What evidence is stronger than configuration alone?
Behavioural evidence records an attempted action against a known identity and resource state, then captures the actual authorization result. For time-sensitive controls such as revocation, propagation time and token state matter. For isolation, the evidence should show both the permitted owner path and the denied non-owner path.
What should remain explicit?
Untested roles, endpoints, tenants, token types, caches and entitlement paths should remain visible as unresolved conditions rather than being silently absorbed into a broad claim that the API is secure.
