Detect meaningful changes in agents, models, tools, policies, data, behavior, and compliance state before drift becomes an incident.
Architecture
📊
Data Drift
PSI, JS, KS, Chi-Square, Mean Shift, Variance Ratio
🤖
Model Drift
Provider, Version, Configuration Fingerprints
🔧
Tool Drift
Schema, Permissions, Capabilities Diff
📋
Policy Drift
Version, Rules, Risk Threshold Changes
👤
Behavior Drift
Action Frequency, Tool Selection, Trajectories
🔒
Security Drift
Threat Events, Injection, Blocked Actions
✓
Compliance Drift
Posture Score, Control Impact, Findings
⚙️
Config Drift
Agent, Runtime, Endpoint Configuration
Capabilities
📊
Statistical Methods
Population Stability Index (PSI), Jensen-Shannon Divergence, Kolmogorov-Smirnov Test, Chi-Square, Mean Shift, Variance Ratio, Quantile Shift, Cardinality Change, Missingness Shift. Every result includes baseline, comparison, metric, baseline_value, current_value, delta, threshold, confidence, sample_size, method, severity.
🔍
Structured Diff
Explain exactly WHAT changed, not just "something changed". Tool schema widening, permission scope expansion, input/output schema changes, version updates. Full before/after comparison.
⏱️
Deterministic Severity
CRITICAL, HIGH, MEDIUM, LOW severity with explainable reasoning. Severity is calculated from change type, affected systems, trust impact, compliance impact. Do not invent severity.
This demo shows a real drift detection workflow with actual API calls.
1
Create Baseline
2
Observe
3
Detect
4
Evidence
5
Display
Evidence Integration
Every drift detection produces:
drift_id - unique identifier
correlation_id - links to CAIN Observability events
evidence_id - links to CAIN Evidence Fabric
timestamp - when detected
actor - what detected (cain_drift)
Compliance Integration
✓
Compliance Impact Analysis
Drift can trigger compliance reassessment. Flow: DRIFT → CONTROL IMPACT → EVALUATION → FINDING → EVIDENCE. Drift means "reassessment may be required." Compliance determines the actual control result. Do not mark non-compliant merely because drift occurred.
Full state machine: detected→acknowledged→investigating→mitigated→resolved/accepted/false_positive
Observability Integration
OPERATIONAL
Events emit to CAIN Observability via record_event
Evidence Integration
OPERATIONAL
Evidence IDs wired to CAIN Evidence Fabric with full chain (baseline, observation, comparison, finding)
Compliance Integration
OPERATIONAL
Compliance findings created via CAIN Compliance; drift triggers reassessment NOT automatic failure
CLI
PARTIAL
Commands defined, may need implementation
MCP Tools
PARTIAL
Tools defined, may need implementation
SSE Stream
PARTIAL
Events emit via observability; real-time stream via Redis not yet implemented
Portal Panel
OPERATIONAL
Product registered in catalog at /service/caindrift
Quick Reference
Drift Classes
10
Severity Levels
4
Lifecycle States
7
Statistical Methods
9
CAIN Drift is part of CAIN Trust Fabric. It detects meaningful changes in autonomous AI systems using existing CAIN infrastructure (Observability, Evidence, Trace, Trajectory, Memory, Compliance, Governance, Security). Every drift event flows through CAIN Observability. Every consequential response goes through Governance. Every finding produces Evidence.