No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →Network Boundary
Constrain outbound destinations, protocols, resolution, redirects, and credential flow independently from whether a tool is semantically approved.
What feeds it, and what does it unlock?
Arrows show learning and design dependencies, not runtime data flow. Follow any node to continue through the Atlas.
Constrain outbound destinations, protocols, resolution, redirects, and credential flow independently from whether a tool is semantically approved.
The structured record is in the Atlas, but the L0–L4 article has not passed content review.
Snapshot implementations
An implementation enters the map only when both a snapshot and claims exist; unknowns remain visible.
No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.
Inspect coverage boundary →The teaching-harness reference does not automatically become an architectural claim about any vendor agent.
What has actually been tested?
Formal experiments are separate from course exercises. Exercises can validate the reference implementation but cannot replace Native evidence from a real agent.
sandbox.configure and an exact network decision still appear after approval allows the tool.
python3 -m curriculum.golden verify s11-sandbox-networkAn unlisted host is denied before the backend runs and the simulator call count does not increase.
python3 -m unittest curriculum.tests.test_vertical_slice.VerticalSliceTests.test_s11_denies_unlisted_network_before_backend_execution -vShould policy bind hostnames before or after DNS resolution and redirect handling?
How can a harness expose proxied, tunneled, and child-process traffic in one trace?
Which credential scopes remain safe when one destination is allowed?