauth_session_boundary
Approval policy definitions
Current evaluator status: Satisfied
- policy definitionowner
Why authority is denied
- read metadata is globally disabled.
- Trusted server identity is not enabled.
- Production authentication and persistence are disabled.
- Active trusted workspace membership is required.
- A validated workspace-owned repository connection is required.
- Evidence required: security_review_evidence.
- Evidence required: rollback_plan.
- Verification required: payment_webhook_security.
- Verification required: auth_session_boundary.
- Repository access, agent dispatch, execution, network, secrets, GitHub writes, pull requests, workflows, and automatic merge are globally disabled.
- The package is an internal preview and no active authority was issued.
Current next: Approval requirement satisfied. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.