The capability lifecycle Four states define Tenure's enforcement boundary.
The wire format differs by provider protocol, but Tenure reduces the lifecycle to the same small set of states before policy is evaluated.
STAGE 1 Supplied Application includes it
→
STAGE 2 Exposed Tenure forwards it to the model
→
STAGE 3 Invoked Model emits a structured call
→
STAGE 4 Tenure decision Release or block
RELEASED Allowed back to your runtime
The invocation is returned to your application runtime. What happens after that point belongs to your infrastructure, not to Tenure.
BLOCKED Withheld before release
Policy says no. Tenure withholds the structured invocation and records the attempted call and enforcement decision.
REJECTED Explicit constraint cannot be satisfied
When the caller explicitly requires a disallowed capability, Tenure rejects the request rather than silently altering what the caller asked the model to do.
Tenure's authority ends at release. It does not claim to know whether a released action succeeded, failed, was ignored, or produced a side effect after it reached the application runtime.