Evidence library · family
Envelope
52 tested rules in the 'envelope' family, 52 held.
Last reviewed 2026-10-01
52 of 52 held niche Evidence, receipts & proofs
What this family tests
Every rule the CAIN-42 test suites recorded under the family envelope, across 2 evidence bundles. Each rule links to its own page with the recorded result and an in-browser check of the file it came from.
| ID | Rule | Bundle | Result |
|---|---|---|---|
| E28-I21 | identity envelope signed by another key is refused | E28 | held |
| E28-I22 | a tampered envelope field is refused on decode | E28 | held |
| E28-I23 | an envelope for another audience is refused | E28 | held |
| E28-I24 | an expired envelope is refused | E28 | held |
| E28-I25 | a session envelope cannot stand in for a transaction envelope | E28 | held |
| E28-I26 | a transaction envelope cannot live longer than 30 s | E28 | held |
| E28-I27 | the envelope authority field is always NONE, whatever the issuer is asked | E28 | held |
| E34-ENVELOPE-proof_id | the envelope binds proof_id for every executed operation | E34 | held |
| E34-ENVELOPE-proof_version | the envelope binds proof_version for every executed operation | E34 | held |
| E34-ENVELOPE-action_id | the envelope binds action_id for every executed operation | E34 | held |
| E34-ENVELOPE-operation_id | the envelope binds operation_id for every executed operation | E34 | held |
| E34-ENVELOPE-transaction_id | the envelope binds transaction_id for every executed operation | E34 | held |
| E34-ENVELOPE-agent_identity | the envelope binds agent_identity for every executed operation | E34 | held |
| E34-ENVELOPE-agent_passport_digest | the envelope binds agent_passport_digest for every executed operation | E34 | held |
| E34-ENVELOPE-identity_state | the envelope binds identity_state for every executed operation | E34 | held |
| E34-ENVELOPE-capability_state | the envelope binds capability_state for every executed operation | E34 | held |
| E34-ENVELOPE-delegation_chain | the envelope binds delegation_chain for every executed operation | E34 | held |
| E34-ENVELOPE-authority_state | the envelope binds authority_state for every executed operation | E34 | held |
| E34-ENVELOPE-authority_digest | the envelope binds authority_digest for every executed operation | E34 | held |
| E34-ENVELOPE-policy_digest | the envelope binds policy_digest for every executed operation | E34 | held |
| E34-ENVELOPE-policy_version | the envelope binds policy_version for every executed operation | E34 | held |
| E34-ENVELOPE-context_digest | the envelope binds context_digest for every executed operation | E34 | held |
| E34-ENVELOPE-evidence_digest | the envelope binds evidence_digest for every executed operation | E34 | held |
| E34-ENVELOPE-risk_digest | the envelope binds risk_digest for every executed operation | E34 | held |
| E34-ENVELOPE-decision_digest | the envelope binds decision_digest for every executed operation | E34 | held |
| E34-ENVELOPE-trajectory_digest | the envelope binds trajectory_digest for every executed operation | E34 | held |
| E34-ENVELOPE-world_state_digest | the envelope binds world_state_digest for every executed operation | E34 | held |
| E34-ENVELOPE-model_runtime_identity | the envelope binds model_runtime_identity for every executed operation | E34 | held |
| E34-ENVELOPE-model_runtime_version | the envelope binds model_runtime_version for every executed operation | E34 | held |
| E34-ENVELOPE-execution_environment | the envelope binds execution_environment for every executed operation | E34 | held |
| E34-ENVELOPE-capability_used | the envelope binds capability_used for every executed operation | E34 | held |
| E34-ENVELOPE-resource_target | the envelope binds resource_target for every executed operation | E34 | held |
| E34-ENVELOPE-requested_effect | the envelope binds requested_effect for every executed operation | E34 | held |
| E34-ENVELOPE-authorization_id | the envelope binds authorization_id for every executed operation | E34 | held |
| E34-ENVELOPE-authorization_scope | the envelope binds authorization_scope for every executed operation | E34 | held |
| E34-ENVELOPE-authorization_expiry | the envelope binds authorization_expiry for every executed operation | E34 | held |
| E34-ENVELOPE-authorization_nonce | the envelope binds authorization_nonce for every executed operation | E34 | held |
| E34-ENVELOPE-e8_commit_id | the envelope binds e8_commit_id for every executed operation | E34 | held |
| E34-ENVELOPE-enforcement_boundary | the envelope binds enforcement_boundary for every executed operation | E34 | held |
| E34-ENVELOPE-enforcement_result | the envelope binds enforcement_result for every executed operation | E34 | held |
| E34-ENVELOPE-execution_result | the envelope binds execution_result for every executed operation | E34 | held |
| E34-ENVELOPE-outcome_evidence | the envelope binds outcome_evidence for every executed operation | E34 | held |
| E34-ENVELOPE-revocation_state | the envelope binds revocation_state for every executed operation | E34 | held |
| E34-ENVELOPE-conformance_state | the envelope binds conformance_state for every executed operation | E34 | held |
| E34-ENVELOPE-governance_coverage | the envelope binds governance_coverage for every executed operation | E34 | held |
| E34-ENVELOPE-proof_status | the envelope binds proof_status for every executed operation | E34 | held |
| E34-ENVELOPE-timestamp | the envelope binds timestamp for every executed operation | E34 | held |
| E34-ENVELOPE-sequence | the envelope binds sequence for every executed operation | E34 | held |
| E34-ENVELOPE-previous_proof_hash | the envelope binds previous_proof_hash for every executed operation | E34 | held |
| E34-ENVELOPE-evidence_references | the envelope binds evidence_references for every executed operation | E34 | held |
| E34-ENVELOPE-verifier_metadata | the envelope binds verifier_metadata for every executed operation | E34 | held |
| E34-ENVELOPE-governance_contract_digest | the envelope binds governance_contract_digest for every executed operation | E34 | held |
Other families in this niche
domain · moat · packet · receipt · research · certificate · supply_chain · state_machine · agency_graph · envelope_binding · telemetry · integrity · graph · proof · radar · risk · event_kind · action_binding · proof_carrying_action · ip · failure_class · status · environment_query · attestation
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem