ZUSE-ELIGIBILITY-ADD's own doc comment admitted "no authorization check here or anywhere else... applied later if and when actually needed -- not invented here." That's now: anyone reaching a Hera FORTH prompt could add their own pubkey to the eligibility list with zero legitimate identity material -- no minted drive, no WIREBIND, no cert-signature check involved at all. Once a future caller reaches ELEVATE-GRANT again, a self-added pubkey would pass zuse_eligibility_is_member() and grant ACL-ALLOW!/ACL-TTL! on any named word. Fixed the FORTH-only way, matching this project's own convention (ACL policy belongs in ACL.4th, never in C; never gate on zuse_session in C -- her power is the absence of ACLs, not a hardcoded session check): ZUSE-ELIGIBILITY-ADD is now denied by default (capsules/zuse.4th block 4016), granted and pinned only inside ACL-ZUSE-BOOT's already-existing authenticated branch (block 4017) -- the same gate her own god-mode already goes through, requiring a real cert-verified Zuse before it opens. Live-verified on all three architectures, not just boot-clean: after genesis authentication, ACL-ALLOW@ and ACL-PINNED? both read -1, and HERE ZUSE-ELIGIBILITY-ADD executes successfully past the ACL gate. Phase 8 v1 plan: /home/rajames/.claude/plans/jiggly-cuddling-stallman.md Part A (the ELEVATE-GRANT pointer-confusion fix, FABRIC-3.7.md) is separate, not yet built. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>