Evidence library · niche
Identity, authority & delegation
Who an agent is, what it may do, and who allowed it. 964 tested invariants.
Last reviewed 2026-10-01
964 of 964 held
Test families in this niche
capability (54) · handshake (54) · authorization_binding (49) · aip (48) · revocation (26) · credential (25) · domain (21) · service_passport (21) · non_authority (18) · binding (16) · lease_v2 (15) · protected_key (14) · research (13) · state_machine (11) · cross_domain (11) · delegation (11) · kernel (11) · delegation_attenuation (9) · replay_revocation (9) · moat (9) · risk (6) · failure_class (6) · root_of_trust (6) · telemetry (5) · action (5) · action_binding (4) · config_key (4) · knowledge_revocation (4) · primitive (4) · agency_graph (4) · relationship (4) · delegation_receipt (3) · reassessment (3) · capability_passport (3) · authority_graph (3) · integrity (3) · consistency (3) · soc (3) · lease (3) · operation_kind (3) · event_kind (3) · exhaustion_mode (3) · gap_detector (3) · profile (3) · graph (3) · approval (2) · offline (2) · registration (2) · scientist (2) · radar (2) · federation (1) · intent (1) · tenancy (1) · cross-domain (1) · passport (1) · stage (1) · operation_state (1) · status (1) · environment_query (1) · ip (1) · competitive_gap (1) · authority_algebra (1) · minimum_authority (1) · systemic (1)
Where these come from
- CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric: 198
- CAIN-42 Evolution 25 -- Universal Machine Agency Fabric: 105
- CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric: 90
- CAIN-42 Evolution 23 -- Governed Meta-Intelligence Fabric: 84
- CAIN-42 Evolution 27 -- Agentic Internet Control Plane: 64
- CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric: 52
- CAIN-42 Evolution 33 -- Governed Agentic Operating Fabric: 49
- CAIN-42 Evolution 36 -- Machine Agency Exchange Fabric: 49
- CAIN-42 Evolution 19 -- Governed Autonomy Operating Fabric: 43
- CAIN-42 Evolution 21 -- Governed Open-Ended Intelligence Fabric: 40
- CAIN-42 Evolution 20 -- Governed Agentic Civilization Fabric: 36
- CAIN-42 Evolution 32 -- Governed Autonomy Learning Fabric: 34
- CAIN-42 Evolution 41 -- Machine Agency Exchange Fabric: 28
- CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform: 24
- CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric: 21
- CAIN-42 Evolution 34 -- Proof-Carrying Machine Agency: 20
- CAIN-42 Evolution 28 -- Portable Machine Agency & Execution Identity: 18
- CAIN-42 Evolution 30 -- Governed Machine Autonomy Fabric: 2
- CAIN-42 Evolution 37 -- Autonomous Execution Mesh: 2
- CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency: 2
- CAIN-42 Evolution 29 -- Governed Agentic Internet Transaction Fabric: 1
- CAIN-42 Evolution 39 -- Governed Agent Factory: 1
- CAIN-42 Evolution 40 -- Autonomous Enterprise Intelligence Fabric: 1
Rules 1–150 of 964
| ID | Rule | Bundle | Result |
|---|---|---|---|
| G1 | identity cannot self-authorize | E19 | held |
| G2 | goals cannot create authority | E19 | held |
| G3 | subgoals cannot exceed parent authority | E19 | held |
| G4 | memory cannot create authority | E19 | held |
| G5 | beliefs cannot create authority | E19 | held |
| G6 | predictions cannot create authority | E19 | held |
| G7 | confidence cannot create authority | E19 | held |
| G9 | learning cannot create authority | E19 | held |
| G10 | capability cannot create authority | E19 | held |
| G11 | stale state cannot authorize | E19 | held |
| G12 | invalid evidence cannot authorize | E19 | held |
| G13 | expired authority cannot authorize | E19 | held |
| G14 | revoked authority cannot authorize | E19 | held |
| G15 | changed world state can invalidate authorization | E19 | held |
| G16 | changed trajectory can invalidate authorization | E19 | held |
| G17 | changed model can invalidate authorization | E19 | held |
| G18 | changed policy can invalidate authorization | E19 | held |
| G19 | changed capability can invalidate authorization | E19 | held |
| G20 | changed identity can invalidate authorization | E19 | held |
| G26 | authority cannot increase through degradation | E19 | held |
| G28 | recovery cannot create authority | E19 | held |
| G29 | self-improvement cannot create authority | E19 | held |
| G30 | model replacement cannot create authority | E19 | held |
| G31 | collective agreement cannot create authority | E19 | held |
| G32 | delegation cannot exceed parent authority | E19 | held |
| G33 | agent cloning cannot inherit authority | E19 | held |
| G34 | memory sharing cannot transfer authority | E19 | held |
| G37 | every action has canonical identity | E19 | held |
| G39 | every action has authority binding | E19 | held |
| G48 | state replay cannot create new authority | E19 | held |
| G50 | recovery cannot bypass authorization | E19 | held |
| G57 | mission expiration invalidates authority | E19 | held |
| G59 | revoked human authority propagates | E19 | held |
| G60 | revoked collective membership propagates | E19 | held |
| G61 | execution result cannot rewrite authorization history | E19 | held |
| G62 | outcome cannot retroactively authorize action | E19 | held |
| G81 | no hidden authority path | E19 | held |
| G85 | no authorization resurrection | E19 | held |
| G88 | policy evolution cannot silently expand authority | E19 | held |
| G89 | capability composition cannot silently expand authority | E19 | held |
| G90 | agent composition cannot silently expand authority | E19 | held |
| G102 | a clone sharing a credential is refused by the collective | E19 | held |
| G104 | a human REJECT is never read as approval | E19 | held |
| I1 | organization cannot create authority | E20 | held |
| I2 | institution cannot create authority | E20 | held |
| I3 | wealth cannot create authority | E20 | held |
| I4 | resources cannot create authority | E20 | held |
| I5 | reputation cannot create authority | E20 | held |
| I6 | membership cannot create authority | E20 | held |
| I7 | majority cannot create authority | E20 | held |
| I9 | negotiation cannot create authority | E20 | held |
| I10 | contract cannot exceed issuer authority | E20 | held |
| I11 | child agent cannot inherit unlimited authority | E20 | held |
| I13 | institutional memory cannot create authority | E20 | held |
| I14 | institutional reputation cannot create authority | E20 | held |
| I15 | organizational evolution cannot create authority | E20 | held |
| I16 | economic success cannot create authority | E20 | held |
| I17 | capability accumulation cannot create authority | E20 | held |
| I19 | delegation cannot exceed parent authority | E20 | held |
| I24 | authority relationships require provenance | E20 | held |
| I26 | terminated authority cannot resurrect | E20 | held |
| I28 | expired contracts cannot authorize | E20 | held |
| I29 | revoked relationships cannot authorize | E20 | held |
| I30 | revoked credentials cannot authorize | E20 | held |
| I35 | economic simulation cannot create authority | E20 | held |
| I40 | institutional recovery cannot create authority | E20 | held |
| I43 | trust is not authority | E20 | held |
| I45 | capability is not permission | E20 | held |
| I52 | member authority is an intersection, never a sum | E20 | held |
| I53 | institution authority re-derives as boundary ∩ founding ∩ state ceiling ∩ parent | E20 | held |
| I59 | legitimate member action is authorized | E20 | held |
| I64 | legitimate delegation works | E20 | held |
| I80 | memory, knowledge, evidence, policy and authority are separate | E20 | held |
| I83 | trust revocation is effective | E20 | held |
| I98 | EXECUTE needs an AUTHORIZED decision | E20 | held |
| I100 | authority contracts automatically on deterioration | E20 | held |
| I105 | approvals are subject-bound | E20 | held |
| I106 | cross-institution authority is re-checked against the grantor at use | E20 | held |
| I108 | market eligibility is computed authority | E20 | held |
| D1 | discovery cannot create authority | E21 | held |
| D2 | hypothesis cannot create authority | E21 | held |
| D3 | confidence cannot create authority | E21 | held |
| D4 | model prediction cannot create authority | E21 | held |
| D5 | simulation cannot create authority | E21 | held |
| D6 | experiment result cannot create authority | E21 | held |
| D8 | research reputation cannot create authority | E21 | held |
| D9 | intelligence improvement cannot create authority | E21 | held |
| D10 | benchmark performance cannot create authority | E21 | held |
| D14 | revoked evidence cannot support authorization | E21 | held |
| D15 | stale evidence cannot silently authorize | E21 | held |
| D31 | learning cannot silently change authority | E21 | held |
| D32 | self-improvement cannot silently change authority | E21 | held |
| D33 | agent spawning cannot silently change authority | E21 | held |
| D34 | research success cannot silently change authority | E21 | held |
| D35 | knowledge accumulation cannot silently change authority | E21 | held |
| D36 | capability promotion requires governance | E21 | held |
| D48 | revoked claims propagate | E21 | held |
| D56 | research authority is bounded | E21 | held |
| D57 | experiment authority is bounded | E21 | held |
| D58 | reviewer authority is bounded | E21 | held |
| D59 | researcher authority is bounded | E21 | held |
| D60 | institutional research authority is bounded | E21 | held |
| D62 | no capability bypasses E8 | E21 | held |
| D76 | autonomous research may continue without autonomous authority escalation | E21 | held |
| D82 | policy does not become authority automatically | E21 | held |
| D83 | authority does not become execution automatically | E21 | held |
| D86 | discovery loops cannot create infinite authority | E21 | held |
| D87 | self-reference cannot create constitutional authority | E21 | held |
| D88 | recursive agents cannot recursively amplify authority | E21 | held |
| D89 | nested institutions cannot recursively amplify authority | E21 | held |
| D90 | delegated research cannot exceed parent authority | E21 | held |
| D91 | experiment environments are identity-bound | E21 | held |
| D101 | research authority is disjoint from execution authority | E21 | held |
| D102 | authority functions take no epistemic input | E21 | held |
| D135 | experiment approvals are single-use and expire | E21 | held |
| D136 | information value is correct and is not permission | E21 | held |
| D137 | curiosity is not authority | E21 | held |
| D147 | hypothesis ranking is not authority | E21 | held |
| D154 | research roles are assigned within the assigner's authority | E21 | held |
| META-I001 | self-model cannot mint authority | E23 | held |
| META-I002 | architecture search cannot mint authority | E23 | held |
| META-I003 | capability discovery cannot mint authority | E23 | held |
| META-I004 | failure discovery cannot mint authority | E23 | held |
| META-I005 | self-improvement cannot mint authority | E23 | held |
| META-I007 | architecture optimization cannot mint authority | E23 | held |
| META-I008 | objective optimization cannot mint authority | E23 | held |
| META-I009 | evaluation success cannot mint authority | E23 | held |
| META-I010 | benchmark success cannot mint authority | E23 | held |
| META-I011 | child authority ⊆ parent authority | E23 | held |
| META-I012 | recursive authority cannot expand | E23 | held |
| META-I013 | architecture replacement cannot expand authority | E23 | held |
| META-I014 | model replacement cannot expand authority | E23 | held |
| META-I015 | memory replacement cannot expand authority | E23 | held |
| META-I016 | evolution proposal ≠ evolution authorization | E23 | held |
| META-I020 | rollback ≠ authority restoration | E23 | held |
| META-I023 | unknown capability cannot become executable | E23 | held |
| META-I025 | unknown execution path cannot become authorized | E23 | held |
| META-I029 | authority change requires governance | E23 | held |
| META-I033 | sandbox output cannot directly authorize production | E23 | held |
| META-I034 | simulation credentials cannot become production credentials | E23 | held |
| META-I035 | test identity cannot become production identity | E23 | held |
| META-I036 | rollback cannot resurrect revoked identity | E23 | held |
| META-I037 | rollback cannot resurrect revoked capability | E23 | held |
| META-I038 | rollback cannot resurrect expired authority | E23 | held |
| META-I068 | authority-path changes are flagged by the blast radius | E23 | held |
| META-I069 | concentration is reported and is not authority | E23 | held |
| META-I074 | structured traces are stored and carry no authority | E23 | held |
| META-I075 | introspection carries no authority | E23 | held |
| META-I077 | no non-authority input is read by the authority or promotion functions | E23 | held |
| META-I079 | runtime modes only contract authority | E23 | held |
Other niches
Consensus & distributed systems · Attacks, threats & containment · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem