CAIN-42 evidence library
298 invariants
From CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric.
Last reviewed 2026-10-01
| ID | Rule | Niche | Result |
|---|---|---|---|
| NET-I001 | discovery cannot create authority | Identity, authority & delegation | held |
| NET-I002 | communication cannot create authority | Identity, authority & delegation | held |
| NET-I003 | negotiation cannot create authority | Identity, authority & delegation | held |
| NET-I004 | contract cannot create authority | Identity, authority & delegation | held |
| NET-I005 | reputation cannot create authority | Identity, authority & delegation | held |
| NET-I006 | payment cannot create authority | Identity, authority & delegation | held |
| NET-I007 | coalition cannot create authority | Identity, authority & delegation | held |
| NET-I008 | federation cannot create authority | Identity, authority & delegation | held |
| NET-I009 | trust cannot create unlimited authority | Identity, authority & delegation | held |
| NET-I010 | capability advertisement cannot create authority | Identity, authority & delegation | held |
| NET-I011 | child authority ⊆ delegated authority | Identity, authority & delegation | held |
| NET-I012 | cross-domain authority ⊆ local ∩ remote policy | Identity, authority & delegation | held |
| NET-I013 | trust translation cannot silently increase authority | Identity, authority & delegation | held |
| NET-I014 | protocol translation cannot silently increase authority | Identity, authority & delegation | held |
| NET-I015 | identity translation cannot silently increase authority | Identity, authority & delegation | held |
| NET-I016 | revoked identity cannot transact | Identity, authority & delegation | held |
| NET-I017 | revoked capability cannot execute | Identity, authority & delegation | held |
| NET-I018 | expired contract cannot authorize | Identity, authority & delegation | held |
| NET-I019 | expired evidence cannot authorize | Identity, authority & delegation | held |
| NET-I020 | quarantined agent cannot regain authority without reattestation | Attacks, threats & containment | held |
| NET-I021 | agent compromise cannot automatically compromise every peer | Attacks, threats & containment | held |
| NET-I022 | incident propagation must preserve unrelated trust domains | Attacks, threats & containment | held |
| NET-I023 | quarantine cannot erase evidence | Attacks, threats & containment | held |
| NET-I024 | recovery cannot erase incident history | Attacks, threats & containment | held |
| NET-I025 | rollback cannot resurrect revoked authority | Identity, authority & delegation | held |
| NET-I026 | economic resources cannot mint authority | Identity, authority & delegation | held |
| NET-I027 | reputation cannot mint authority | Identity, authority & delegation | held |
| NET-I028 | arbitration cannot mint unlimited authority | Identity, authority & delegation | held |
| NET-I029 | negotiation cannot bypass policy | Transactions, markets & economics | held |
| NET-I030 | contract fulfillment cannot bypass E8 | Transactions, markets & economics | held |
| NET-I031 | MCP execution reaches E8 | Tools, MCP, protocols & adapters | held |
| NET-I032 | A2A consequential delegation reaches E8 | Identity, authority & delegation | held |
| NET-I033 | computer-use actions reach E8 | Transactions, markets & economics | held |
| NET-I034 | API actions reach E8 | Tools, MCP, protocols & adapters | held |
| NET-I035 | physical consequential actions reach E8 | Tools, MCP, protocols & adapters | held |
| NET-I036 | network partition cannot expand authority | Consensus & distributed systems | held |
| NET-I037 | revocation outage cannot expand authority | Identity, authority & delegation | held |
| NET-I038 | identity outage cannot expand authority | Identity, authority & delegation | held |
| NET-I039 | evidence outage cannot expand authority | Identity, authority & delegation | held |
| NET-I040 | protocol downgrade cannot expand authority | Identity, authority & delegation | held |
| NET-I041 | unknown trust remains unknown | Trust & reputation | held |
| NET-I042 | unknown identity remains unknown | Identity, authority & delegation | held |
| NET-I043 | unknown capability remains unknown | Identity, authority & delegation | held |
| NET-I044 | unknown provenance remains unknown | Evidence, receipts & proofs | held |
| NET-I045 | unknown execution state remains unknown | Core guarantees | held |
| NET-I046 | the legitimate cross-domain chain commits through E19 and E8 | Evidence, receipts & proofs | held |
| NET-I047 | every discovery answers the eight questions | Tools, MCP, protocols & adapters | held |
| NET-I048 | a forged discovery advertisement is refused | Attacks, threats & containment | held |
| NET-I049 | trust is a 14-dimension vector, never one score | Trust & reputation | held |
| NET-I050 | mixed trust states coexist (high identity, low behaviour, unknown security) | Identity, authority & delegation | held |
| NET-I051 | hiring grants exactly the minimum authority | Identity, authority & delegation | held |
| NET-I052 | a legitimate escrow settles and is labelled SIMULATED | Prediction, world models & simulation | held |
| NET-I053 | escrow conserves abstract units | Transactions, markets & economics | held |
| NET-I054 | a legitimately re-attested agent is restored with its history intact | Core guarantees | held |
| NET-I055 | a legitimate two-hop delegation chain narrows | Identity, authority & delegation | held |
| NET-I056 | numeric trust translation is monotone and bounded | Trust & reputation | held |
| NET-I057 | VERIFIED is not translated as HIGH | Core guarantees | held |
| NET-I058 | the MachineSystemBOM has all sections and no authority | Identity, authority & delegation | held |
| NET-I059 | legitimate shared memory carries provenance and no authority | Identity, authority & delegation | held |
| NET-I060 | a legitimate signed artifact is admitted | Evidence, receipts & proofs | held |
| NET-I061 | the governance clock: authorized now, not authorized later | Consensus & distributed systems | held |
| NET-I062 | no non-authority input is read by the authority functions | Identity, authority & delegation | held |
| NET-I063 | the evidence log is hash-chained and tamper-evident | Attacks, threats & containment | held |
| NET-I064 | the network has 20 constitutional laws | Policy, law & governance | held |
| NET-I065 | a revoked or expired delegation is not live | Identity, authority & delegation | held |
| NET-P-http-GET | http GET: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-http-POST | http POST: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-http-PUT | http PUT: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-http-DELETE | http DELETE: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-rest-GET | rest GET: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-rest-POST | rest POST: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-grpc-Query | grpc Query: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-grpc-Mutate | grpc Mutate: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-websocket-subscribe | websocket subscribe: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-websocket-publish | websocket publish: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-event_bus-emit | event_bus emit: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-message_queue-enqueue | message_queue enqueue: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-cli-cat | cli cat: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-cli-run | cli run: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-browser-navigate | browser navigate: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-browser-click:submit_payment | browser click:submit_payment: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-browser-click:submit_order | browser click:submit_order: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-browser-type | browser type: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-computer_use-screenshot | computer_use screenshot: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-computer_use-click:submit_order | computer_use click:submit_order: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-computer_use-click:submit_payment | computer_use click:submit_payment: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-computer_use-terminal:run | computer_use terminal:run: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-computer_use-file:write | computer_use file:write: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-local_ipc-call:read | local_ipc call:read: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-local_ipc-call:write | local_ipc call:write: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-cloud_api-Describe | cloud_api Describe: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-cloud_api-Update | cloud_api Update: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-P-cloud_api-Terminate | cloud_api Terminate: an authorization always comes from an E8 commit | Identity, authority & delegation | held |
| NET-Q-active | quarantine state ACTIVE never raises authority | Attacks, threats & containment | held |
| NET-Q-restricted | quarantine state RESTRICTED never raises authority | Attacks, threats & containment | held |
| NET-Q-suspected | quarantine state SUSPECTED never raises authority | Attacks, threats & containment | held |
| NET-Q-quarantined | quarantine state QUARANTINED never raises authority | Attacks, threats & containment | held |
| NET-Q-isolated | quarantine state ISOLATED never raises authority | Attacks, threats & containment | held |
| NET-Q-revoked | quarantine state REVOKED never raises authority | Attacks, threats & containment | held |
| NET-Q-recovering | quarantine state RECOVERING never raises authority | Attacks, threats & containment | held |
| NET-Q-restored | quarantine state RESTORED never raises authority | Attacks, threats & containment | held |
| NET-Q-revoked-terminal | REVOKED has no outgoing transition | Identity, authority & delegation | held |
| NET-F-unknown-local | factor 'local' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-local | factor 'local' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-remote | factor 'remote' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-remote | factor 'remote' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-delegated | factor 'delegated' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-delegated | factor 'delegated' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-contract_scope | factor 'contract_scope' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-contract_scope | factor 'contract_scope' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-policy | factor 'policy' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-policy | factor 'policy' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-risk | factor 'risk' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-risk | factor 'risk' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-capability | factor 'capability' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-capability | factor 'capability' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-resource | factor 'resource' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-resource | factor 'resource' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-time | factor 'time' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-time | factor 'time' narrows authority | Identity, authority & delegation | held |
| NET-F-unknown-context | factor 'context' unknown makes authority empty | Identity, authority & delegation | held |
| NET-F-narrows-context | factor 'context' narrows authority | Identity, authority & delegation | held |
| NET-C-agent-a-delegate | agent-a/delegate is VERIFIED only while its evidence is fresh | Identity, authority & delegation | held |
| NET-C-agent-a-dispatch | agent-a/dispatch is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-a-notify | agent-a/notify is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-a-pay | agent-a/pay is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-a-read | agent-a/read is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-a-submit | agent-a/submit is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-a-write | agent-a/write is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-b-delegate | agent-b/delegate is VERIFIED only while its evidence is fresh | Identity, authority & delegation | held |
| NET-C-agent-b-dispatch | agent-b/dispatch is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-b-notify | agent-b/notify is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-b-pay | agent-b/pay is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-b-read | agent-b/read is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-b-write | agent-b/write is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-c-dispatch | agent-c/dispatch is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-c-notify | agent-c/notify is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-c-query | agent-c/query is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-c-read | agent-c/read is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-C-agent-c-write | agent-c/write is VERIFIED only while its evidence is fresh | Evidence, receipts & proofs | held |
| NET-T-low-identity_trust | identity_trust UNKNOWN fails a low-consequence action | Identity, authority & delegation | held |
| NET-T-medium-identity_trust | identity_trust UNKNOWN fails a medium-consequence action | Identity, authority & delegation | held |
| NET-T-medium-behavioral_trust | behavioral_trust UNKNOWN fails a medium-consequence action | Prediction, world models & simulation | held |
| NET-T-medium-security_trust | security_trust UNKNOWN fails a medium-consequence action | Prediction, world models & simulation | held |
| NET-T-high-identity_trust | identity_trust UNKNOWN fails a high-consequence action | Identity, authority & delegation | held |
| NET-T-high-behavioral_trust | behavioral_trust UNKNOWN fails a high-consequence action | Prediction, world models & simulation | held |
| NET-T-high-security_trust | security_trust UNKNOWN fails a high-consequence action | Prediction, world models & simulation | held |
| NET-T-high-provenance_trust | provenance_trust UNKNOWN fails a high-consequence action | Evidence, receipts & proofs | held |
| NET-T-high-execution_trust | execution_trust UNKNOWN fails a high-consequence action | Prediction, world models & simulation | held |
| NET-S-model-tamper | a tampered model is refused | Attacks, threats & containment | held |
| NET-S-model-rollback | a rolled-back model is refused | Prediction, world models & simulation | held |
| NET-S-plugin-tamper | a tampered plugin is refused | Attacks, threats & containment | held |
| NET-S-plugin-rollback | a rolled-back plugin is refused | Core guarantees | held |
| NET-S-skill-tamper | a tampered skill is refused | Attacks, threats & containment | held |
| NET-S-skill-rollback | a rolled-back skill is refused | Core guarantees | held |
| NET-S-tool-tamper | a tampered tool is refused | Attacks, threats & containment | held |
| NET-S-tool-rollback | a rolled-back tool is refused | Tools, MCP, protocols & adapters | held |
| NET-S-prompt-tamper | a tampered prompt is refused | Attacks, threats & containment | held |
| NET-S-prompt-rollback | a rolled-back prompt is refused | Core guarantees | held |
| NET-S-policy-tamper | a tampered policy is refused | Attacks, threats & containment | held |
| NET-S-policy-rollback | a rolled-back policy is refused | Policy, law & governance | held |
| NET-S-dataset-tamper | a tampered dataset is refused | Attacks, threats & containment | held |
| NET-S-dataset-rollback | a rolled-back dataset is refused | Memory, data & privacy | held |
| NET-S-memory_pack-tamper | a tampered memory_pack is refused | Attacks, threats & containment | held |
| NET-S-memory_pack-rollback | a rolled-back memory_pack is refused | Memory, data & privacy | held |
| NET-S-code-tamper | a tampered code is refused | Attacks, threats & containment | held |
| NET-S-code-rollback | a rolled-back code is refused | Core guarantees | held |
| NET-S-agent-tamper | a tampered agent is refused | Attacks, threats & containment | held |
| NET-S-agent-rollback | a rolled-back agent is refused | Core guarantees | held |
| NET-S-container-tamper | a tampered container is refused | Attacks, threats & containment | held |
| NET-S-container-rollback | a rolled-back container is refused | Attacks, threats & containment | held |
| NET-O-identity-provider | identity-provider outage denies instead of trusting | Identity, authority & delegation | held |
| NET-O-attestation-provider | attestation-provider outage denies instead of trusting | Evidence, receipts & proofs | held |
| NET-O-trust-provider | trust-provider outage denies instead of trusting | Trust & reputation | held |
| NET-O-revocation-provider | revocation-provider outage denies instead of trusting | Identity, authority & delegation | held |
| NET-O-evidence-provider | evidence-provider outage denies instead of trusting | Evidence, receipts & proofs | held |
| NET-E-communicated | incident exposure via 'communicated' follows the influence direction | Attacks, threats & containment | held |
| NET-E-delegated_to | incident exposure via 'delegated_to' follows the influence direction | Attacks, threats & containment | held |
| NET-E-trusted | incident exposure via 'trusted' follows the influence direction | Attacks, threats & containment | held |
| NET-E-received_artifact | incident exposure via 'received_artifact' follows the influence direction | Attacks, threats & containment | held |
| NET-E-imported_output | incident exposure via 'imported_output' follows the influence direction | Attacks, threats & containment | held |
| NET-E-executed_recommendation | incident exposure via 'executed_recommendation' follows the influence direction | Attacks, threats & containment | held |
| NET-E-exchanged_credentials | incident exposure via 'exchanged_credentials' follows the influence direction | Attacks, threats & containment | held |
| NET-E-contracted | incident exposure via 'contracted' follows the influence direction | Attacks, threats & containment | held |
| NET-L01 | NET-L01 DISCOVERY IS NOT TRUST | Tools, MCP, protocols & adapters | held |
| NET-L02 | NET-L02 TRUST IS NOT AUTHORITY | Identity, authority & delegation | held |
| NET-L03 | NET-L03 AUTHORITY IS NOT AUTHORIZATION | Identity, authority & delegation | held |
| NET-L04 | NET-L04 AUTHORIZATION IS NOT EXECUTION | Identity, authority & delegation | held |
| NET-L05 | NET-L05 EXECUTION IS NOT SUCCESS | Core guarantees | held |
| NET-L06 | NET-L06 SUCCESS IS NOT TRUST | Trust & reputation | held |
| NET-L07 | NET-L07 NEGOTIATION IS NOT AUTHORIZATION | Identity, authority & delegation | held |
| NET-L08 | NET-L08 CONTRACT IS NOT AUTHORITY | Identity, authority & delegation | held |
| NET-L09 | NET-L09 MONEY IS NOT AUTHORITY | Identity, authority & delegation | held |
| NET-L10 | NET-L10 REPUTATION IS NOT AUTHORITY | Identity, authority & delegation | held |
| NET-L11 | NET-L11 FEDERATION IS NOT UNLIMITED TRUST | Trust & reputation | held |
| NET-L12 | NET-L12 IDENTITY DOES NOT IMPLY AUTHORITY | Identity, authority & delegation | held |
| NET-L13 | NET-L13 A CAPABILITY ADVERTISEMENT IS A CLAIM | Identity, authority & delegation | held |
| NET-L14 | NET-L14 LOSS OF CONNECTIVITY NEVER CREATES AUTHORITY | Identity, authority & delegation | held |
| NET-L15 | NET-L15 UNKNOWN NEVER BECOMES TRUSTED | Trust & reputation | held |
| NET-L16 | NET-L16 QUARANTINE ONLY REDUCES AUTHORITY | Attacks, threats & containment | held |
| NET-L17 | NET-L17 RECOVERY IS NOT TRUST RESTORATION | Autonomy, control loops & recovery | held |
| NET-L18 | NET-L18 NO PROTOCOL BYPASSES E8 | Tools, MCP, protocols & adapters | held |
| NET-L19 | NET-L19 MEMORY IS NOT TRUST, AUTHORITY OR FACT | Identity, authority & delegation | held |
| NET-L20 | NET-L20 ROUTING NEVER CHANGES AUTHORITY | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-b-read | agent-a -> agent-b read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-b-notify | agent-a -> agent-b notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-b-dispatch | agent-a -> agent-b dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-b-write | agent-a -> agent-b write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-c-read | agent-a -> agent-c read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-c-notify | agent-a -> agent-c notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-c-dispatch | agent-a -> agent-c dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-c-write | agent-a -> agent-c write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-a2-read | agent-a -> agent-a2 read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-a2-notify | agent-a -> agent-a2 notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-a2-dispatch | agent-a -> agent-a2 dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-a2-write | agent-a -> agent-a2 write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-c2-read | agent-a -> agent-c2 read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-c2-notify | agent-a -> agent-c2 notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-c2-dispatch | agent-a -> agent-c2 dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a-agent-c2-write | agent-a -> agent-c2 write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-a-read | agent-b -> agent-a read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-a-notify | agent-b -> agent-a notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-a-dispatch | agent-b -> agent-a dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-a-write | agent-b -> agent-a write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-c-read | agent-b -> agent-c read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-c-notify | agent-b -> agent-c notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-c-dispatch | agent-b -> agent-c dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-c-write | agent-b -> agent-c write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-a2-read | agent-b -> agent-a2 read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-a2-notify | agent-b -> agent-a2 notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-a2-dispatch | agent-b -> agent-a2 dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-a2-write | agent-b -> agent-a2 write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-c2-read | agent-b -> agent-c2 read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-c2-notify | agent-b -> agent-c2 notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-c2-dispatch | agent-b -> agent-c2 dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-b-agent-c2-write | agent-b -> agent-c2 write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-a-read | agent-c -> agent-a read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-a-notify | agent-c -> agent-a notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-a-dispatch | agent-c -> agent-a dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-a-write | agent-c -> agent-a write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-b-read | agent-c -> agent-b read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-b-notify | agent-c -> agent-b notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-b-dispatch | agent-c -> agent-b dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-b-write | agent-c -> agent-b write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-a2-read | agent-c -> agent-a2 read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-a2-notify | agent-c -> agent-a2 notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-a2-dispatch | agent-c -> agent-a2 dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-a2-write | agent-c -> agent-a2 write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-c2-read | agent-c -> agent-c2 read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-c2-notify | agent-c -> agent-c2 notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-c2-dispatch | agent-c -> agent-c2 dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c-agent-c2-write | agent-c -> agent-c2 write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-a-read | agent-a2 -> agent-a read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-a-notify | agent-a2 -> agent-a notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-a-dispatch | agent-a2 -> agent-a dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-a-write | agent-a2 -> agent-a write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-b-read | agent-a2 -> agent-b read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-b-notify | agent-a2 -> agent-b notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-b-dispatch | agent-a2 -> agent-b dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-b-write | agent-a2 -> agent-b write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-c-read | agent-a2 -> agent-c read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-c-notify | agent-a2 -> agent-c notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-c-dispatch | agent-a2 -> agent-c dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-c-write | agent-a2 -> agent-c write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-c2-read | agent-a2 -> agent-c2 read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-c2-notify | agent-a2 -> agent-c2 notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-c2-dispatch | agent-a2 -> agent-c2 dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-a2-agent-c2-write | agent-a2 -> agent-c2 write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-a-read | agent-c2 -> agent-a read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-a-notify | agent-c2 -> agent-a notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-a-dispatch | agent-c2 -> agent-a dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-a-write | agent-c2 -> agent-a write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-b-read | agent-c2 -> agent-b read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-b-notify | agent-c2 -> agent-b notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-b-dispatch | agent-c2 -> agent-b dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-b-write | agent-c2 -> agent-b write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-c-read | agent-c2 -> agent-c read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-c-notify | agent-c2 -> agent-c notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-c-dispatch | agent-c2 -> agent-c dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-c-write | agent-c2 -> agent-c write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-a2-read | agent-c2 -> agent-a2 read: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-a2-notify | agent-c2 -> agent-a2 notify: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-a2-dispatch | agent-c2 -> agent-a2 dispatch: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-SOUND-agent-c2-agent-a2-write | agent-c2 -> agent-a2 write: authorized only if independently derivable, via E8 | Identity, authority & delegation | held |
| NET-U-a2a | a2a: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-mcp | mcp: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-http | http: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-rest | rest: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-grpc | grpc: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-websocket | websocket: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-event_bus | event_bus: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-message_queue | message_queue: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-cli | cli: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-browser | browser: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-computer_use | computer_use: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-local_ipc | local_ipc: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-U-cloud_api | cloud_api: an unmapped operation normalizes to UNKNOWN (never to a capability) | Identity, authority & delegation | held |
| NET-S-bench-targets | every adversarial scenario names an invariant that exists | Attacks, threats & containment | held |
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem