Framing the test around invariants rather than translation quality is the right move, since the agent can read fluent and still drop a precondition or flip the ownership check before the tool call. Your stage 3 point, that the Persian plan must not reverse the verify-ownership-then-retrieve order, is exactly where I see parity break. I wrote up a related failure on agent handoffs where the same silent constraint drop shows up: kartiknvjk.hashnode.dev/how-i-evaluate-agent-hand…