=== 5A: Findings meta ===
total_count: 51
byClassification: {
  "observed_absence": 32,
  "correlated_pattern": 105,
  "structural_authority": 260
}

=== 5B: Individual finding fields ===
Finding: llm_egress
  type: llm_egress
  evidence_classification: structural_authority
  evidence_classification_label: Derived from graph structure
  path_id: MISSING

Finding: external_egress
  type: external_egress
  evidence_classification: structural_authority
  evidence_classification_label: Derived from graph structure
  path_id: MISSING

Finding: reachable_sensitive_domain
  type: reachable_sensitive_domain
  evidence_classification: structural_authority
  evidence_classification_label: Derived from graph structure
  path_id: MISSING

Finding: reachable_sensitive_domain
  type: reachable_sensitive_domain
  evidence_classification: structural_authority
  evidence_classification_label: Derived from graph structure
  path_id: MISSING

Finding: orphaned_ownership
  type: orphaned_ownership
  evidence_classification: structural_authority
  evidence_classification_label: Derived from graph structure
  path_id: MISSING

=== 5C: Single finding evidence_claim ===
FINDING_ID: eval:018e4c9cab75140a0a60ebf93550939c
=== EVIDENCE CLAIM ===
  claim_statement: Graph structure confirms workload "AI Classifier" has an authority path to LLM endpoint "a4e2874786825e022cd5bfe6" (egress_category: llm).
  classification: structural_authority
  effective_classification: structural_authority
  classification_label: Derived from graph structure
  business_impact: Workload can autonomously exfiltrate data or invoke LLM endpoints reaching "customer" — high data loss risk.
  recommended_action: Review LLM egress necessity; require formal approval and data handling controls.
  owner_role: Security Operations
  basis: [
    "Authority path egress_category field",
    "Destination endpoint classification"
]
path_id: fa7e05abcde65d6ee6ca018a

=== 5D: Filter by classification ===
Filter structural_authority: 51 results
  llm_egress: structural_authority
  external_egress: structural_authority
  reachable_sensitive_domain: structural_authority

=== 5E: Exposures with classification ===
Exposure: ?
  evidence_classifications: ['structural_authority', 'observed_absence']
  primary_classification: observed_absence
Exposure: ?
  evidence_classifications: ['structural_authority', 'correlated_pattern', 'observed_absence']
  primary_classification: observed_absence
Exposure: ?
  evidence_classifications: ['structural_authority', 'correlated_pattern']
  primary_classification: correlated_pattern

=== 5F: Classification correctness ===
orphaned_ownership -> structural_authority: PASS
scope_drift -> correlated_pattern: PASS
dormant_authority -> observed_absence: PASS
