Enterprise AI delivery — illustrative decision rules These new examples explain general engineering patterns. They are not copied client code and do not reproduce a client environment. They make no AWS calls. Run locally 1. Save controls.ts and controls.test.txt in an empty directory. 2. Rename controls.test.txt to controls.test.ts. 3. With a supported Node.js and npm installation, run: npm init -y npm install --save-dev vitest npx vitest run controls.test.ts (This installs Vitest locally. The website repository already includes it.) Boundaries - requirePermission assumes trusted middleware already verified identity and mapped permissions. A TypeScript type does not verify a token or header. - canPromote compares artifact identities and a test result. Trusted CI and approval systems must authenticate that evidence and enforce deployment. - acceptResearchResult checks a JSON result's shape, sizes and admitted URLs. It neither fetches sources nor verifies that they support the summary. Bound the raw response size before JSON parsing. - taskIngress creates one CloudFormation ingress resource for port 443 from a designated security group. It does not build a stack, configure TLS, constrain egress or prove that no other rule permits access. The tests demonstrate these narrow contracts. Production integration needs its own threat model, identity verification, deployment and behavioural checks.