Evidence library · niche
Identity, authority & delegation
Who an agent is, what it may do, and who allowed it. 964 tested invariants.
Last reviewed 2026-10-01
964 of 964 held
Test families in this niche
capability (54) · handshake (54) · authorization_binding (49) · aip (48) · revocation (26) · credential (25) · domain (21) · service_passport (21) · non_authority (18) · binding (16) · lease_v2 (15) · protected_key (14) · research (13) · state_machine (11) · cross_domain (11) · delegation (11) · kernel (11) · delegation_attenuation (9) · replay_revocation (9) · moat (9) · risk (6) · failure_class (6) · root_of_trust (6) · telemetry (5) · action (5) · action_binding (4) · config_key (4) · knowledge_revocation (4) · primitive (4) · agency_graph (4) · relationship (4) · delegation_receipt (3) · reassessment (3) · capability_passport (3) · authority_graph (3) · integrity (3) · consistency (3) · soc (3) · lease (3) · operation_kind (3) · event_kind (3) · exhaustion_mode (3) · gap_detector (3) · profile (3) · graph (3) · approval (2) · offline (2) · registration (2) · scientist (2) · radar (2) · federation (1) · intent (1) · tenancy (1) · cross-domain (1) · passport (1) · stage (1) · operation_state (1) · status (1) · environment_query (1) · ip (1) · competitive_gap (1) · authority_algebra (1) · minimum_authority (1) · systemic (1)
Where these come from
- CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric: 198
- CAIN-42 Evolution 25 -- Universal Machine Agency Fabric: 105
- CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric: 90
- CAIN-42 Evolution 23 -- Governed Meta-Intelligence Fabric: 84
- CAIN-42 Evolution 27 -- Agentic Internet Control Plane: 64
- CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric: 52
- CAIN-42 Evolution 33 -- Governed Agentic Operating Fabric: 49
- CAIN-42 Evolution 36 -- Machine Agency Exchange Fabric: 49
- CAIN-42 Evolution 19 -- Governed Autonomy Operating Fabric: 43
- CAIN-42 Evolution 21 -- Governed Open-Ended Intelligence Fabric: 40
- CAIN-42 Evolution 20 -- Governed Agentic Civilization Fabric: 36
- CAIN-42 Evolution 32 -- Governed Autonomy Learning Fabric: 34
- CAIN-42 Evolution 41 -- Machine Agency Exchange Fabric: 28
- CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform: 24
- CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric: 21
- CAIN-42 Evolution 34 -- Proof-Carrying Machine Agency: 20
- CAIN-42 Evolution 28 -- Portable Machine Agency & Execution Identity: 18
- CAIN-42 Evolution 30 -- Governed Machine Autonomy Fabric: 2
- CAIN-42 Evolution 37 -- Autonomous Execution Mesh: 2
- CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency: 2
- CAIN-42 Evolution 29 -- Governed Agentic Internet Transaction Fabric: 1
- CAIN-42 Evolution 39 -- Governed Agent Factory: 1
- CAIN-42 Evolution 40 -- Autonomous Enterprise Intelligence Fabric: 1
Rules 151–300 of 964
| ID | Rule | Bundle | Result |
|---|---|---|---|
| META-P001 | every compiled candidate routes every execution path through AUTHORIZATION (all depth-2 candidates) | E23 | held |
| META-P007 | every compiled candidate has bounded credentials (all depth-2 candidates) | E23 | held |
| META-P012 | no candidate's sandbox result carries authority (all depth-2 candidates) | E23 | held |
| META-P016 | no candidate diff carries authority (all depth-2 candidates) | E23 | held |
| META-P017 | no candidate unknown-scan carries authority (all depth-2 candidates) | E23 | held |
| META-P020 | every dependency report carries no authority (all depth-2 candidates) | E23 | held |
| META-L001 | META-001 SELF-KNOWLEDGE IS NOT AUTHORITY | E23 | held |
| META-L003 | META-003 SELF-IMPROVEMENT IS NOT SELF-AUTHORIZATION | E23 | held |
| META-L004 | META-004 INTELLIGENCE GAIN IS NOT AUTHORITY GAIN | E23 | held |
| META-L005 | META-005 CAPABILITY DISCOVERY IS NOT CAPABILITY PERMISSION | E23 | held |
| META-L006 | META-006 ARCHITECTURE DISCOVERY IS NOT DEPLOYMENT AUTHORIZATION | E23 | held |
| META-L008 | META-008 REASONING ABOUT GOVERNANCE IS NOT AUTHORITY OVER GOVERNANCE | E23 | held |
| META-L009 | META-009 DISCOVERING A POLICY WEAKNESS IS NOT PERMISSION TO EXPLOIT IT | E23 | held |
| META-L010 | META-010 DISCOVERING AN E8 WEAKNESS IS NOT PERMISSION TO BYPASS E8 | E23 | held |
| META-L011 | META-011 DISCOVERING A CAIN BUG IS NOT PERMISSION TO MODIFY GOVERNANCE STATE | E23 | held |
| META-L012 | META-012 MODEL IMPROVEMENT MUST NOT SILENTLY CHANGE AUTHORITY | E23 | held |
| META-L013 | META-013 ARCHITECTURE REPLACEMENT MUST NOT SILENTLY CHANGE AUTHORITY | E23 | held |
| META-L014 | META-014 MEMORY RESTRUCTURING MUST NOT SILENTLY CHANGE AUTHORITY | E23 | held |
| META-L020 | META-020 EMERGENT CAPABILITY MUST REMAIN GOVERNED | E23 | held |
| META-L024 | META-024 ROLLBACK RESTORES THE GOVERNED STATE, NOT REVOKED AUTHORITY | E23 | held |
| META-S-dim-authorization_integrity | governability dimension 'authorization_integrity' drops when its property is violated | E23 | held |
| META-S-dim-authority_boundedness | governability dimension 'authority_boundedness' drops when its property is violated | E23 | held |
| META-S-registry-revoked | registry state REVOKED has no self-loop and PRODUCTION only via CANARY | E23 | held |
| META-S-unknown-unknown_capability | the self-unknown engine surfaces unknown_capability as a first-class state | E23 | held |
| META-S-unknown-unknown_authority_path | the self-unknown engine surfaces unknown_authority_path as a first-class state | E23 | held |
| META-S-quorum-none | board signers [] authorize iff at least 2 of 3 | E23 | held |
| META-S-quorum-0 | board signers [0] authorize iff at least 2 of 3 | E23 | held |
| META-S-quorum-1 | board signers [1] authorize iff at least 2 of 3 | E23 | held |
| META-S-quorum-2 | board signers [2] authorize iff at least 2 of 3 | E23 | held |
| META-S-quorum-01 | board signers [0, 1] authorize iff at least 2 of 3 | E23 | held |
| META-S-quorum-02 | board signers [0, 2] authorize iff at least 2 of 3 | E23 | held |
| META-S-quorum-12 | board signers [1, 2] authorize iff at least 2 of 3 | E23 | held |
| META-S-quorum-012 | board signers [0, 1, 2] authorize iff at least 2 of 3 | E23 | held |
| META-S-sandbox-plan | improving the plan component does not lower plan capability | E23 | held |
| META-S-sandbox-retrieve | improving the retrieve component does not lower retrieve capability | E23 | held |
| META-S-sandbox-verify | improving the verify component does not lower verify capability | E23 | held |
| META-S-sandbox-reason | improving the reason component does not lower reason capability | E23 | held |
| META-S-cascade-model | losing 'model' never widens authority | E23 | held |
| META-S-cascade-context | losing 'context' never widens authority | E23 | held |
| META-S-cascade-memory | losing 'memory' never widens authority | E23 | held |
| META-S-cascade-retrieval | losing 'retrieval' never widens authority | E23 | held |
| META-S-cascade-reasoner | losing 'reasoner' never widens authority | E23 | held |
| META-S-cascade-planner | losing 'planner' never widens authority | E23 | held |
| META-S-cascade-simulator | losing 'simulator' never widens authority | E23 | held |
| META-S-cascade-critic | losing 'critic' never widens authority | E23 | held |
| META-S-cascade-verifier | losing 'verifier' never widens authority | E23 | held |
| META-S-cascade-decision | losing 'decision' never widens authority | E23 | held |
| META-S-cascade-authorization | losing 'authorization' never widens authority | E23 | held |
| META-S-cascade-action | losing 'action' never widens authority | E23 | held |
| META-S-cascade-audit | losing 'audit' never widens authority | E23 | held |
| META-S-cascade-evidence | losing 'evidence' never widens authority | E23 | held |
| META-S-cascade-rollback | losing 'rollback' never widens authority | E23 | held |
| META-S-self-model-authority | the self-model refuses and does not store an authority assertion | E23 | held |
| NET-I001 | discovery cannot create authority | E24 | held |
| NET-I002 | communication cannot create authority | E24 | held |
| NET-I003 | negotiation cannot create authority | E24 | held |
