This record uses fictional hosts and events. It represents neither a customer incident nor an inspection of your device.
DEMO-CONSOLE-02
Owned storage recovery, export boundary intact
A synthetic write probe is denied in the Axiom-owned data root. A bounded recovery succeeds there, while an arbitrary export destination remains denied.
Initial business impact
The fictional diagnostic console cannot save its own synthetic run record. The replay contains no customer or clinical data, and no system-wide permissions are changed.
Synthetic scenario diagram
Fictional request
Scope check
Axiom-owned storage Eligible scope
External destination denied POLICY_DENIED
The destinations are separate branches: owned storage can be eligible; the external destination remains denied.
Ivan Ferland · Synthetic record — no customer incident
Owned storage recovery, export boundary intact
DEMO-CONSOLE-02
Impact and final state
The fictional diagnostic console cannot save its own synthetic run record. The replay contains no customer or clinical data, and no system-wide permissions are changed.
A synthetic write probe is denied in the Axiom-owned data root. A bounded recovery succeeds there, while an arbitrary export destination remains denied.
Decision and permission boundary
In the synthetic record, the operator confirms the owned data root and selects the scoped storage-recovery operation. Only that owned root is eligible. The external destination is rejected again instead of expanding the allowlist.
The documented executable recovery allowlist is restricted to Axiom-owned storage and runtime. An arbitrary export path is outside that boundary and must stay denied. This public experience changes narrative state only; it does not read paths or modify permissions.
Validation and handover
A new fictional write probe succeeds within the owned data root and the synthetic run record is readable. The outside export destination still receives POLICY_DENIED. Both checks are required: recovery must not weaken the boundary.
The original write denial is observed; its historical cause is unknown. The record cannot distinguish inherited ACL drift, a prior setup mismatch or another local condition. The arbitrary export denial is expected policy behaviour, not evidence of a fault.
Stop conditions
Stop if ownership or the canonical data root cannot be confirmed, if the destination escapes the allowlist or if the bounded recovery fails. Preserve the denial; do not request broad permissions or retry arbitrary export paths.
In the synthetic record, the operator confirms the owned data root and selects the scoped storage-recovery operation. Only that owned root is eligible. The external destination is rejected again instead of expanding the allowlist.
Permission boundary
The documented executable recovery allowlist is restricted to Axiom-owned storage and runtime. An arbitrary export path is outside that boundary and must stay denied. This public experience changes narrative state only; it does not read paths or modify permissions.
Stop and escalation conditions
Stop if ownership or the canonical data root cannot be confirmed, if the destination escapes the allowlist or if the bounded recovery fails. Preserve the denial; do not request broad permissions or retry arbitrary export paths.
Validation and open questions
A new fictional write probe succeeds within the owned data root and the synthetic run record is readable. The outside export destination still receives POLICY_DENIED. Both checks are required: recovery must not weaken the boundary.
The original write denial is observed; its historical cause is unknown. The record cannot distinguish inherited ACL drift, a prior setup mismatch or another local condition. The arbitrary export denial is expected policy behaviour, not evidence of a fault.