CAIN-42 CAIN Studio

CAIN-42 evidence library

166 invariants

From CAIN-42 Evolution 30 -- Governed Machine Autonomy Fabric.

Last reviewed 2026-10-01

IDRuleNicheResult
E30-L1no verified identity, no trustPolicy, law & governanceheld
E30-L2no authority, no authorizationPolicy, law & governanceheld
E30-L3no authorization, no executionPolicy, law & governanceheld
E30-L4no enforcement, no claim of controlPolicy, law & governanceheld
E30-L5no evidence, no trust upgradePolicy, law & governanceheld
E30-L6unknown never becomes verifiedPolicy, law & governanceheld
E30-L7perception is not reality; confidence is not truthPolicy, law & governanceheld
E30-L8memory never mints authorityPolicy, law & governanceheld
E30-L9reasoning is not authority; more compute is not more authorityPolicy, law & governanceheld
E30-L10consensus is not authorizationPolicy, law & governanceheld
E30-L11self-improvement never bypasses governancePolicy, law & governanceheld
E30-L12self-healing may propose a repair, never authorize its own deploymentPolicy, law & governanceheld
E30-L13model output is not world actionPolicy, law & governanceheld
E30-L14no agent promotes its own autonomy levelPolicy, law & governanceheld
E30-L15REVOKED never goes straight to AUTHORIZED; UNKNOWN never becomes TRUSTEDPolicy, law & governanceheld
E30-L16every consequential action consumes autonomy budget; replenishment is governedPolicy, law & governanceheld
E30-L17crossing a containment boundary needs a new authorizationPolicy, law & governanceheld
E30-L18monitored is not enforcedPolicy, law & governanceheld
E30-L19screenshots and visual observations are evidence, not authorityPolicy, law & governanceheld
E30-L20knowledge is superseded or revoked, never silently deletedPolicy, law & governanceheld
E30-H1self-healing deploys only with two registered humansPolicy, law & governanceheld
E30-LVL-1L1 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-LVL-2L2 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-LVL-3L3 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-LVL-4L4 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-LVL-5L5 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-LVL-6L6 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-LVL-7L7 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-LVL-8L8 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-LVL-9L9 is reached only with every evidence item it requiresAutonomy, control loops & recoveryheld
E30-STATE-REGISTEREDonly the listed states reach REGISTERED, by the listed actorCore guaranteesheld
E30-STATE-IDENTIFIEDonly the listed states reach IDENTIFIED, by the listed actorCore guaranteesheld
E30-STATE-ATTESTEDonly the listed states reach ATTESTED, by the listed actorCore guaranteesheld
E30-STATE-GOVERNEDonly the listed states reach GOVERNED, by the listed actorCore guaranteesheld
E30-STATE-AUTHORIZEDonly the listed states reach AUTHORIZED, by the listed actorIdentity, authority & delegationheld
E30-STATE-EXECUTINGonly the listed states reach EXECUTING, by the listed actorCore guaranteesheld
E30-STATE-DEGRADEDonly the listed states reach DEGRADED, by the listed actorAutonomy, control loops & recoveryheld
E30-STATE-QUARANTINEDonly the listed states reach QUARANTINED, by the listed actorAttacks, threats & containmentheld
E30-STATE-REVOKEDonly the listed states reach REVOKED, by the listed actorIdentity, authority & delegationheld
E30-STATE-RECOVERINGonly the listed states reach RECOVERING, by the listed actorAutonomy, control loops & recoveryheld
E30-STATE-RETIREDonly the listed states reach RETIRED, by the listed actorCore guaranteesheld
E30-UMA-principalthe UMA digest binds 'principal'Tools, MCP, protocols & adaptersheld
E30-UMA-identitythe UMA digest binds 'identity'Tools, MCP, protocols & adaptersheld
E30-UMA-intentthe UMA digest binds 'intent'Tools, MCP, protocols & adaptersheld
E30-UMA-contextthe UMA digest binds 'context'Tools, MCP, protocols & adaptersheld
E30-UMA-observationthe UMA digest binds 'observation'Tools, MCP, protocols & adaptersheld
E30-UMA-memorythe UMA digest binds 'memory'Tools, MCP, protocols & adaptersheld
E30-UMA-modelthe UMA digest binds 'model'Tools, MCP, protocols & adaptersheld
E30-UMA-runtimethe UMA digest binds 'runtime'Tools, MCP, protocols & adaptersheld
E30-UMA-capabilitythe UMA digest binds 'capability'Tools, MCP, protocols & adaptersheld
E30-UMA-delegationthe UMA digest binds 'delegation'Tools, MCP, protocols & adaptersheld
E30-UMA-policythe UMA digest binds 'policy'Tools, MCP, protocols & adaptersheld
E30-UMA-authoritythe UMA digest binds 'authority'Tools, MCP, protocols & adaptersheld
E30-UMA-riskthe UMA digest binds 'risk'Tools, MCP, protocols & adaptersheld
E30-UMA-consequencethe UMA digest binds 'consequence'Tools, MCP, protocols & adaptersheld
E30-UMA-transactionthe UMA digest binds 'transaction'Tools, MCP, protocols & adaptersheld
E30-UMA-environmentthe UMA digest binds 'environment'Tools, MCP, protocols & adaptersheld
E30-UMA-actionthe UMA digest binds 'action'Tools, MCP, protocols & adaptersheld
E30-UMA-executionthe UMA digest binds 'execution'Tools, MCP, protocols & adaptersheld
E30-UMA-outcomethe UMA digest binds 'outcome'Tools, MCP, protocols & adaptersheld
E30-UMA-evidencethe UMA digest binds 'evidence'Tools, MCP, protocols & adaptersheld
E30-BUDGET-time_ms'time_ms' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-compute'compute' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-money'money' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-tool_calls'tool_calls' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-delegation'delegation' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-memory_mutation'memory_mutation' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-network_access'network_access' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-data_access'data_access' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-physical_actions'physical_actions' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-code_modification'code_modification' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-self_improvement'self_improvement' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-BUDGET-transaction_value'transaction_value' is consumed, recorded and exhaustsTransactions, markets & economicsheld
E30-MEM-observationmemory class 'observation' follows its write rule and never carries authorityMemory, data & privacyheld
E30-MEM-evidencememory class 'evidence' follows its write rule and never carries authorityMemory, data & privacyheld
E30-MEM-hypothesismemory class 'hypothesis' follows its write rule and never carries authorityMemory, data & privacyheld
E30-MEM-instructionmemory class 'instruction' follows its write rule and never carries authorityMemory, data & privacyheld
E30-MEM-preferencememory class 'preference' follows its write rule and never carries authorityMemory, data & privacyheld
E30-MEM-policymemory class 'policy' follows its write rule and never carries authorityMemory, data & privacyheld
E30-MEM-authoritymemory class 'authority' follows its write rule and never carries authorityMemory, data & privacyheld
E30-MEM-historical_recordmemory class 'historical_record' follows its write rule and never carries authorityMemory, data & privacyheld
E30-MEM-unknownmemory class 'unknown' follows its write rule and never carries authorityMemory, data & privacyheld
E30-COV-ENFORCEDcoverage class 'ENFORCED' is a closed, reported categoryBenchmarks, coverage & performanceheld
E30-COV-MONITOREDcoverage class 'MONITORED' is a closed, reported categoryBenchmarks, coverage & performanceheld
E30-COV-OBSERVEDcoverage class 'OBSERVED' is a closed, reported categoryBenchmarks, coverage & performanceheld
E30-COV-PARTIALLY_ENFORCEDcoverage class 'PARTIALLY_ENFORCED' is a closed, reported categoryBenchmarks, coverage & performanceheld
E30-COV-BYPASSABLEcoverage class 'BYPASSABLE' is a closed, reported categoryBenchmarks, coverage & performanceheld
E30-COV-UNCONTROLLEDcoverage class 'UNCONTROLLED' is a closed, reported categoryBenchmarks, coverage & performanceheld
E30-COV-UNKNOWNcoverage class 'UNKNOWN' is a closed, reported categoryBenchmarks, coverage & performanceheld
E30-COV-MONITOREDmonitored paths are never counted as enforcedBenchmarks, coverage & performanceheld
E30-CAND-architecturea 'architecture' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-plannera 'planner' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-memorya 'memory' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-toola 'tool' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-capabilitya 'capability' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-modela 'model' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-codea 'code' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-agenta 'agent' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-organizationa 'organization' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-CAND-research_strategya 'research_strategy' candidate passes only the full firewall and a human reviewAutonomy, control loops & recoveryheld
E30-SCORE-capability_gainscorecard dimension 'capability_gain' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-reliabilityscorecard dimension 'reliability' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-securityscorecard dimension 'security' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-authority_preservationscorecard dimension 'authority_preservation' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-evidence_qualityscorecard dimension 'evidence_quality' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-regression_impactscorecard dimension 'regression_impact' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-resource_costscorecard dimension 'resource_cost' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-interpretabilityscorecard dimension 'interpretability' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-recoveryscorecard dimension 'recovery' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-rollbackscorecard dimension 'rollback' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-adversarial_resiliencescorecard dimension 'adversarial_resilience' is recorded separately (no single score)Trust & reputationheld
E30-SCORE-governance_coveragescorecard dimension 'governance_coverage' is recorded separately (no single score)Trust & reputationheld
E30-BOM-modela changed or known-malicious 'model' is detectedEvidence, receipts & proofsheld
E30-BOM-weightsa changed or known-malicious 'weights' is detectedEvidence, receipts & proofsheld
E30-BOM-runtimea changed or known-malicious 'runtime' is detectedEvidence, receipts & proofsheld
E30-BOM-packagea changed or known-malicious 'package' is detectedEvidence, receipts & proofsheld
E30-BOM-toola changed or known-malicious 'tool' is detectedEvidence, receipts & proofsheld
E30-BOM-mcp_servera changed or known-malicious 'mcp_server' is detectedEvidence, receipts & proofsheld
E30-BOM-skilla changed or known-malicious 'skill' is detectedEvidence, receipts & proofsheld
E30-BOM-plugina changed or known-malicious 'plugin' is detectedEvidence, receipts & proofsheld
E30-BOM-dataseta changed or known-malicious 'dataset' is detectedEvidence, receipts & proofsheld
E30-BOM-memorya changed or known-malicious 'memory' is detectedEvidence, receipts & proofsheld
E30-BOM-prompta changed or known-malicious 'prompt' is detectedEvidence, receipts & proofsheld
E30-BOM-codea changed or known-malicious 'code' is detectedEvidence, receipts & proofsheld
E30-BOM-containera changed or known-malicious 'container' is detectedEvidence, receipts & proofsheld
E30-BOM-dependencya changed or known-malicious 'dependency' is detectedEvidence, receipts & proofsheld
E30-MARKET-policy_packa 'policy_pack' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-MARKET-adaptera 'adapter' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-MARKET-conformance_testa 'conformance_test' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-MARKET-security_testa 'security_test' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-MARKET-agent_connectora 'agent_connector' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-MARKET-evidence_validatora 'evidence_validator' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-MARKET-capability_validatora 'capability_validator' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-MARKET-research_modulea 'research_module' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-MARKET-domain_governance_modulea 'domain_governance_module' component installs only when tested and unsubstitutedTransactions, markets & economicsheld
E30-ENV-browserenvironment 'browser' is ENFORCED and treated soPrediction, world models & simulationheld
E30-ENV-cloudenvironment 'cloud' is ENFORCED and treated soPrediction, world models & simulationheld
E30-ENV-databaseenvironment 'database' is ENFORCED and treated soPrediction, world models & simulationheld
E30-ENV-filesystemenvironment 'filesystem' is ENFORCED and treated soPrediction, world models & simulationheld
E30-ENV-laboratoryenvironment 'laboratory' is UNENFORCED and treated soPrediction, world models & simulationheld
E30-ENV-physical_actuatorenvironment 'physical_actuator' is UNENFORCED and treated soPrediction, world models & simulationheld
E30-ENV-robotenvironment 'robot' is UNENFORCED and treated soPrediction, world models & simulationheld
E30-ENV-simulated_worldenvironment 'simulated_world' is SIMULATED and treated soPrediction, world models & simulationheld
E30-ENV-softwareenvironment 'software' is ENFORCED and treated soPrediction, world models & simulationheld
E30-ENV-vehicleenvironment 'vehicle' is UNENFORCED and treated soPrediction, world models & simulationheld
E30-CU-navigatecomputer-use action 'navigate' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-CU-click_submitcomputer-use action 'click_submit' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-CU-screenshotcomputer-use action 'screenshot' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-CU-typecomputer-use action 'type' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-CU-downloadcomputer-use action 'download' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-CU-uploadcomputer-use action 'upload' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-CU-clipboard_readcomputer-use action 'clipboard_read' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-CU-credential_entrycomputer-use action 'credential_entry' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-CU-sessioncomputer-use action 'session' maps to a governed adapter or is refusedTransactions, markets & economicsheld
E30-E2E-ALLthe 30-step autonomy proof completesBenchmarks, coverage & performanceheld
E30-E2E-ORDERthe proof steps run in the specified orderBenchmarks, coverage & performanceheld
E30-REPLAY-ALLOWreplay explains why an action was allowedBenchmarks, coverage & performanceheld
E30-REPLAY-DENYreplay explains why an action was deniedBenchmarks, coverage & performanceheld
E30-TIME-MACHINEthe time machine answers from append-only recordsBenchmarks, coverage & performanceheld
E30-UAR-CHAINuniversal action receipts verify as a signed chain that binds each UMABenchmarks, coverage & performanceheld
E30-BUDGET-LEDGERthe autonomy budget ledger verifiesBenchmarks, coverage & performanceheld
E30-GRAPH-TRACEan executed action traces back to its sponsoring human in the governance graphBenchmarks, coverage & performanceheld
E30-DENY-RECEIPTEDa refused action also gets a universal receiptBenchmarks, coverage & performanceheld
E30-PROMOTION-NO-AUTHORITYpromotion leaves the promoted agent below execution levels until reauthorizedBenchmarks, coverage & performanceheld
E30-SDK-SEALEDan SDK-wrapped tool runs only inside the E8 boundary for an allowed callTools, MCP, protocols & adaptersheld
E30-LAB-ISOLATIONthe kernel imports no experimental (frontier lab / E22) moduleCore guaranteesheld

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem