SE2 ★ — the application ceiling caps the key. A key granting BOTH entity:read and agent:execute
is bound to a throwaway application whose ceiling admits ONLY entity:read. The agent:execute
request is denied at the APPLICATION level even though the key grants it; the entity:read request
passes both levels. Proves the ceiling is a hard cap, not merely advisory.
SE2 ★ — the application ceiling caps the key. A key granting BOTH
entity:readandagent:executeis bound to a throwaway application whose ceiling admits ONLYentity:read. Theagent:executerequest is denied at the APPLICATION level even though the key grants it; theentity:readrequest passes both levels. Proves the ceiling is a hard cap, not merely advisory.