FlowSentinel
Back to examplesSynthetic trust domain · never live evidence
Executable case-study lab

Stress the assurance system without pretending the test is reality.

These scenarios run FlowSentinel's deterministic Assurance Twin, proof-frontier, exact blast-radius, recovery-lifecycle, currentness, and maturity-firewall logic against synthetic inputs. They are regression oracles and product demonstrations—not provider receipts, workspace readiness, or production authority.

Synthetic catalog root

sha256:37b4de1de0a0515ba97bfdaf4e83023b1b3dee45371ab3ba4c2b6ef584a0cc7b

Internal deterministic catalog identity only. Not a signature, provider attestation, external notarization, Assurance Witness production checkpoint, or proof that any customer system was inspected.

10

Executable scenarios

32

Feature synergies

3

Recovery cases

2

Blast-radius cases

Authority firewall

Every report is structurally synthetic. A successful scenario has exactly zero authority over live provider evidence, provider maturity, workspace readiness, recovery admission, Witness history, provider writes, or production mutation.

Live evidence: false
Maturity promotion: false
Recovery authority: false
Production writes: false
Synthetic #1Assurance Twincontradiction precedencecontinuity regressionMinimal Proof Plan

Stale success loses to newer failure

Show that an older successful destination observation cannot hide a newer contradiction or blocked runtime state.

Scenario root

bccae8879c62…de9ac041

1

Workflows

0

Exact edges

0

Runtime verified

0

Destinations confirmed

1

Contradictions

1

Blocked proofs

Minimal Proof Plan

1 step

Proof frontier

Resolve the current runtime blocker

make · runtime · blocked

Resolve the current runtime blocker

make · runtime · impact 1

Cross-feature result

This scenario exercises Twin/proof/continuity behavior without manufacturing a recovery receipt.

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • Newer contradictory evidence outranks historical success
  • • The proof frontier identifies the first unresolved exact layer

Still unknown

  • • Root cause
  • • Whether a repair is safe
  • • Business recovery

Allowed next actions

  • • Investigate the exact destination contradiction
  • • Re-establish attributable runtime evidence

Forbidden authority leaps

  • • Claim recovery from the older success
  • • Promote provider maturity
  • • Change production

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #2recovery historylive currentnessAssurance Twin recencyproduction-control boundary

Self-healed incident stops recovery

Show that a historically valid recovery receipt does not keep a repair path alive after current runtime evidence becomes healthy.

Scenario root

c36c536e8717…cd0f6936

1

Workflows

0

Exact edges

1

Runtime verified

0

Destinations confirmed

0

Contradictions

0

Blocked proofs

Minimal Proof Plan

1 step

Proof frontier

Bind and read back one exact destination object

n8n · outcome · missing

Bind and read back one exact destination object

n8n · outcome · impact 1

Cross-feature result

recovery-no-longer-admissiblenext: none

Stored provenance: assurance-definition-bound-v1 · live currentness: superseded

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • The lifecycle reports recovery-no-longer-admissible
  • • Historical recovery evidence stays truthful without staying authoritative

Still unknown

  • • Why the workflow recovered
  • • Future reliability

Allowed next actions

  • • Retain the historical receipt
  • • Continue observation

Forbidden authority leaps

  • • Run another repair solely because the historical receipt exists
  • • Fetch provider definition for an obsolete repair path
  • • Change production

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #3shadow provenanceprovider fingerprintlive currentnessreassessment gating

Definition changed after a green shadow receipt

Show that strong historical provenance is superseded when the exact saved provider definition changes while recovery is still needed.

Scenario root

f8b0fcf35923…3fbb575b

1

Workflows

0

Exact edges

0

Runtime verified

0

Destinations confirmed

0

Contradictions

1

Blocked proofs

Minimal Proof Plan

1 step

Proof frontier

Resolve the current runtime blocker

n8n · runtime · blocked

Resolve the current runtime blocker

n8n · runtime · impact 1

Cross-feature result

shadow-currentness-requirednext: assess-shadow

Stored provenance: assurance-definition-bound-v1 · live currentness: superseded

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • The lifecycle reports shadow-currentness-required
  • • Exact provider-definition identity participates in current truth

Still unknown

  • • Whether the changed definition is correct
  • • Whether downstream outputs recovered

Allowed next actions

  • • Run a fresh provenance-bound shadow assessment

Forbidden authority leaps

  • • Reuse the stale green shadow receipt
  • • Infer equivalence from workflow name
  • • Change production

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #4Continuity Contractsprovider-reported dependencyAssurance Twinblast radius

Exact continuity blast radius excludes lookalikes

Show that blast radius follows only explicit persisted dependency edges, not similar labels.

Scenario root

a26e8601ca28…b98b0d6f

3

Workflows

1

Exact edges

2

Runtime verified

0

Destinations confirmed

0

Contradictions

1

Blocked proofs

Minimal Proof Plan

3 steps

Proof frontier

Resolve the current runtime blocker

n8n · runtime · blocked

Resolve the current runtime blocker

n8n · runtime · impact 2

Bind and read back one exact destination object

make · outcome · impact 1

Bind and read back one exact destination object

zapier · outcome · impact 1

Cross-feature result

This scenario exercises Twin/proof/continuity behavior without manufacturing a recovery receipt.

Customer Master

Exact affected workflows: 1

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • Blast radius contains only explicitly reachable workflows
  • • Similar names do not create continuity truth

Still unknown

  • • Undocumented dependencies outside the explicit evidence graph

Allowed next actions

  • • Prioritize the exact dependent invoice workflow in impact review

Forbidden authority leaps

  • • Include Customer Master Copy because of its name
  • • Infer an undocumented Zapier dependency

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #5source availabilityAssurance TwinMinimal Proof Planfail-closed coverage

Unavailable continuity source is not a healthy empty estate

Show that missing binding/outcome sources become blocked proof rather than zero-risk evidence.

Scenario root

620a9187b92d…5b766238

1

Workflows

0

Exact edges

0

Runtime verified

0

Destinations confirmed

0

Contradictions

1

Blocked proofs

Minimal Proof Plan

1 step

Proof frontier

Collect attributable runtime evidence

power-automate · runtime · observed

Collect attributable runtime evidence

power-automate · runtime · impact 1

Cross-feature result

This scenario exercises Twin/proof/continuity behavior without manufacturing a recovery receipt.

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • Unavailable evidence becomes an explicit blocked proof boundary

Still unknown

  • • Destination correctness
  • • Continuity
  • • Current runtime health

Allowed next actions

  • • Restore the missing evidence sources

Forbidden authority leaps

  • • Report zero dependencies as independence
  • • Report missing destination evidence as healthy

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #6last-known-goodreplay bindingrecovery lifecyclehistorical evidence

Baseline rotation invalidates replay inheritance

Show that a new active last-known-good artifact cannot inherit a replay trace from the old baseline.

Scenario root

bdd330cfd769…a6ee29b6

1

Workflows

0

Exact edges

0

Runtime verified

0

Destinations confirmed

0

Contradictions

1

Blocked proofs

Minimal Proof Plan

1 step

Proof frontier

Resolve the current runtime blocker

n8n · runtime · blocked

Resolve the current runtime blocker

n8n · runtime · impact 1

Cross-feature result

replay-trace-requirednext: run-provider-verification

Stored provenance: assurance-definition-bound-v1 · live currentness: current

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • The lifecycle returns replay-trace-required for mismatched baseline evidence

Still unknown

  • • Whether the new baseline is recoverable

Allowed next actions

  • • Capture a replay trace for the exact new active baseline

Forbidden authority leaps

  • • Reuse the old replay receipt
  • • Inherit old shadow success across baseline rotation

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #7provider maturitysynthetic trust domainreadiness firewallproduction-control boundary

Synthetic success cannot promote provider maturity

Demonstrate that even arbitrarily successful synthetic observations have zero provider-wide authority.

Scenario root

aded955b34be…dd0d10c9

1

Workflows

0

Exact edges

1

Runtime verified

1

Destinations confirmed

0

Contradictions

0

Blocked proofs

Minimal Proof Plan

0 steps

No missing proof frontier in this synthetic derivation.

Cross-feature result

This scenario exercises Twin/proof/continuity behavior without manufacturing a recovery receipt.

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • Synthetic derivation can exercise a complete-looking chain
  • • Canonical provider maturity remains bit-for-bit unchanged

Still unknown

  • • Anything about a real Zapier workspace or provider account

Allowed next actions

  • • Use the result as a feature demonstration and regression fixture

Forbidden authority leaps

  • • Promote Zapier maturity
  • • Count this as workspace live readiness
  • • Append it to the production Witness ledger
  • • Authorize production change
The scenario is intentionally strong enough to expose any accidental synthetic-to-live authority leak.

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #8runtime recencyAssurance Twinrecovery admission boundaryfail closed

Untimestamped runtime ambiguity cannot authorize recovery

Show that unresolved runtime recency stays observed instead of becoming a current failure claim.

Scenario root

3e9527aed0f1…0dc6e127

1

Workflows

0

Exact edges

0

Runtime verified

0

Destinations confirmed

0

Contradictions

0

Blocked proofs

Minimal Proof Plan

1 step

Proof frontier

Collect attributable runtime evidence

make · runtime · observed

Collect attributable runtime evidence

make · runtime · impact 1

Cross-feature result

This scenario exercises Twin/proof/continuity behavior without manufacturing a recovery receipt.

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • Runtime ambiguity remains an explicit missing proof boundary

Still unknown

  • • Whether the workflow is currently healthy or failed

Allowed next actions

  • • Acquire a trustworthy attributable runtime timestamp

Forbidden authority leaps

  • • Treat the ambiguous status as current blocked runtime
  • • Authorize recovery

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #9cross-provider Assurance TwinContinuity Contractsblast radiusno-inference rule

Cross-provider incident propagation follows explicit edges only

Show exact cross-provider blast radius while excluding an unlinked workflow sharing the same business theme.

Scenario root

47ee8db0db42…ffff968a

4

Workflows

2

Exact edges

2

Runtime verified

0

Destinations confirmed

0

Contradictions

1

Blocked proofs

Minimal Proof Plan

4 steps

Proof frontier

Resolve the current runtime blocker

make · runtime · blocked

Resolve the current runtime blocker

make · runtime · impact 3

Bind and read back one exact destination object

n8n · outcome · impact 2

Bind and read back one exact destination object

zapier · outcome · impact 1

Collect attributable runtime evidence

power-automate · runtime · impact 1

Cross-feature result

This scenario exercises Twin/proof/continuity behavior without manufacturing a recovery receipt.

Orders Intake

Exact affected workflows: 2

Orders Enrichment

Exact affected workflows: 1

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • Blast radius traverses exact cross-provider edges transitively
  • • Unlinked same-theme workflows stay outside the claim

Still unknown

  • • Any undocumented dependency that lacks explicit evidence

Allowed next actions

  • • Review the exact n8n and Power Automate dependents

Forbidden authority leaps

  • • Include Orders Notify without an explicit edge
  • • Infer continuity from the shared Orders label

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.

Synthetic #10exact artifact identityComfyUI output assuranceclaim boundarymaturity firewall

ComfyUI byte change is evidence, not semantic judgment

Demonstrate the exact-output boundary: changed bytes can prove output change without claiming better, worse, or visually different semantics.

Scenario root

01da380b26dd…554f04ac

1

Workflows

0

Exact edges

1

Runtime verified

0

Destinations confirmed

0

Contradictions

0

Blocked proofs

Minimal Proof Plan

1 step

Proof frontier

Bind and read back one exact destination object

comfyui · outcome · missing

Bind and read back one exact destination object

comfyui · outcome · impact 1

Cross-feature result

This scenario exercises Twin/proof/continuity behavior without manufacturing a recovery receipt.

Maturity firewall

Canonical matrix unchanged: yes

Claim boundary

What this demonstrates

  • • Exact byte identity can distinguish stable versus changed output sets

Still unknown

  • • Visual quality
  • • Semantic correctness
  • • Business outcome
  • • Independent destination proof

Allowed next actions

  • • Record that the exact output artifact set changed
  • • Request independent semantic evaluation if needed

Forbidden authority leaps

  • • Claim the new image is better
  • • Claim semantic equivalence
  • • Promote L4 or L6 from byte change alone
Synthetic old artifact root aaaaaaaaaaaa… differs from new root bbbbbbbbbbbb…; this is deliberately not a semantic image comparison.

Synthetic Assurance Lab output is deterministic demonstration and regression evidence only. It is not provider-issued evidence, workspace readiness, provider-wide maturity proof, Assurance Witness production history, recovery admission authority, customer approval, or production mutation authority.