{
  "id": "RUNTIME-AUTH-EMPTY",
  "title": "DENY list-shape differences",
  "status": "not-run",
  "required_authorization": "Separate explicit environment and experiment authorization; no automated provisioning is included",
  "preconditions": [
    "An isolated sidecar workload with complete applicable policy set"
  ],
  "procedure": [
    "Record baseline access",
    "Test missing rules, empty list, and one empty rule as three separately reviewed configurations",
    "Confirm acceptance, actual attachment, and allowed/denied requests for each"
  ],
  "acceptance": [
    "Missing/empty lists and single empty rule produce the documented distinct effects under identical scope"
  ],
  "capture": [
    "Pinned versions/digests",
    "Target identities and timestamps",
    "Sanitized before/after objects",
    "Positive and negative traffic results",
    "Path/enforcement correlation",
    "Residual risk and cleanup evidence"
  ],
  "stop_conditions": [
    "Unexpected external destination",
    "Unknown target identity",
    "Unapproved scope change",
    "Loss of observability",
    "Unresolved critical acceptance failure"
  ],
  "cleanup": "Use only separately approved ownership-aware cleanup. Verify teardown without deleting unrelated resources."
}
