CAIN-42 CAIN Studio

Evidence library · niche

Identity, authority & delegation

Who an agent is, what it may do, and who allowed it. 964 tested invariants.

Last reviewed 2026-10-01

964 of 964 held

Where this niche's rules come from

Test families in this niche

capability (54) · handshake (54) · authorization_binding (49) · aip (48) · revocation (26) · credential (25) · domain (21) · service_passport (21) · non_authority (18) · binding (16) · lease_v2 (15) · protected_key (14) · research (13) · state_machine (11) · cross_domain (11) · delegation (11) · kernel (11) · delegation_attenuation (9) · replay_revocation (9) · moat (9) · risk (6) · failure_class (6) · root_of_trust (6) · telemetry (5) · action (5) · action_binding (4) · config_key (4) · knowledge_revocation (4) · primitive (4) · agency_graph (4) · relationship (4) · delegation_receipt (3) · reassessment (3) · capability_passport (3) · authority_graph (3) · integrity (3) · consistency (3) · soc (3) · lease (3) · operation_kind (3) · event_kind (3) · exhaustion_mode (3) · gap_detector (3) · profile (3) · graph (3) · approval (2) · offline (2) · registration (2) · scientist (2) · radar (2) · federation (1) · intent (1) · tenancy (1) · cross-domain (1) · passport (1) · stage (1) · operation_state (1) · status (1) · environment_query (1) · ip (1) · competitive_gap (1) · authority_algebra (1) · minimum_authority (1) · systemic (1)

Where these come from

Rules 1–150 of 964

IDRuleBundleResult
G1identity cannot self-authorizeE19held
G2goals cannot create authorityE19held
G3subgoals cannot exceed parent authorityE19held
G4memory cannot create authorityE19held
G5beliefs cannot create authorityE19held
G6predictions cannot create authorityE19held
G7confidence cannot create authorityE19held
G9learning cannot create authorityE19held
G10capability cannot create authorityE19held
G11stale state cannot authorizeE19held
G12invalid evidence cannot authorizeE19held
G13expired authority cannot authorizeE19held
G14revoked authority cannot authorizeE19held
G15changed world state can invalidate authorizationE19held
G16changed trajectory can invalidate authorizationE19held
G17changed model can invalidate authorizationE19held
G18changed policy can invalidate authorizationE19held
G19changed capability can invalidate authorizationE19held
G20changed identity can invalidate authorizationE19held
G26authority cannot increase through degradationE19held
G28recovery cannot create authorityE19held
G29self-improvement cannot create authorityE19held
G30model replacement cannot create authorityE19held
G31collective agreement cannot create authorityE19held
G32delegation cannot exceed parent authorityE19held
G33agent cloning cannot inherit authorityE19held
G34memory sharing cannot transfer authorityE19held
G37every action has canonical identityE19held
G39every action has authority bindingE19held
G48state replay cannot create new authorityE19held
G50recovery cannot bypass authorizationE19held
G57mission expiration invalidates authorityE19held
G59revoked human authority propagatesE19held
G60revoked collective membership propagatesE19held
G61execution result cannot rewrite authorization historyE19held
G62outcome cannot retroactively authorize actionE19held
G81no hidden authority pathE19held
G85no authorization resurrectionE19held
G88policy evolution cannot silently expand authorityE19held
G89capability composition cannot silently expand authorityE19held
G90agent composition cannot silently expand authorityE19held
G102a clone sharing a credential is refused by the collectiveE19held
G104a human REJECT is never read as approvalE19held
I1organization cannot create authorityE20held
I2institution cannot create authorityE20held
I3wealth cannot create authorityE20held
I4resources cannot create authorityE20held
I5reputation cannot create authorityE20held
I6membership cannot create authorityE20held
I7majority cannot create authorityE20held
I9negotiation cannot create authorityE20held
I10contract cannot exceed issuer authorityE20held
I11child agent cannot inherit unlimited authorityE20held
I13institutional memory cannot create authorityE20held
I14institutional reputation cannot create authorityE20held
I15organizational evolution cannot create authorityE20held
I16economic success cannot create authorityE20held
I17capability accumulation cannot create authorityE20held
I19delegation cannot exceed parent authorityE20held
I24authority relationships require provenanceE20held
I26terminated authority cannot resurrectE20held
I28expired contracts cannot authorizeE20held
I29revoked relationships cannot authorizeE20held
I30revoked credentials cannot authorizeE20held
I35economic simulation cannot create authorityE20held
I40institutional recovery cannot create authorityE20held
I43trust is not authorityE20held
I45capability is not permissionE20held
I52member authority is an intersection, never a sumE20held
I53institution authority re-derives as boundary ∩ founding ∩ state ceiling ∩ parentE20held
I59legitimate member action is authorizedE20held
I64legitimate delegation worksE20held
I80memory, knowledge, evidence, policy and authority are separateE20held
I83trust revocation is effectiveE20held
I98EXECUTE needs an AUTHORIZED decisionE20held
I100authority contracts automatically on deteriorationE20held
I105approvals are subject-boundE20held
I106cross-institution authority is re-checked against the grantor at useE20held
I108market eligibility is computed authorityE20held
D1discovery cannot create authorityE21held
D2hypothesis cannot create authorityE21held
D3confidence cannot create authorityE21held
D4model prediction cannot create authorityE21held
D5simulation cannot create authorityE21held
D6experiment result cannot create authorityE21held
D8research reputation cannot create authorityE21held
D9intelligence improvement cannot create authorityE21held
D10benchmark performance cannot create authorityE21held
D14revoked evidence cannot support authorizationE21held
D15stale evidence cannot silently authorizeE21held
D31learning cannot silently change authorityE21held
D32self-improvement cannot silently change authorityE21held
D33agent spawning cannot silently change authorityE21held
D34research success cannot silently change authorityE21held
D35knowledge accumulation cannot silently change authorityE21held
D36capability promotion requires governanceE21held
D48revoked claims propagateE21held
D56research authority is boundedE21held
D57experiment authority is boundedE21held
D58reviewer authority is boundedE21held
D59researcher authority is boundedE21held
D60institutional research authority is boundedE21held
D62no capability bypasses E8E21held
D76autonomous research may continue without autonomous authority escalationE21held
D82policy does not become authority automaticallyE21held
D83authority does not become execution automaticallyE21held
D86discovery loops cannot create infinite authorityE21held
D87self-reference cannot create constitutional authorityE21held
D88recursive agents cannot recursively amplify authorityE21held
D89nested institutions cannot recursively amplify authorityE21held
D90delegated research cannot exceed parent authorityE21held
D91experiment environments are identity-boundE21held
D101research authority is disjoint from execution authorityE21held
D102authority functions take no epistemic inputE21held
D135experiment approvals are single-use and expireE21held
D136information value is correct and is not permissionE21held
D137curiosity is not authorityE21held
D147hypothesis ranking is not authorityE21held
D154research roles are assigned within the assigner's authorityE21held
META-I001self-model cannot mint authorityE23held
META-I002architecture search cannot mint authorityE23held
META-I003capability discovery cannot mint authorityE23held
META-I004failure discovery cannot mint authorityE23held
META-I005self-improvement cannot mint authorityE23held
META-I007architecture optimization cannot mint authorityE23held
META-I008objective optimization cannot mint authorityE23held
META-I009evaluation success cannot mint authorityE23held
META-I010benchmark success cannot mint authorityE23held
META-I011child authority ⊆ parent authorityE23held
META-I012recursive authority cannot expandE23held
META-I013architecture replacement cannot expand authorityE23held
META-I014model replacement cannot expand authorityE23held
META-I015memory replacement cannot expand authorityE23held
META-I016evolution proposal ≠ evolution authorizationE23held
META-I020rollback ≠ authority restorationE23held
META-I023unknown capability cannot become executableE23held
META-I025unknown execution path cannot become authorizedE23held
META-I029authority change requires governanceE23held
META-I033sandbox output cannot directly authorize productionE23held
META-I034simulation credentials cannot become production credentialsE23held
META-I035test identity cannot become production identityE23held
META-I036rollback cannot resurrect revoked identityE23held
META-I037rollback cannot resurrect revoked capabilityE23held
META-I038rollback cannot resurrect expired authorityE23held
META-I068authority-path changes are flagged by the blast radiusE23held
META-I069concentration is reported and is not authorityE23held
META-I074structured traces are stored and carry no authorityE23held
META-I075introspection carries no authorityE23held
META-I077no non-authority input is read by the authority or promotion functionsE23held
META-I079runtime modes only contract authorityE23held

1 2 3 4 5 6 7

Other niches

Consensus & distributed systems · Attacks, threats & containment · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem