{
  "abstractInjectedCondition": "synthetic credential replay or identity-policy violation",
  "assuranceClaimIds": [
    "AC-K05-C04",
    "AC-K05-C05"
  ],
  "canonicalUrl": "https://xn--mwe.com/evaluation-range/scenarios/workload-identity-compromise/",
  "claimStatus": "PROJECT TECHNICAL PROPOSAL",
  "forbiddenDetails": [
    "exploit or payload instructions",
    "credential theft procedure",
    "persistence or evasion recipe",
    "targeting or engagement thresholds",
    "weapon construction",
    "real-world unauthorized access"
  ],
  "id": "RNG-03",
  "lastReviewed": "2026-08-15",
  "name": "Workload identity compromise",
  "objective": "Evaluate short-lived identity revocation, session termination, lateral-movement containment, and service continuity.",
  "observations": [
    "protected-function state",
    "policy decision and confidence",
    "authority and configuration state",
    "timing and identity health",
    "incident chronology",
    "rollback or safe-state result"
  ],
  "passEvidence": "identity is revoked within target time; unaffected functions continue; decision and rollback evidence is complete",
  "releaseId": "K12-2026-08-16",
  "safetyEnvelope": [
    "isolated range or approved hardware-in-the-loop environment",
    "no production plant or public-network target",
    "synthetic or authorized data and identities",
    "effects-disabled or non-damaging test substitutes",
    "independent stop authority",
    "complete artifact removal and reset evidence"
  ],
  "slug": "workload-identity-compromise"
}