| NET-I004 | contract cannot create authority | E24 | held |
| NET-I005 | reputation cannot create authority | E24 | held |
| NET-I006 | payment cannot create authority | E24 | held |
| NET-I007 | coalition cannot create authority | E24 | held |
| NET-I008 | federation cannot create authority | E24 | held |
| NET-I009 | trust cannot create unlimited authority | E24 | held |
| NET-I010 | capability advertisement cannot create authority | E24 | held |
| NET-I011 | child authority ⊆ delegated authority | E24 | held |
| NET-I012 | cross-domain authority ⊆ local ∩ remote policy | E24 | held |
| NET-I013 | trust translation cannot silently increase authority | E24 | held |
| NET-I014 | protocol translation cannot silently increase authority | E24 | held |
| NET-I015 | identity translation cannot silently increase authority | E24 | held |
| NET-I016 | revoked identity cannot transact | E24 | held |
| NET-I017 | revoked capability cannot execute | E24 | held |
| NET-I018 | expired contract cannot authorize | E24 | held |
| NET-I019 | expired evidence cannot authorize | E24 | held |
| NET-I025 | rollback cannot resurrect revoked authority | E24 | held |
| NET-I026 | economic resources cannot mint authority | E24 | held |
| NET-I027 | reputation cannot mint authority | E24 | held |
| NET-I028 | arbitration cannot mint unlimited authority | E24 | held |
| NET-I032 | A2A consequential delegation reaches E8 | E24 | held |
| NET-I037 | revocation outage cannot expand authority | E24 | held |
| NET-I038 | identity outage cannot expand authority | E24 | held |
| NET-I039 | evidence outage cannot expand authority | E24 | held |
| NET-I040 | protocol downgrade cannot expand authority | E24 | held |
| NET-I042 | unknown identity remains unknown | E24 | held |
| NET-I043 | unknown capability remains unknown | E24 | held |
| NET-I050 | mixed trust states coexist (high identity, low behaviour, unknown security) | E24 | held |
| NET-I051 | hiring grants exactly the minimum authority | E24 | held |
| NET-I055 | a legitimate two-hop delegation chain narrows | E24 | held |
| NET-I058 | the MachineSystemBOM has all sections and no authority | E24 | held |
| NET-I059 | legitimate shared memory carries provenance and no authority | E24 | held |
| NET-I062 | no non-authority input is read by the authority functions | E24 | held |
| NET-I065 | a revoked or expired delegation is not live | E24 | held |
| NET-P-http-GET | http GET: an authorization always comes from an E8 commit | E24 | held |
| NET-P-http-POST | http POST: an authorization always comes from an E8 commit | E24 | held |
| NET-P-http-PUT | http PUT: an authorization always comes from an E8 commit | E24 | held |
| NET-P-http-DELETE | http DELETE: an authorization always comes from an E8 commit | E24 | held |
| NET-P-rest-GET | rest GET: an authorization always comes from an E8 commit | E24 | held |
| NET-P-rest-POST | rest POST: an authorization always comes from an E8 commit | E24 | held |
| NET-P-grpc-Query | grpc Query: an authorization always comes from an E8 commit | E24 | held |
| NET-P-grpc-Mutate | grpc Mutate: an authorization always comes from an E8 commit | E24 | held |
| NET-P-websocket-subscribe | websocket subscribe: an authorization always comes from an E8 commit | E24 | held |
| NET-P-websocket-publish | websocket publish: an authorization always comes from an E8 commit | E24 | held |
| NET-P-event_bus-emit | event_bus emit: an authorization always comes from an E8 commit | E24 | held |
| NET-P-message_queue-enqueue | message_queue enqueue: an authorization always comes from an E8 commit | E24 | held |
| NET-P-cli-cat | cli cat: an authorization always comes from an E8 commit | E24 | held |
| NET-P-cli-run | cli run: an authorization always comes from an E8 commit | E24 | held |
| NET-P-browser-navigate | browser navigate: an authorization always comes from an E8 commit | E24 | held |
| NET-P-browser-click:submit_payment | browser click:submit_payment: an authorization always comes from an E8 commit | E24 | held |
