CAIN-42 CAIN Studio

CAIN-42 invariant · E25

I-TX-AUTH-engine-empty: AUTHORIZED only by engine+allow

Held · CAIN-42 Evolution 25 -- Universal Machine Agency Fabric

Last reviewed 2026-10-01

held   niche Identity, authority & delegation · family state_machine

What this rule means

CAIN-42 must always satisfy: AUTHORIZED only by engine+allow. It is one of 501 invariants checked for CAIN-42 Evolution 25 -- Universal Machine Agency Fabric. An invariant is a rule the system may never break, whatever an agent or attacker does; the test suite tries to break it across many scenarios and records the result.

Verify it in your browser

Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).

Check it yourself

Browse the raw bundle · How to reproduce it · SHA-256 manifest

Scope: {"limitation": "In-process governance library. Protocol adapters normalize REFERENCE messages; no third-party agent, MCP server or A2A peer has been governed.", "status": "SCOPE"}

Related rules

← I-TX-AUTH-agent-d · all 501 · I-TX-AUTH-engine-notallowed →

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem