Gateway quorum · hosted lab theater
Multi-role approval conditions — without live capital.
Walk authorize, deny, and replay check lists that mirror @runbook/engine/gateway semantics. Browser does not import node:crypto evaluation. Full signed quorum evaluation remains MCP/CLI.
fixture theater · full crypto evaluation is MCP/CLI
Fixture scenarios
Authorize · deny · replay
Authorize · 2-of-2 role quorum
Owner + risk both approve a live broker.order.submit with distinct registered keys, valid windows, and matching digests.
- request.time-validPASS
- request.policy-boundPASS
- idempotency.uniquePASS
- idempotency.binding-validPASS
- approval.ids-uniquePASS
- approval.approvers-distinctPASS
- approval.authorities-registeredPASS
- approval.bindings-validPASS
- approval.signatures-validPASSFixture outcome · not live verify()
- approval.windows-validPASS
- approval.lifetimes-validPASS
- approval.no-vetoPASS
- approval.quorum-metPASS
- approval.roles-metPASS
- authorizationConditionsSatisfied is not mayExecute
- Host may still bypass Runbook
- Self-asserted demo keys only
- fixture theater · full crypto evaluation is MCP/CLI
- authorize ≠ order placement
Web Crypto · 2 roles
Owner + risk signing demo
Generates ephemeral Ed25519 key pairs for owner and risk, signs a demo approval payload, and verifies both signatures in-browser. This is not approvalSigningPayload / evaluateActionAuthorization — those require node:crypto and stay on MCP/CLI.
No signing demo run yet.
- not-broker-issued
- not-live-capital
- not-identity-proof
- browser-fixture-not-engine-evaluate
- full-crypto-evaluation-is-mcp-cli
- no-mayExecute-authority
Select a fixture scenario or run the 2-role Web Crypto signing demo. Full evaluateActionAuthorization is MCP/CLI only.