CAIN-42 invariant · E36
E36-PASSPORT-recovery_history: a passport without recovery_history is refused
Held · CAIN-42 Evolution 36 -- Machine Agency Exchange Fabric
Last reviewed 2026-10-01
held niche Identity, authority & delegation · family service_passport
What this rule means
CAIN-42 must always satisfy: a passport without recovery_history is refused. It is one of 842 invariants checked for CAIN-42 Evolution 36 -- Machine Agency Exchange Fabric. An invariant is a rule the system may never break, whatever an agent or attacker does; the test suite tries to break it across many scenarios and records the result.
Recorded detail
'ExchangeError:PASSPORT_FIELD_MISSING:recovery_history'Products this protects
- CAIN Agent Labor — Rules for agents doing paid work: who did what, and who gets credit.
- CAIN Agent Procurement — Let agents buy things for you, within limits you set.
- CAIN Agent Store — A store of reviewed, governed agents.
- CAIN Dispute — Settle disagreements between agents or companies using signed evidence.
- CAIN Economy Simulator — Simulate many agents trading, to find failures before they happen.
- CAIN Governance Warranty — A written commitment backed by evidence that governance held.
- CAIN Machine Contracts — Contracts that agents can make and keep, with evidence.
- CAIN Machine Economy — Rules for agents that pay and get paid.
- CAIN Machine Organizations — Organisations made of agents, governed like companies.
- CAIN Machine Reputation — Reputation for agents, earned from signed history.
- CAIN Marketplace — A marketplace for governed agent services.
- CAIN Procurement Intelligence — Helps buyers compare agent vendors on evidence.
- CAIN Proof Market — A market where verified proofs have value.
- CAIN Service Exchange — Agents offering and buying services from each other, governed.
- CAIN Service Intelligence — Insight into which agent services are worth trusting.
- CAIN Threat Intelligence — Shared intelligence on attacks against AI agents.
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Check it yourself
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Scope: An in-process TESTED library; not hosted, not a deployed network. The directory and marketplace are local registries, not a public exchange.
Related rules
- E36-DOMAIN-SERVICE-IDENTITY: signed domain SERVICE-IDENTITY is defined
- E36-DOMAIN-SERVICE-PASSPORT: signed domain SERVICE-PASSPORT is defined
- E36-DOMAIN-CAPABILITY: signed domain CAPABILITY is defined
- E36-DOMAIN-PAYMENT-AUTHORIZATION: signed domain PAYMENT-AUTHORIZATION is defined
- E36-DOMAIN-REVOCATION: signed domain REVOCATION is defined
- E36-PASSPORT-service_id: a passport without service_id is refused
- E36-PASSPORT-owner_id: a passport without owner_id is refused
- E36-PASSPORT-operator_id: a passport without operator_id is refused
← E36-PASSPORT-incident_history · all 842 · E36-PASSPORT-security_history →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem