{
  "schema_version": "1.0.0",
  "artifact_id": "artifact:when-the-agent-had-to-ask-github",
  "status": "complete-pending-hosted-validation",
  "authority_receipt": "docs/publication/issue-389/EVIDENCE_RELATIONSHIP_AUTHORITY.json",
  "evidence_posture": "The provider-behavior observation is bound to controlled Control Tower evidence and a private GitHub Support response. Current GitHub primary documentation independently corroborates the client-facing revocation contract, not the observed propagation interval.",
  "current_primary_sources": [
    {
      "title": "REST API endpoints for GitHub App installations",
      "locator": "https://docs.github.com/en/rest/apps/installations",
      "role": "Current primary documentation for the installation-token revocation endpoint and successful HTTP 204 response."
    },
    {
      "title": "GitHub credential types",
      "locator": "https://docs.github.com/en/organizations/managing-programmatic-access-to-your-organization/github-credential-types",
      "role": "Current primary credential-lifecycle and revocation context for GitHub App installation access tokens."
    }
  ],
  "claim_bindings": [
    {
      "claim": "Brief post-204 authentication acceptance occurred in controlled reproductions.",
      "support": "Private GitHub Support provider authority plus exact Control Tower field evidence.",
      "boundary": "No claim of a global maximum propagation interval, independent endpoint caches, or provider-wide convergence moment."
    },
    {
      "claim": "HTTP 204 is the documented successful revocation response and later authenticated use requires a new installation token.",
      "support": "Current GitHub primary documentation plus provider clarification.",
      "boundary": "This does not imply instantaneous provider-wide convergence."
    },
    {
      "claim": "The final external support submission remained a human action.",
      "support": "Issue #389 owner authority plus Control Tower escalation lineage.",
      "boundary": "The agent is not represented as independently opening or owning the external support relationship."
    }
  ],
  "reader_relationships": [
    {
      "type": "foundation",
      "target_id": "artifact:the-agent-is-not-the-product-the-control-plane-is",
      "label": "Start with the governed control-plane boundary",
      "href": "/artifacts/the-agent-is-not-the-product-the-control-plane-is/"
    },
    {
      "type": "foundation",
      "target_id": "artifact:stop-prompting-agents-start-managing-workers",
      "label": "Start with bounded worker authority",
      "href": "/artifacts/stop-prompting-agents-start-managing-workers/"
    }
  ],
  "withheld_reader_relationships": [
    {
      "target_id": "artifact:the-mesh-is-no-longer-a-diagram",
      "reason": "Target remains protected Development with public=false."
    },
    {
      "target_id": "artifact:the-mesh-held",
      "reason": "Target remains a Development candidate without owner acceptance or Production release."
    },
    {
      "target_id": "artifact:inference-at-the-ambiguity-frontier",
      "reason": "Target remains on separate unmerged PR #388 and is not canonical on this base."
    }
  ],
  "historical_uat": {
    "head": "f2d856d79c83932c883ea85101514226167b9732",
    "disposition": "technical proof only; new exact-head UAT required after authority repair"
  },
  "public_boundary": "No credential values, private keys, authorization headers, email addresses, App/installation identifiers, raw request IDs, or full Support correspondence are exposed."
}
