CAIN-42 evidence library
166 invariants
From CAIN-42 Evolution 30 -- Governed Machine Autonomy Fabric.
Last reviewed 2026-10-01
| ID | Rule | Niche | Result |
|---|---|---|---|
| E30-L1 | no verified identity, no trust | Policy, law & governance | held |
| E30-L2 | no authority, no authorization | Policy, law & governance | held |
| E30-L3 | no authorization, no execution | Policy, law & governance | held |
| E30-L4 | no enforcement, no claim of control | Policy, law & governance | held |
| E30-L5 | no evidence, no trust upgrade | Policy, law & governance | held |
| E30-L6 | unknown never becomes verified | Policy, law & governance | held |
| E30-L7 | perception is not reality; confidence is not truth | Policy, law & governance | held |
| E30-L8 | memory never mints authority | Policy, law & governance | held |
| E30-L9 | reasoning is not authority; more compute is not more authority | Policy, law & governance | held |
| E30-L10 | consensus is not authorization | Policy, law & governance | held |
| E30-L11 | self-improvement never bypasses governance | Policy, law & governance | held |
| E30-L12 | self-healing may propose a repair, never authorize its own deployment | Policy, law & governance | held |
| E30-L13 | model output is not world action | Policy, law & governance | held |
| E30-L14 | no agent promotes its own autonomy level | Policy, law & governance | held |
| E30-L15 | REVOKED never goes straight to AUTHORIZED; UNKNOWN never becomes TRUSTED | Policy, law & governance | held |
| E30-L16 | every consequential action consumes autonomy budget; replenishment is governed | Policy, law & governance | held |
| E30-L17 | crossing a containment boundary needs a new authorization | Policy, law & governance | held |
| E30-L18 | monitored is not enforced | Policy, law & governance | held |
| E30-L19 | screenshots and visual observations are evidence, not authority | Policy, law & governance | held |
| E30-L20 | knowledge is superseded or revoked, never silently deleted | Policy, law & governance | held |
| E30-H1 | self-healing deploys only with two registered humans | Policy, law & governance | held |
| E30-LVL-1 | L1 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-LVL-2 | L2 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-LVL-3 | L3 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-LVL-4 | L4 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-LVL-5 | L5 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-LVL-6 | L6 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-LVL-7 | L7 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-LVL-8 | L8 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-LVL-9 | L9 is reached only with every evidence item it requires | Autonomy, control loops & recovery | held |
| E30-STATE-REGISTERED | only the listed states reach REGISTERED, by the listed actor | Core guarantees | held |
| E30-STATE-IDENTIFIED | only the listed states reach IDENTIFIED, by the listed actor | Core guarantees | held |
| E30-STATE-ATTESTED | only the listed states reach ATTESTED, by the listed actor | Core guarantees | held |
| E30-STATE-GOVERNED | only the listed states reach GOVERNED, by the listed actor | Core guarantees | held |
| E30-STATE-AUTHORIZED | only the listed states reach AUTHORIZED, by the listed actor | Identity, authority & delegation | held |
| E30-STATE-EXECUTING | only the listed states reach EXECUTING, by the listed actor | Core guarantees | held |
| E30-STATE-DEGRADED | only the listed states reach DEGRADED, by the listed actor | Autonomy, control loops & recovery | held |
| E30-STATE-QUARANTINED | only the listed states reach QUARANTINED, by the listed actor | Attacks, threats & containment | held |
| E30-STATE-REVOKED | only the listed states reach REVOKED, by the listed actor | Identity, authority & delegation | held |
| E30-STATE-RECOVERING | only the listed states reach RECOVERING, by the listed actor | Autonomy, control loops & recovery | held |
| E30-STATE-RETIRED | only the listed states reach RETIRED, by the listed actor | Core guarantees | held |
| E30-UMA-principal | the UMA digest binds 'principal' | Tools, MCP, protocols & adapters | held |
| E30-UMA-identity | the UMA digest binds 'identity' | Tools, MCP, protocols & adapters | held |
| E30-UMA-intent | the UMA digest binds 'intent' | Tools, MCP, protocols & adapters | held |
| E30-UMA-context | the UMA digest binds 'context' | Tools, MCP, protocols & adapters | held |
| E30-UMA-observation | the UMA digest binds 'observation' | Tools, MCP, protocols & adapters | held |
| E30-UMA-memory | the UMA digest binds 'memory' | Tools, MCP, protocols & adapters | held |
| E30-UMA-model | the UMA digest binds 'model' | Tools, MCP, protocols & adapters | held |
| E30-UMA-runtime | the UMA digest binds 'runtime' | Tools, MCP, protocols & adapters | held |
| E30-UMA-capability | the UMA digest binds 'capability' | Tools, MCP, protocols & adapters | held |
| E30-UMA-delegation | the UMA digest binds 'delegation' | Tools, MCP, protocols & adapters | held |
| E30-UMA-policy | the UMA digest binds 'policy' | Tools, MCP, protocols & adapters | held |
| E30-UMA-authority | the UMA digest binds 'authority' | Tools, MCP, protocols & adapters | held |
| E30-UMA-risk | the UMA digest binds 'risk' | Tools, MCP, protocols & adapters | held |
| E30-UMA-consequence | the UMA digest binds 'consequence' | Tools, MCP, protocols & adapters | held |
| E30-UMA-transaction | the UMA digest binds 'transaction' | Tools, MCP, protocols & adapters | held |
| E30-UMA-environment | the UMA digest binds 'environment' | Tools, MCP, protocols & adapters | held |
| E30-UMA-action | the UMA digest binds 'action' | Tools, MCP, protocols & adapters | held |
| E30-UMA-execution | the UMA digest binds 'execution' | Tools, MCP, protocols & adapters | held |
| E30-UMA-outcome | the UMA digest binds 'outcome' | Tools, MCP, protocols & adapters | held |
| E30-UMA-evidence | the UMA digest binds 'evidence' | Tools, MCP, protocols & adapters | held |
| E30-BUDGET-time_ms | 'time_ms' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-compute | 'compute' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-money | 'money' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-tool_calls | 'tool_calls' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-delegation | 'delegation' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-memory_mutation | 'memory_mutation' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-network_access | 'network_access' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-data_access | 'data_access' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-physical_actions | 'physical_actions' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-code_modification | 'code_modification' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-self_improvement | 'self_improvement' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-BUDGET-transaction_value | 'transaction_value' is consumed, recorded and exhausts | Transactions, markets & economics | held |
| E30-MEM-observation | memory class 'observation' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-MEM-evidence | memory class 'evidence' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-MEM-hypothesis | memory class 'hypothesis' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-MEM-instruction | memory class 'instruction' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-MEM-preference | memory class 'preference' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-MEM-policy | memory class 'policy' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-MEM-authority | memory class 'authority' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-MEM-historical_record | memory class 'historical_record' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-MEM-unknown | memory class 'unknown' follows its write rule and never carries authority | Memory, data & privacy | held |
| E30-COV-ENFORCED | coverage class 'ENFORCED' is a closed, reported category | Benchmarks, coverage & performance | held |
| E30-COV-MONITORED | coverage class 'MONITORED' is a closed, reported category | Benchmarks, coverage & performance | held |
| E30-COV-OBSERVED | coverage class 'OBSERVED' is a closed, reported category | Benchmarks, coverage & performance | held |
| E30-COV-PARTIALLY_ENFORCED | coverage class 'PARTIALLY_ENFORCED' is a closed, reported category | Benchmarks, coverage & performance | held |
| E30-COV-BYPASSABLE | coverage class 'BYPASSABLE' is a closed, reported category | Benchmarks, coverage & performance | held |
| E30-COV-UNCONTROLLED | coverage class 'UNCONTROLLED' is a closed, reported category | Benchmarks, coverage & performance | held |
| E30-COV-UNKNOWN | coverage class 'UNKNOWN' is a closed, reported category | Benchmarks, coverage & performance | held |
| E30-COV-MONITORED | monitored paths are never counted as enforced | Benchmarks, coverage & performance | held |
| E30-CAND-architecture | a 'architecture' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-planner | a 'planner' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-memory | a 'memory' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-tool | a 'tool' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-capability | a 'capability' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-model | a 'model' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-code | a 'code' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-agent | a 'agent' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-organization | a 'organization' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-CAND-research_strategy | a 'research_strategy' candidate passes only the full firewall and a human review | Autonomy, control loops & recovery | held |
| E30-SCORE-capability_gain | scorecard dimension 'capability_gain' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-reliability | scorecard dimension 'reliability' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-security | scorecard dimension 'security' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-authority_preservation | scorecard dimension 'authority_preservation' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-evidence_quality | scorecard dimension 'evidence_quality' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-regression_impact | scorecard dimension 'regression_impact' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-resource_cost | scorecard dimension 'resource_cost' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-interpretability | scorecard dimension 'interpretability' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-recovery | scorecard dimension 'recovery' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-rollback | scorecard dimension 'rollback' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-adversarial_resilience | scorecard dimension 'adversarial_resilience' is recorded separately (no single score) | Trust & reputation | held |
| E30-SCORE-governance_coverage | scorecard dimension 'governance_coverage' is recorded separately (no single score) | Trust & reputation | held |
| E30-BOM-model | a changed or known-malicious 'model' is detected | Evidence, receipts & proofs | held |
| E30-BOM-weights | a changed or known-malicious 'weights' is detected | Evidence, receipts & proofs | held |
| E30-BOM-runtime | a changed or known-malicious 'runtime' is detected | Evidence, receipts & proofs | held |
| E30-BOM-package | a changed or known-malicious 'package' is detected | Evidence, receipts & proofs | held |
| E30-BOM-tool | a changed or known-malicious 'tool' is detected | Evidence, receipts & proofs | held |
| E30-BOM-mcp_server | a changed or known-malicious 'mcp_server' is detected | Evidence, receipts & proofs | held |
| E30-BOM-skill | a changed or known-malicious 'skill' is detected | Evidence, receipts & proofs | held |
| E30-BOM-plugin | a changed or known-malicious 'plugin' is detected | Evidence, receipts & proofs | held |
| E30-BOM-dataset | a changed or known-malicious 'dataset' is detected | Evidence, receipts & proofs | held |
| E30-BOM-memory | a changed or known-malicious 'memory' is detected | Evidence, receipts & proofs | held |
| E30-BOM-prompt | a changed or known-malicious 'prompt' is detected | Evidence, receipts & proofs | held |
| E30-BOM-code | a changed or known-malicious 'code' is detected | Evidence, receipts & proofs | held |
| E30-BOM-container | a changed or known-malicious 'container' is detected | Evidence, receipts & proofs | held |
| E30-BOM-dependency | a changed or known-malicious 'dependency' is detected | Evidence, receipts & proofs | held |
| E30-MARKET-policy_pack | a 'policy_pack' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-MARKET-adapter | a 'adapter' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-MARKET-conformance_test | a 'conformance_test' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-MARKET-security_test | a 'security_test' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-MARKET-agent_connector | a 'agent_connector' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-MARKET-evidence_validator | a 'evidence_validator' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-MARKET-capability_validator | a 'capability_validator' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-MARKET-research_module | a 'research_module' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-MARKET-domain_governance_module | a 'domain_governance_module' component installs only when tested and unsubstituted | Transactions, markets & economics | held |
| E30-ENV-browser | environment 'browser' is ENFORCED and treated so | Prediction, world models & simulation | held |
| E30-ENV-cloud | environment 'cloud' is ENFORCED and treated so | Prediction, world models & simulation | held |
| E30-ENV-database | environment 'database' is ENFORCED and treated so | Prediction, world models & simulation | held |
| E30-ENV-filesystem | environment 'filesystem' is ENFORCED and treated so | Prediction, world models & simulation | held |
| E30-ENV-laboratory | environment 'laboratory' is UNENFORCED and treated so | Prediction, world models & simulation | held |
| E30-ENV-physical_actuator | environment 'physical_actuator' is UNENFORCED and treated so | Prediction, world models & simulation | held |
| E30-ENV-robot | environment 'robot' is UNENFORCED and treated so | Prediction, world models & simulation | held |
| E30-ENV-simulated_world | environment 'simulated_world' is SIMULATED and treated so | Prediction, world models & simulation | held |
| E30-ENV-software | environment 'software' is ENFORCED and treated so | Prediction, world models & simulation | held |
| E30-ENV-vehicle | environment 'vehicle' is UNENFORCED and treated so | Prediction, world models & simulation | held |
| E30-CU-navigate | computer-use action 'navigate' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-CU-click_submit | computer-use action 'click_submit' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-CU-screenshot | computer-use action 'screenshot' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-CU-type | computer-use action 'type' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-CU-download | computer-use action 'download' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-CU-upload | computer-use action 'upload' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-CU-clipboard_read | computer-use action 'clipboard_read' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-CU-credential_entry | computer-use action 'credential_entry' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-CU-session | computer-use action 'session' maps to a governed adapter or is refused | Transactions, markets & economics | held |
| E30-E2E-ALL | the 30-step autonomy proof completes | Benchmarks, coverage & performance | held |
| E30-E2E-ORDER | the proof steps run in the specified order | Benchmarks, coverage & performance | held |
| E30-REPLAY-ALLOW | replay explains why an action was allowed | Benchmarks, coverage & performance | held |
| E30-REPLAY-DENY | replay explains why an action was denied | Benchmarks, coverage & performance | held |
| E30-TIME-MACHINE | the time machine answers from append-only records | Benchmarks, coverage & performance | held |
| E30-UAR-CHAIN | universal action receipts verify as a signed chain that binds each UMA | Benchmarks, coverage & performance | held |
| E30-BUDGET-LEDGER | the autonomy budget ledger verifies | Benchmarks, coverage & performance | held |
| E30-GRAPH-TRACE | an executed action traces back to its sponsoring human in the governance graph | Benchmarks, coverage & performance | held |
| E30-DENY-RECEIPTED | a refused action also gets a universal receipt | Benchmarks, coverage & performance | held |
| E30-PROMOTION-NO-AUTHORITY | promotion leaves the promoted agent below execution levels until reauthorized | Benchmarks, coverage & performance | held |
| E30-SDK-SEALED | an SDK-wrapped tool runs only inside the E8 boundary for an allowed call | Tools, MCP, protocols & adapters | held |
| E30-LAB-ISOLATION | the kernel imports no experimental (frontier lab / E22) module | Core guarantees | held |
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem