| E33-L1 | no identity, no trust | Policy, law & governance | held |
| E33-L2 | no provenance, no elevated trust | Policy, law & governance | held |
| E33-L3 | no capability, no capability use | Policy, law & governance | held |
| E33-L4 | no authority, no authorization | Policy, law & governance | held |
| E33-L5 | no authorization, no execution | Policy, law & governance | held |
| E33-L6 | no enforcement, no claim of control | Policy, law & governance | held |
| E33-L7 | no evidence, no verified outcome | Policy, law & governance | held |
| E33-L8 | no proof, no verified governance claim | Policy, law & governance | held |
| E33-L9 | communication is not authority | Policy, law & governance | held |
| E33-L10 | memory is not authority | Policy, law & governance | held |
| E33-L11 | knowledge is not authority | Policy, law & governance | held |
| E33-L12 | prediction is not authority | Policy, law & governance | held |
| E33-L13 | reputation is not authority | Policy, law & governance | held |
| E33-L14 | consensus is not authority | Policy, law & governance | held |
| E33-L15 | reward is not authority | Policy, law & governance | held |
| E33-L16 | economic value is not authority | Policy, law & governance | held |
| E33-L17 | learning is not authority | Policy, law & governance | held |
| E33-L18 | self-improvement is not authority | Policy, law & governance | held |
| E33-L19 | model quality is not authority | Policy, law & governance | held |
| E33-L20 | model confidence is not authority | Policy, law & governance | held |
| E33-L21 | tool availability is not authorization | Policy, law & governance | held |
| E33-L22 | capability discovery is not a capability grant | Policy, law & governance | held |
| E33-L23 | delegation is not unbounded authority | Policy, law & governance | held |
| E33-L24 | simulation is not reality | Policy, law & governance | held |
| E33-L25 | prediction is not fact | Policy, law & governance | held |
| E33-L26 | historical success is not future permission | Policy, law & governance | held |
| E33-L27 | proof of past authorization is not future authorization | Policy, law & governance | held |
| E33-L28 | child authority is a subset of parent authority | Policy, law & governance | held |
| E33-L29 | learning cannot remove governance | Policy, law & governance | held |
| E33-L30 | agents cannot govern their own authority expansion | Policy, law & governance | held |
| E33-L31 | governance cannot be self-deleted by the system it governs | Policy, law & governance | held |
| E33-L32 | failed controls become evidence | Policy, law & governance | held |
| E33-L33 | evidence retains provenance | Policy, law & governance | held |
| E33-L34 | unknown remains unknown | Policy, law & governance | held |
| E33-L35 | outside the enforcement boundary CAIN does not claim control | Policy, law & governance | held |
| E33-L36 | every consequential action reaches E8 | Policy, law & governance | held |
| E33-L37 | every governed action is traceable | Policy, law & governance | held |
| E33-L38 | every promoted governance change is reversible where practical | Policy, law & governance | held |
| E33-L39 | every critical governance change is proof-carrying | Policy, law & governance | held |
| E33-L40 | the governance fabric itself is governed | Policy, law & governance | held |
| E33-STATE-DISCOVER | no state can be skipped after DISCOVER | Core guarantees | held |
| E33-STATE-IDENTIFY | no state can be skipped after IDENTIFY | Core guarantees | held |
| E33-STATE-UNDERSTAND | no state can be skipped after UNDERSTAND | Core guarantees | held |
| E33-STATE-PROPOSE | no state can be skipped after PROPOSE | Core guarantees | held |
| E33-STATE-SIMULATE | no state can be skipped after SIMULATE | Prediction, world models & simulation | held |
| E33-STATE-ASSESS | no state can be skipped after ASSESS | Core guarantees | held |
| E33-STATE-AUTHORIZE | no state can be skipped after AUTHORIZE | Identity, authority & delegation | held |
| E33-STATE-COMMIT | no state can be skipped after COMMIT | Core guarantees | held |
| E33-STATE-ENFORCE | no state can be skipped after ENFORCE | Policy, law & governance | held |
| E33-STATE-EXECUTE | no state can be skipped after EXECUTE | Core guarantees | held |
| E33-STATE-OBSERVE | no state can be skipped after OBSERVE | Core guarantees | held |
| E33-STATE-VERIFY | no state can be skipped after VERIFY | Core guarantees | held |
| E33-STATE-PROVE | no state can be skipped after PROVE | Core guarantees | held |
| E33-STATE-LEARN | no state can be skipped after LEARN | Core guarantees | held |
| E33-STATE-RECOVER_ADAPT | no state can be skipped after RECOVER_ADAPT | Autonomy, control loops & recovery | held |
| E33-STATE-REASSESS | no state can be skipped after REASSESS | Core guarantees | held |
| E33-KIND-send_message | send_message is executed only through E8 | Tools, MCP, protocols & adapters | held |
| E33-KIND-invoke_tool | invoke_tool is executed only through E8 | Tools, MCP, protocols & adapters | held |
| E33-KIND-execute_code | execute_code is executed only through E8 | Core guarantees | held |
| E33-KIND-modify_file | modify_file is executed only through E8 | Core guarantees | held |
| E33-KIND-query_database | query_database is executed only through E8 | Memory, data & privacy | held |
| E33-KIND-access_credential | access_credential is executed only through E8 | Identity, authority & delegation | held |
| E33-KIND-call_api | call_api is executed only through E8 | Tools, MCP, protocols & adapters | held |
| E33-KIND-create_subagent | create_subagent is executed only through E8 | Core guarantees | held |
| E33-KIND-delegate_capability | delegate_capability is executed only through E8 | Identity, authority & delegation | held |
| E33-KIND-modify_memory | modify_memory is executed only through E8 | Memory, data & privacy | held |
| E33-KIND-modify_policy | modify_policy is routed to E32 CAINEvolutionPromotionGate | Tools, MCP, protocols & adapters | held |
| E33-KIND-change_model | change_model is routed to E32 CAINSwapGovernance | Prediction, world models & simulation | held |
| E33-KIND-change_runtime | change_runtime is routed to E32 CAINSwapGovernance | Tools, MCP, protocols & adapters | held |
| E33-KIND-deploy_software | deploy_software is executed only through E8 | Supply chain, registry & lifecycle | held |
| E33-KIND-move_money | move_money is executed only through E8 | Core guarantees | held |
| E33-KIND-enter_contract | enter_contract is routed to E29 contract + escrow lifecycle | Transactions, markets & economics | held |
| E33-KIND-control_physical_actuator | control_physical_actuator is executed only through E8 | Tools, MCP, protocols & adapters | held |
| E33-KIND-computer_use_action | computer_use_action is executed only through E8 | Transactions, markets & economics | held |
| E33-KIND-create_organization | create_organization is routed to E29 MachineOrganizationBudget (human) | Tools, MCP, protocols & adapters | held |
| E33-KIND-create_capability | create_capability is routed to E29 AgentCapabilityMarketplace conformance | Identity, authority & delegation | held |
| E33-KIND-modify_world_model | modify_world_model is routed to E32 world model (observations only) | Prediction, world models & simulation | held |
| E33-KIND-propose_governance_evolution | propose_governance_evolution is routed to E32 CAINEvolutionPromotionGate | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-low_risk | route low_risk keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-high_risk | route high_risk keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-physical | route physical keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-financial | route financial keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-privileged | route privileged keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-research | route research keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-code_execution | route code_execution keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-deployment | route deployment keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-memory_mutation | route memory_mutation keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-policy_mutation | route policy_mutation keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-governance_mutation | route governance_mutation keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-ROUTE-communication | route communication keeps its required controls | Tools, MCP, protocols & adapters | held |
| E33-DEGRADED-verifier_unavailable | verifier_unavailable only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-evidence_unavailable | evidence_unavailable only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-trust_domain_unreachable | trust_domain_unreachable only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-policy_service_unavailable | policy_service_unavailable only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-world_state_stale | world_state_stale only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-revocation_service_unavailable | revocation_service_unavailable only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-cluster_partition | cluster_partition only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-model_unavailable | model_unavailable only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-runtime_failure | runtime_failure only removes routes | Autonomy, control loops & recovery | held |
| E33-DEGRADED-enforcement_boundary_unavailable | enforcement_boundary_unavailable only removes routes | Autonomy, control loops & recovery | held |
| E33-EVENT-request_metadata | request_metadata events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-intent | intent events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-message | message events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-tool_request | tool_request events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-tool_response | tool_response events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-capability_request | capability_request events chain and verify | Identity, authority & delegation | held |
| E33-EVENT-authorization_request | authorization_request events chain and verify | Identity, authority & delegation | held |
| E33-EVENT-delegation | delegation events chain and verify | Identity, authority & delegation | held |
| E33-EVENT-memory_mutation | memory_mutation events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-policy_mutation | policy_mutation events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-model_change | model_change events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-runtime_change | runtime_change events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-execution | execution events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-outcome | outcome events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-error | error events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-recovery | recovery events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-transaction | transaction events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-physical_action | physical_action events chain and verify | Evidence, receipts & proofs | held |
| E33-EVENT-governance_change | governance_change events chain and verify | Evidence, receipts & proofs | held |
| E33-CHANNEL-a2a | channel a2a is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-mcp | channel mcp is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-http | channel http is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-rest | channel rest is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-websocket | channel websocket is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-event_bus | channel event_bus is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-message_queue | channel message_queue is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-local_ipc | channel local_ipc is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-file | channel file is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-database | channel database is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-shared_memory | channel shared_memory is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-browser | channel browser is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-collaboration | channel collaboration is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-CHANNEL-cloud_api | channel cloud_api is classified, consequential use only if governed | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-informational | a informational message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-evidentiary | a evidentiary message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-instructional | a instructional message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-delegated | a delegated message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-negotiated | a negotiated message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-contractual | a contractual message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-authorization_related | a authorization_related message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-security_sensitive | a security_sensitive message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-MSGCLASS-policy_sensitive | a policy_sensitive message grants no authority | Tools, MCP, protocols & adapters | held |
| E33-BUDGET-action | action exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-time_ms | time_ms exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-compute | compute exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-financial | financial exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-capability | capability exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-delegation | delegation exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-risk | risk exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-uncertainty | uncertainty exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-communication | communication exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-physical_action | physical_action exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-BUDGET-organizational | organizational exhaustion stops and never self-replenishes | Transactions, markets & economics | held |
| E33-EXHAUST-STOP | exhaustion mode STOP never increases authority | Identity, authority & delegation | held |
| E33-EXHAUST-REAUTHORIZE | exhaustion mode REAUTHORIZE never increases authority | Identity, authority & delegation | held |
| E33-EXHAUST-DEGRADED_MODE | exhaustion mode DEGRADED_MODE never increases authority | Identity, authority & delegation | held |
| E33-CLOCK-state | a stale state invalidates authorization | Consensus & distributed systems | held |
| E33-CLOCK-evidence | a stale evidence invalidates authorization | Consensus & distributed systems | held |
| E33-CLOCK-policy | a stale policy invalidates authorization | Consensus & distributed systems | held |
| E33-CLOCK-authorization | a stale authorization invalidates authorization | Consensus & distributed systems | held |
| E33-CLOCK-world_model | a stale world_model invalidates authorization | Consensus & distributed systems | held |
| E33-CLOCK-identity | a stale identity invalidates authorization | Consensus & distributed systems | held |
| E33-CLOCK-capability | a stale capability invalidates authorization | Consensus & distributed systems | held |
| E33-CLOCK-revocation | a stale revocation invalidates authorization | Consensus & distributed systems | held |
| E33-LEASE-identity | a lease without identity is refused | Identity, authority & delegation | held |
| E33-LEASE-scope | a lease without scope is refused | Identity, authority & delegation | held |
| E33-LEASE-capabilities | a lease without capabilities is refused | Identity, authority & delegation | held |
| E33-LEASE-authority | a lease without authority is refused | Identity, authority & delegation | held |
| E33-LEASE-budget | a lease without budget is refused | Identity, authority & delegation | held |
| E33-LEASE-not_after | a lease without not_after is refused | Identity, authority & delegation | held |
| E33-LEASE-max_actions | a lease without max_actions is refused | Identity, authority & delegation | held |
| E33-LEASE-risk_threshold | a lease without risk_threshold is refused | Identity, authority & delegation | held |
| E33-LEASE-trajectory | a lease without trajectory is refused | Identity, authority & delegation | held |
| E33-LEASE-economic | a lease without economic is refused | Identity, authority & delegation | held |
| E33-LEASE-physical | a lease without physical is refused | Identity, authority & delegation | held |
| E33-LEASE-geographic | a lease without geographic is refused | Identity, authority & delegation | held |
| E33-LEASE-delegation | a lease without delegation is refused | Identity, authority & delegation | held |
| E33-LEASE-model_runtime | a lease without model_runtime is refused | Identity, authority & delegation | held |
| E33-LEASE-evidence_requirements | a lease without evidence_requirements is refused | Identity, authority & delegation | held |
| E33-KERNEL-identity | identity kernel names its backing implementation (E28) | Policy, law & governance | held |
| E33-KERNEL-authority | authority kernel names its backing implementation (E28/E30) | Policy, law & governance | held |
| E33-KERNEL-policy | policy kernel names its backing implementation (E25/E32) | Policy, law & governance | held |
| E33-KERNEL-capability | capability kernel names its backing implementation (E29) | Policy, law & governance | held |
| E33-KERNEL-memory | memory kernel names its backing implementation (E30/E32) | Policy, law & governance | held |
| E33-KERNEL-evidence | evidence kernel names its backing implementation (E8/E30) | Policy, law & governance | held |
| E33-KERNEL-reasoning_governance | reasoning_governance kernel names its backing implementation (E13) | Policy, law & governance | held |
| E33-KERNEL-world_state | world_state kernel names its backing implementation (E30) | Policy, law & governance | held |
| E33-KERNEL-risk | risk kernel names its backing implementation (E29/E30) | Policy, law & governance | held |
| E33-KERNEL-execution | execution kernel names its backing implementation (E25/E8) | Policy, law & governance | held |
| E33-KERNEL-transaction | transaction kernel names its backing implementation (E29) | Policy, law & governance | held |
| E33-KERNEL-communication | communication kernel names its backing implementation (E33) | Policy, law & governance | held |
| E33-KERNEL-learning | learning kernel names its backing implementation (E32) | Policy, law & governance | held |
| E33-KERNEL-evolution | evolution kernel names its backing implementation (E32) | Policy, law & governance | held |
| E33-KERNEL-proof | proof kernel names its backing implementation (E31) | Policy, law & governance | held |
| E33-KERNEL-recovery | recovery kernel names its backing implementation (E29/E32) | Policy, law & governance | held |
| E33-KERNEL-telemetry | telemetry kernel names its backing implementation (E33) | Policy, law & governance | held |
| E33-KERNEL-conformance | conformance kernel names its backing implementation (E31) | Policy, law & governance | held |
| E33-ABI-identify | ABI identify fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-authorize | ABI authorize fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-check_capability | ABI check_capability fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-evaluate_risk | ABI evaluate_risk fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-request_execution | ABI request_execution fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-produce_proof | ABI produce_proof fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-verify_proof | ABI verify_proof fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-record_evidence | ABI record_evidence fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-revoke | ABI revoke fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-replay | ABI replay fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-conform | ABI conform fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-recover | ABI recover fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-delegate | ABI delegate fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABI-commit | ABI commit fails closed on malformed/forged/unknown input | Tools, MCP, protocols & adapters | held |
| E33-ABIERR-ABI_VERSION_UNSUPPORTED | ABI_VERSION_UNSUPPORTED is returned, never an allow | Tools, MCP, protocols & adapters | held |
| E33-ABIERR-ABI_OP_UNKNOWN | ABI_OP_UNKNOWN is returned, never an allow | Tools, MCP, protocols & adapters | held |
| E33-ABIERR-ABI_ARGUMENT_MISSING | ABI_ARGUMENT_MISSING is returned, never an allow | Tools, MCP, protocols & adapters | held |
| E33-ABIERR-ABI_MALFORMED | ABI_MALFORMED is returned, never an allow | Tools, MCP, protocols & adapters | held |
| E33-ABIERR-ABI_UNAUTHENTICATED | ABI_UNAUTHENTICATED is returned, never an allow | Tools, MCP, protocols & adapters | held |
| E33-CONTRACT-governs | a contract without governs is refused | Transactions, markets & economics | held |
| E33-CONTRACT-observes | a contract without observes is refused | Transactions, markets & economics | held |
| E33-CONTRACT-enforces | a contract without enforces is refused | Transactions, markets & economics | held |
| E33-CONTRACT-verifies | a contract without verifies is refused | Transactions, markets & economics | held |
| E33-CONTRACT-does_not_control | a contract without does_not_control is refused | Transactions, markets & economics | held |
| E33-CONTRACT-on_failure | a contract without on_failure is refused | Transactions, markets & economics | held |
| E33-CONTRACT-on_partition | a contract without on_partition is refused | Transactions, markets & economics | held |
| E33-CONTRACT-on_degraded | a contract without on_degraded is refused | Transactions, markets & economics | held |
| E33-CONTRACT-revocation | a contract without revocation is refused | Transactions, markets & economics | held |
| E33-CONTRACT-evidence | a contract without evidence is refused | Transactions, markets & economics | held |
| E33-CONTRACT-proofs | a contract without proofs is refused | Transactions, markets & economics | held |
| E33-RUNTIME-generic_llm_agent | generic_llm_agent is classified ENFORCED with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-mcp_agent | mcp_agent is classified ENFORCED with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-a2a_agent | a2a_agent is classified ENFORCED with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-coding_agent | coding_agent is classified PARTIAL with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-browser_agent | browser_agent is classified PARTIAL with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-computer_use_agent | computer_use_agent is classified PARTIAL with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-workflow_agent | workflow_agent is classified UNKNOWN with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-multi_agent_system | multi_agent_system is classified PARTIAL with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-research_agent | research_agent is classified SIMULATED with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-physical_robotic_system | physical_robotic_system is classified UNKNOWN with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-enterprise_automation | enterprise_automation is classified UNKNOWN with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-RUNTIME-cloud_agent | cloud_agent is classified PARTIAL with a stated basis | Tools, MCP, protocols & adapters | held |
| E33-IMMUNE-coordinated_attack | the immune system responds fully to coordinated_attack | Attacks, threats & containment | held |
| E33-IMMUNE-authority_laundering | the immune system responds fully to authority_laundering | Attacks, threats & containment | held |
| E33-IMMUNE-capability_laundering | the immune system responds fully to capability_laundering | Attacks, threats & containment | held |
| E33-IMMUNE-identity_cloning | the immune system responds fully to identity_cloning | Attacks, threats & containment | held |
| E33-IMMUNE-policy_poisoning | the immune system responds fully to policy_poisoning | Attacks, threats & containment | held |
| E33-IMMUNE-memory_poisoning | the immune system responds fully to memory_poisoning | Attacks, threats & containment | held |
| E33-IMMUNE-world_model_poisoning | the immune system responds fully to world_model_poisoning | Attacks, threats & containment | held |
| E33-IMMUNE-verifier_attack | the immune system responds fully to verifier_attack | Attacks, threats & containment | held |
| E33-IMMUNE-supply_chain_attack | the immune system responds fully to supply_chain_attack | Attacks, threats & containment | held |
| E33-IMMUNE-channel_attack | the immune system responds fully to channel_attack | Attacks, threats & containment | held |
| E33-IMMUNE-economic_attack | the immune system responds fully to economic_attack | Attacks, threats & containment | held |
| E33-IMMUNE-organizational_attack | the immune system responds fully to organizational_attack | Attacks, threats & containment | held |
| E33-IMMUNE-recursive_self_improvement_attack | the immune system responds fully to recursive_self_improvement_attack | Attacks, threats & containment | held |
| E33-IMMUNESTEP-DETECT | immune response step DETECT runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-CLASSIFY | immune response step CLASSIFY runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-CONTAIN | immune response step CONTAIN runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-REVOKE | immune response step REVOKE runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-QUARANTINE | immune response step QUARANTINE runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-PRESERVE_EVIDENCE | immune response step PRESERVE_EVIDENCE runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-RECOVER | immune response step RECOVER runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-LEARN | immune response step LEARN runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-GENERATE_TEST | immune response step GENERATE_TEST runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-HARDEN | immune response step HARDEN runs in order | Attacks, threats & containment | held |
| E33-IMMUNESTEP-VERIFY | immune response step VERIFY runs in order | Attacks, threats & containment | held |
| E33-INCIDENT-FREEZE_AUTHORITY | incident command performs FREEZE_AUTHORITY | Attacks, threats & containment | held |
| E33-INCIDENT-PRESERVE_EVIDENCE | incident command performs PRESERVE_EVIDENCE | Attacks, threats & containment | held |
| E33-INCIDENT-ISOLATE_AGENTS | incident command performs ISOLATE_AGENTS | Attacks, threats & containment | held |
| E33-INCIDENT-REVOKE_CREDENTIALS | incident command performs REVOKE_CREDENTIALS | Attacks, threats & containment | held |
| E33-INCIDENT-BLOCK_CHANNELS | incident command performs BLOCK_CHANNELS | Attacks, threats & containment | held |
| E33-INCIDENT-FREEZE_TRANSACTIONS | incident command performs FREEZE_TRANSACTIONS | Attacks, threats & containment | held |
| E33-INCIDENT-SNAPSHOT_STATE | incident command performs SNAPSHOT_STATE | Attacks, threats & containment | held |
| E33-INCIDENT-BLAST_RADIUS | incident command performs BLAST_RADIUS | Attacks, threats & containment | held |
| E33-INCIDENT-DEPENDENCIES | incident command performs DEPENDENCIES | Attacks, threats & containment | held |
| E33-INCIDENT-RECOVER | incident command performs RECOVER | Attacks, threats & containment | held |
| E33-INCIDENT-REPLAY | incident command performs REPLAY | Attacks, threats & containment | held |
| E33-INCIDENT-GENERATE_TESTS | incident command performs GENERATE_TESTS | Attacks, threats & containment | held |
| E33-BLAST-agents | blast radius reports agents separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-identities | blast radius reports identities separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-organizations | blast radius reports organizations separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-capabilities | blast radius reports capabilities separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-tools | blast radius reports tools separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-credentials | blast radius reports credentials separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-networks | blast radius reports networks separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-data | blast radius reports data separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-finances | blast radius reports finances separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-physical_systems | blast radius reports physical_systems separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-contracts | blast radius reports contracts separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-downstream_agents | blast radius reports downstream_agents separately (no aggregate) | Prediction, world models & simulation | held |
| E33-BLAST-trust_domains | blast radius reports trust_domains separately (no aggregate) | Prediction, world models & simulation | held |
| E33-CAUSAL-ROOT_CAUSE | a missing causal link is visible | Attacks, threats & containment | held |
| E33-CAUSAL-EXPLOIT | a missing causal link is visible | Attacks, threats & containment | held |
| E33-CAUSAL-AGENT_BEHAVIOR | a missing causal link is visible | Attacks, threats & containment | held |
| E33-CAUSAL-AUTHORIZATION | a missing causal link is visible | Attacks, threats & containment | held |
| E33-CAUSAL-EXECUTION | a missing causal link is visible | Attacks, threats & containment | held |
| E33-CAUSAL-EFFECT | a missing causal link is visible | Attacks, threats & containment | held |
| E33-CAUSAL-DOWNSTREAM_EFFECT | a missing causal link is visible | Attacks, threats & containment | held |
| E33-CHAOS-node_failure | chaos node_failure never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-network_partition | chaos network_partition never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-clock_skew | chaos clock_skew never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-stale_state | chaos stale_state never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-corrupted_evidence | chaos corrupted_evidence never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-malicious_agent | chaos malicious_agent never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-revoked_credentials | chaos revoked_credentials never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-model_swap | chaos model_swap never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-runtime_swap | chaos runtime_swap never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-policy_conflict | chaos policy_conflict never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-compromised_tool | chaos compromised_tool never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-unavailable_verifier | chaos unavailable_verifier never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-economic_shock | chaos economic_shock never expands authority | Attacks, threats & containment | held |
| E33-CHAOS-communication_failure | chaos communication_failure never expands authority | Attacks, threats & containment | held |
| E33-REP-reliability | reputation reliability needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-provenance | reputation provenance needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-policy_compliance | reputation policy_compliance needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-execution_quality | reputation execution_quality needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-evidence_quality | reputation evidence_quality needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-security_history | reputation security_history needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-recovery_history | reputation recovery_history needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-delegation_behavior | reputation delegation_behavior needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-contract_behavior | reputation contract_behavior needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-communication_integrity | reputation communication_integrity needs evidence and mints no authority | Trust & reputation | held |
| E33-REP-governance_conformance | reputation governance_conformance needs evidence and mints no authority | Trust & reputation | held |
| E33-MODULE-policy | policy modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-verifier | verifier modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-detector | detector modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-protocol_adapter | protocol_adapter modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-risk_model | risk_model modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-recovery_strategy | recovery_strategy modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-evidence_validator | evidence_validator modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-world_model_adapter | world_model_adapter modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-capability_control | capability_control modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODULE-incident_detector | incident_detector modules need every field and may only propose | Transactions, markets & economics | held |
| E33-MODFIELD-provenance | modules need provenance | Transactions, markets & economics | held |
| E33-MODFIELD-author | modules need author | Transactions, markets & economics | held |
| E33-MODFIELD-version | modules need version | Transactions, markets & economics | held |
| E33-MODFIELD-capabilities | modules need capabilities | Transactions, markets & economics | held |
| E33-MODFIELD-permissions | modules need permissions | Transactions, markets & economics | held |
| E33-MODFIELD-tests | modules need tests | Transactions, markets & economics | held |
| E33-MODFIELD-evidence | modules need evidence | Transactions, markets & economics | held |
| E33-MODFIELD-conformance | modules need conformance | Transactions, markets & economics | held |
| E33-MODFIELD-rollback | modules need rollback | Transactions, markets & economics | held |
| E33-SDK-identify | SDK identify is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-authorize | SDK authorize is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-check_capability | SDK check_capability is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-evaluate_risk | SDK evaluate_risk is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-request_execution | SDK request_execution is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-commit | SDK commit is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-produce_proof | SDK produce_proof is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-verify_proof | SDK verify_proof is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-record_evidence | SDK record_evidence is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-revoke | SDK revoke is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-delegate | SDK delegate is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-replay | SDK replay is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-conform | SDK conform is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-SDK-recover | SDK recover is a signed ABI call | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-mcp | gateway surface mcp states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-a2a | gateway surface a2a states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-http | gateway surface http states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-api | gateway surface api states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-tools | gateway surface tools states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-browser | gateway surface browser states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-computer_use | gateway surface computer_use states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-cloud | gateway surface cloud states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-code | gateway surface code states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-databases | gateway surface databases states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-financial_systems | gateway surface financial_systems states its real status | Tools, MCP, protocols & adapters | held |
| E33-GATEWAY-physical_interfaces | gateway surface physical_interfaces states its real status | Tools, MCP, protocols & adapters | held |
| E33-CLOUD-identity | cloud service identity is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-trust | cloud service trust is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-policy | cloud service policy is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-evidence | cloud service evidence is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-proof | cloud service proof is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-conformance | cloud service conformance is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-incident_response | cloud service incident_response is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-analytics | cloud service analytics is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-governance_learning | cloud service governance_learning is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-federation | cloud service federation is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-marketplace | cloud service marketplace is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-CLOUD-research | cloud service research is architecture only (NOT DEPLOYED) | Policy, law & governance | held |
| E33-PRODUCT-CAIN_Governance_Gateway | CAIN Governance Gateway maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Governance_Sidecar | CAIN Governance Sidecar maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Agent_Passport | CAIN Agent Passport maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Governance_Proof | CAIN Governance Proof maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Verify | CAIN Verify maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Conformance | CAIN Conformance maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Trust_Network | CAIN Trust Network maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Incident | CAIN Incident maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Edge | CAIN Edge maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Transactions | CAIN Transactions maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Research | CAIN Research maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Evolution | CAIN Evolution maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Machine_Economy | CAIN Machine Economy maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-PRODUCT-CAIN_Governance_Cloud | CAIN Governance Cloud maps to real code or says it is not deployed | Supply chain, registry & lifecycle | held |
| E33-MOAT-governance_infrastructure | governance_infrastructure is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-protocol_interoperability | protocol_interoperability is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-developer_sdk | developer_sdk is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-conformance_ecosystem | conformance_ecosystem is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-governance_proofs | governance_proofs is not claimed as an established market moat | Evidence, receipts & proofs | held |
| E33-MOAT-evidence_history | evidence_history is not claimed as an established market moat | Evidence, receipts & proofs | held |
| E33-MOAT-trust_federation | trust_federation is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-identity_continuity | identity_continuity is not claimed as an established market moat | Identity, authority & delegation | held |
| E33-MOAT-machine_reputation | machine_reputation is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-transaction_history | transaction_history is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-incident_intelligence | incident_intelligence is not claimed as an established market moat | Attacks, threats & containment | held |
| E33-MOAT-failure_corpus | failure_corpus is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-governance_datasets | governance_datasets is not claimed as an established market moat | Memory, data & privacy | held |
| E33-MOAT-verification_tooling | verification_tooling is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-policy_portability | policy_portability is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-integration_ecosystem | integration_ecosystem is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-edge_deployment | edge_deployment is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-enterprise_integration | enterprise_integration is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-research_ip | research_ip is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-standards_participation | standards_participation is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MOAT-switching_costs | switching_costs is not claimed as an established market moat | Transactions, markets & economics | held |
| E33-MANIFEST-identity | a governability manifest needs identity | Evidence, receipts & proofs | held |
| E33-MANIFEST-runtime | a governability manifest needs runtime | Evidence, receipts & proofs | held |
| E33-MANIFEST-model | a governability manifest needs model | Evidence, receipts & proofs | held |
| E33-MANIFEST-capabilities | a governability manifest needs capabilities | Evidence, receipts & proofs | held |
| E33-MANIFEST-protocols | a governability manifest needs protocols | Evidence, receipts & proofs | held |
| E33-MANIFEST-governance_boundaries | a governability manifest needs governance_boundaries | Evidence, receipts & proofs | held |
| E33-MANIFEST-enforcement_paths | a governability manifest needs enforcement_paths | Evidence, receipts & proofs | held |
| E33-MANIFEST-evidence_capabilities | a governability manifest needs evidence_capabilities | Evidence, receipts & proofs | held |
| E33-MANIFEST-proof_capabilities | a governability manifest needs proof_capabilities | Evidence, receipts & proofs | held |
| E33-MANIFEST-policy_capabilities | a governability manifest needs policy_capabilities | Evidence, receipts & proofs | held |
| E33-MANIFEST-delegation_rules | a governability manifest needs delegation_rules | Evidence, receipts & proofs | held |
| E33-MANIFEST-revocation | a governability manifest needs revocation | Evidence, receipts & proofs | held |
| E33-MANIFEST-limitations | a governability manifest needs limitations | Evidence, receipts & proofs | held |
| E33-MANIFEST-unknown_states | a governability manifest needs unknown_states | Evidence, receipts & proofs | held |
| E33-CERT-identity_verified | certificate claim identity_verified is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERT-authorization_verified | certificate claim authorization_verified is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERT-execution_boundary_verified | certificate claim execution_boundary_verified is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERT-proof_generated | certificate claim proof_generated is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERT-evidence_verified | certificate claim evidence_verified is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERT-conformance_passed | certificate claim conformance_passed is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERT-revocation_tested | certificate claim revocation_tested is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERT-recovery_tested | certificate claim recovery_tested is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERT-protocol_adapter_tested | certificate claim protocol_adapter_tested is scoped and never authority | Evidence, receipts & proofs | held |
| E33-CERTBAN-safe_ai | blanket claim safe_ai is refused | Evidence, receipts & proofs | held |
| E33-CERTBAN-fully_autonomous | blanket claim fully_autonomous is refused | Evidence, receipts & proofs | held |
| E33-CERTBAN-guaranteed_safe | blanket claim guaranteed_safe is refused | Evidence, receipts & proofs | held |
| E33-CERTBAN-aligned | blanket claim aligned is refused | Evidence, receipts & proofs | held |
| E33-CERTBAN-certified | blanket claim certified is refused | Evidence, receipts & proofs | held |
| E33-CERTBAN-secure | blanket claim secure is refused | Evidence, receipts & proofs | held |
| E33-DISCOVERY-policy | policy discovery records must be signed | Tools, MCP, protocols & adapters | held |
| E33-DISCOVERY-identity | identity discovery records must be signed | Tools, MCP, protocols & adapters | held |
| E33-DISCOVERY-verification | verification discovery records must be signed | Tools, MCP, protocols & adapters | held |
| E33-DISCOVERY-proof | proof discovery records must be signed | Tools, MCP, protocols & adapters | held |
| E33-DISCOVERY-conformance | conformance discovery records must be signed | Tools, MCP, protocols & adapters | held |
| E33-DISCOVERY-trust_domain | trust_domain discovery records must be signed | Tools, MCP, protocols & adapters | held |
| E33-DISCOVERY-enforcement_boundary | enforcement_boundary discovery records must be signed | Tools, MCP, protocols & adapters | held |
| E33-DISCOVERY-incident | incident discovery records must be signed | Tools, MCP, protocols & adapters | held |
| E33-NEGOTIATE-identity | negotiation without identity is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-capabilities | negotiation without capabilities is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-authority | negotiation without authority is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-policies | negotiation without policies is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-evidence_requirements | negotiation without evidence_requirements is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-proof_format | negotiation without proof_format is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-enforcement_expectations | negotiation without enforcement_expectations is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-liability_metadata | negotiation without liability_metadata is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-resource_budgets | negotiation without resource_budgets is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-revocation | negotiation without revocation is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-NEGOTIATE-incident_handling | negotiation without incident_handling is GOVERNANCE_UNKNOWN | Transactions, markets & economics | held |
| E33-HANDSHAKE-IDENTITY | an unknown IDENTITY stops the handshake | Identity, authority & delegation | held |
| E33-HANDSHAKE-CAPABILITY | an unknown CAPABILITY stops the handshake | Identity, authority & delegation | held |
| E33-HANDSHAKE-AUTHORITY | an unknown AUTHORITY stops the handshake | Identity, authority & delegation | held |
| E33-HANDSHAKE-POLICY | an unknown POLICY stops the handshake | Identity, authority & delegation | held |
| E33-HANDSHAKE-EVIDENCE | an unknown EVIDENCE stops the handshake | Identity, authority & delegation | held |
| E33-HANDSHAKE-ENFORCEMENT | an unknown ENFORCEMENT stops the handshake | Identity, authority & delegation | held |
| E33-HANDSHAKE-PROOF | an unknown PROOF stops the handshake | Identity, authority & delegation | held |
| E33-HANDSHAKE-REVOCATION | an unknown REVOCATION stops the handshake | Identity, authority & delegation | held |
| E33-HANDSHAKE-RECOVERY | an unknown RECOVERY stops the handshake | Identity, authority & delegation | held |
| E33-COVERAGE-ENFORCED | coverage class ENFORCED is reachable only from its evidence | Benchmarks, coverage & performance | held |
| E33-COVERAGE-VERIFIED | coverage class VERIFIED is reachable only from its evidence | Benchmarks, coverage & performance | held |
| E33-COVERAGE-MONITORED | coverage class MONITORED is reachable only from its evidence | Benchmarks, coverage & performance | held |
| E33-COVERAGE-OBSERVED | coverage class OBSERVED is reachable only from its evidence | Benchmarks, coverage & performance | held |
| E33-COVERAGE-BYPASSABLE | coverage class BYPASSABLE is reachable only from its evidence | Benchmarks, coverage & performance | held |
| E33-COVERAGE-UNKNOWN | coverage class UNKNOWN is reachable only from its evidence | Benchmarks, coverage & performance | held |
| E33-REGRESSION-authority_expansion | authority_expansion blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-enforcement_loss | enforcement_loss blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-evidence_loss | evidence_loss blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-proof_loss | proof_loss blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-revocation_regression | revocation_regression blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-identity_regression | identity_regression blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-delegation_regression | delegation_regression blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-memory_regression | memory_regression blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-world_model_regression | world_model_regression blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-latency_regression | latency_regression blocks a change | Benchmarks, coverage & performance | held |
| E33-REGRESSION-recovery_regression | recovery_regression blocks a change | Benchmarks, coverage & performance | held |
| E33-BOM-code | a compromised code is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-package | a compromised package is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-model | a compromised model is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-dataset | a compromised dataset is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-prompt_template | a compromised prompt_template is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-tool | a compromised tool is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-plugin | a compromised plugin is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-connector | a compromised connector is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-runtime | a compromised runtime is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-container | a compromised container is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-infrastructure | a compromised infrastructure is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-policy | a compromised policy is traced to operations | Evidence, receipts & proofs | held |
| E33-BOM-governance_module | a compromised governance_module is traced to operations | Evidence, receipts & proofs | held |
| E33-GAP-ungoverned_execution_path | the gap detector knows ungoverned_execution_path | Core guarantees | held |
| E33-GAP-unknown_channel | the gap detector knows unknown_channel | Tools, MCP, protocols & adapters | held |
| E33-GAP-authority_gap | the gap detector knows authority_gap | Identity, authority & delegation | held |
| E33-GAP-evidence_gap | the gap detector knows evidence_gap | Evidence, receipts & proofs | held |
| E33-GAP-proof_gap | the gap detector knows proof_gap | Evidence, receipts & proofs | held |
| E33-GAP-revocation_gap | the gap detector knows revocation_gap | Identity, authority & delegation | held |
| E33-GAP-recovery_gap | the gap detector knows recovery_gap | Autonomy, control loops & recovery | held |
| E33-GAP-identity_gap | the gap detector knows identity_gap | Identity, authority & delegation | held |
| E33-GAP-policy_gap | the gap detector knows policy_gap | Policy, law & governance | held |
| E33-GAP-supply_chain_gap | the gap detector knows supply_chain_gap | Evidence, receipts & proofs | held |
| E33-RADAR-WATCH | radar ring WATCH is never entered from research directly | Core guarantees | held |
| E33-RADAR-EXPERIMENT | radar ring EXPERIMENT is never entered from research directly | Core guarantees | held |
| E33-RADAR-PROTOTYPE | radar ring PROTOTYPE is never entered from research directly | Core guarantees | held |
| E33-RADAR-INTEGRATE | radar ring INTEGRATE is never entered from research directly | Core guarantees | held |
| E33-RADAR-VERIFY | radar ring VERIFY is never entered from research directly | Core guarantees | held |
| E33-RADAR-PRODUCTION | radar ring PRODUCTION is never entered from research directly | Supply chain, registry & lifecycle | held |
| E33-R2I-TECHNOLOGY_SIGNAL | TECHNOLOGY_SIGNAL cannot be skipped to | Core guarantees | held |
| E33-R2I-CAIN_RELEVANCE | CAIN_RELEVANCE cannot be skipped to | Core guarantees | held |
| E33-R2I-HYPOTHESIS | HYPOTHESIS cannot be skipped to | Core guarantees | held |
| E33-R2I-ARCHITECTURE_PROPOSAL | ARCHITECTURE_PROPOSAL cannot be skipped to | Core guarantees | held |
| E33-R2I-PROTOTYPE | PROTOTYPE cannot be skipped to | Core guarantees | held |
| E33-R2I-EXPERIMENT | EXPERIMENT cannot be skipped to | Core guarantees | held |
| E33-R2I-ADVERSARIAL_TEST | ADVERSARIAL_TEST cannot be skipped to | Attacks, threats & containment | held |
| E33-R2I-EVIDENCE | EVIDENCE cannot be skipped to | Evidence, receipts & proofs | held |
| E33-R2I-GOVERNANCE_REVIEW | GOVERNANCE_REVIEW cannot be skipped to | Policy, law & governance | held |
| E33-R2I-IMPLEMENTATION | IMPLEMENTATION cannot be skipped to | Core guarantees | held |
| E33-R2I-CONFORMANCE | CONFORMANCE cannot be skipped to | Policy, law & governance | held |
| E33-CONTRACTSTAGE-DISCOVER | contract stage DISCOVER is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-NEGOTIATE | contract stage NEGOTIATE is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-PROPOSE | contract stage PROPOSE is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-VERIFY | contract stage VERIFY is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-CONTRACT | contract stage CONTRACT is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-AUTHORIZE | contract stage AUTHORIZE is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-COMMIT | contract stage COMMIT is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-EXECUTE | contract stage EXECUTE is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-SETTLE | contract stage SETTLE is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-VERIFY_DELIVERY | contract stage VERIFY_DELIVERY is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-DISPUTE_OR_ACCEPT | contract stage DISPUTE_OR_ACCEPT is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-CONTRACTSTAGE-RECORD | contract stage RECORD is backed by E29's signed stages | Transactions, markets & economics | held |
| E33-AUTOPILOT-expand_authority | the autopilot may not expand_authority | Autonomy, control loops & recovery | held |
| E33-AUTOPILOT-disable_controls | the autopilot may not disable_controls | Autonomy, control loops & recovery | held |
| E33-AUTOPILOT-promote_itself | the autopilot may not promote_itself | Autonomy, control loops & recovery | held |
| E33-AUTOPILOT-alter_trust_roots | the autopilot may not alter_trust_roots | Autonomy, control loops & recovery | held |
| E33-AUTOPILOT-bypass_e8 | the autopilot may not bypass_e8 | Autonomy, control loops & recovery | held |
| E33-AUTOPILOT-deploy_unverified_governance | the autopilot may not deploy_unverified_governance | Autonomy, control loops & recovery | held |
| E33-CAT-identity | every identity scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-authority | every authority scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-delegation | every delegation scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-capability | every capability scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-policy | every policy scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-memory | every memory scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-evidence | every evidence scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-proof | every proof scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-verifier | every verifier scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-communication | every communication scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-collective | every collective scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-economic | every economic scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-transaction | every transaction scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-supply_chain | every supply_chain scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-runtime | every runtime scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-model | every model scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-world_model | every world_model scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-physical_action | every physical_action scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-computer_use | every computer_use scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-self_improvement | every self_improvement scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-governance_loop | every governance_loop scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-recursive | every recursive scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-recovery | every recovery scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-partition | every partition scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-byzantine | every byzantine scenario holds | Benchmarks, coverage & performance | held |
| E33-CAT-insider | every insider scenario holds | Benchmarks, coverage & performance | held |
| E33-RESEARCH-R1 | research item R1 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R2 | research item R2 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R3 | research item R3 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R4 | research item R4 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R5 | research item R5 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R6 | research item R6 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R7 | research item R7 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R8 | research item R8 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R9 | research item R9 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R10 | research item R10 has provenance and no authority | Identity, authority & delegation | held |
| E33-RESEARCH-R11 | research item R11 has provenance and no authority | Identity, authority & delegation | held |