When you evaluate Hood, proposal, review, authorization and evidence are kept distinct. Authentication is not authority, and an agent cannot enlarge its own permissions.
External assurance: independent security review is required before Hood treats internal test evidence as external assurance.