External communications
Governs the boundary where a message reaches a recipient and cannot be recalled. Recipient classification is asserted by the customer's directory, never inferred by Aarmos; paths that reach the transport without traversing the governed connector are named as bypasses rather than counted as covered.
Facts
A definition names the facts it relies on. It never asserts them and never infers them: each value comes from the participant that is entitled to assert it.
recipientClassrequiredsenderIdentityrequiredrecipientCountoptionalattachmentClassoptional
Enforcement paths
Every path on which the consequence can occur is either enforced or a named bypass. There is no third category, and coverage is reported as counts — never a percentage.
0/2 enforced paths observed · 2 named bypasses
Enforced
governed-mail-connector
Governed mail connector in the calling process: the decision is made before the message is submitted to the transport.
provider-api-adapter
Governed adapter in front of a hosted mail API (for example a workspace mail provider); the decision is made before the send request is issued.
Named bypasses
direct-smtp-credentials
A process holding its own SMTP credentials submits directly to the transport. Aarmos observes nothing on this path.
human-mail-client
A person sending from their own mail client. The consequence is real but the path never reaches a governed connector.
Evidence
Evidence for this action is projected under a 4096-byte budget. Attribution — who asserted a fact — is never truncated; only the listed payload facts can be shortened under budget pressure.
recipientClass · senderIdentity · recipientCount · attachmentClass
Taxonomy aarmos-actions@1.0 · sha256:2862b624a01a4a503c68fc2d3afa31fa2bf84c6024d5d639990d3a63f44b88a0