Thanks Mateo, exactly the distinction I was aiming for. Treating authorization, execution, and outcome as separate guarantees is central to AgentGuard, especially at the MCP boundary. I really like your point about making the provenance chain a first-class invariant. That's a natural direction for future iterations.
