What it evaluates
The first cross-action layer: within one declared window, EVE
groups actions by a declared key, sums a declared field, and compares the
aggregate to a declared collective limit. Each individual action may be
below its own limit — the breach is collective, not
per-action. Groups are evaluated independently. Missing window, group key,
or numeric value produces unknown for that group.
Output verdicts (per group)
breach
pass
unknown
breach when aggregate > limit. Equal to limit = pass.
Sealed proof on EVE Bridge
EVE-TPRM-00004227
breach / collective_limit_exceeded
→ aggregate 105 000 > limit 100 000 · Human decision: reject
Verify publicly →