| NET-P-browser-click:submit_order | browser click:submit_order: an authorization always comes from an E8 commit | E24 | held |
| NET-P-browser-type | browser type: an authorization always comes from an E8 commit | E24 | held |
| NET-P-computer_use-screenshot | computer_use screenshot: an authorization always comes from an E8 commit | E24 | held |
| NET-P-computer_use-click:submit_order | computer_use click:submit_order: an authorization always comes from an E8 commit | E24 | held |
| NET-P-computer_use-click:submit_payment | computer_use click:submit_payment: an authorization always comes from an E8 commit | E24 | held |
| NET-P-computer_use-terminal:run | computer_use terminal:run: an authorization always comes from an E8 commit | E24 | held |
| NET-P-computer_use-file:write | computer_use file:write: an authorization always comes from an E8 commit | E24 | held |
| NET-P-local_ipc-call:read | local_ipc call:read: an authorization always comes from an E8 commit | E24 | held |
| NET-P-local_ipc-call:write | local_ipc call:write: an authorization always comes from an E8 commit | E24 | held |
| NET-P-cloud_api-Describe | cloud_api Describe: an authorization always comes from an E8 commit | E24 | held |
| NET-P-cloud_api-Update | cloud_api Update: an authorization always comes from an E8 commit | E24 | held |
| NET-P-cloud_api-Terminate | cloud_api Terminate: an authorization always comes from an E8 commit | E24 | held |
| NET-Q-revoked-terminal | REVOKED has no outgoing transition | E24 | held |
| NET-F-unknown-local | factor 'local' unknown makes authority empty | E24 | held |
| NET-F-narrows-local | factor 'local' narrows authority | E24 | held |
| NET-F-unknown-remote | factor 'remote' unknown makes authority empty | E24 | held |
| NET-F-narrows-remote | factor 'remote' narrows authority | E24 | held |
| NET-F-unknown-delegated | factor 'delegated' unknown makes authority empty | E24 | held |
| NET-F-narrows-delegated | factor 'delegated' narrows authority | E24 | held |
| NET-F-unknown-contract_scope | factor 'contract_scope' unknown makes authority empty | E24 | held |
| NET-F-narrows-contract_scope | factor 'contract_scope' narrows authority | E24 | held |
| NET-F-unknown-policy | factor 'policy' unknown makes authority empty | E24 | held |
| NET-F-narrows-policy | factor 'policy' narrows authority | E24 | held |
| NET-F-unknown-risk | factor 'risk' unknown makes authority empty | E24 | held |
| NET-F-narrows-risk | factor 'risk' narrows authority | E24 | held |
| NET-F-unknown-capability | factor 'capability' unknown makes authority empty | E24 | held |
| NET-F-narrows-capability | factor 'capability' narrows authority | E24 | held |
| NET-F-unknown-resource | factor 'resource' unknown makes authority empty | E24 | held |
| NET-F-narrows-resource | factor 'resource' narrows authority | E24 | held |
| NET-F-unknown-time | factor 'time' unknown makes authority empty | E24 | held |
| NET-F-narrows-time | factor 'time' narrows authority | E24 | held |
| NET-F-unknown-context | factor 'context' unknown makes authority empty | E24 | held |
| NET-F-narrows-context | factor 'context' narrows authority | E24 | held |
| NET-C-agent-a-delegate | agent-a/delegate is VERIFIED only while its evidence is fresh | E24 | held |
| NET-C-agent-b-delegate | agent-b/delegate is VERIFIED only while its evidence is fresh | E24 | held |
| NET-T-low-identity_trust | identity_trust UNKNOWN fails a low-consequence action | E24 | held |
| NET-T-medium-identity_trust | identity_trust UNKNOWN fails a medium-consequence action | E24 | held |
| NET-T-high-identity_trust | identity_trust UNKNOWN fails a high-consequence action | E24 | held |
| NET-O-identity-provider | identity-provider outage denies instead of trusting | E24 | held |
| NET-O-revocation-provider | revocation-provider outage denies instead of trusting | E24 | held |
| NET-L02 | NET-L02 TRUST IS NOT AUTHORITY | E24 | held |
| NET-L03 | NET-L03 AUTHORITY IS NOT AUTHORIZATION | E24 | held |
| NET-L04 | NET-L04 AUTHORIZATION IS NOT EXECUTION | E24 | held |
| NET-L07 | NET-L07 NEGOTIATION IS NOT AUTHORIZATION | E24 | held |
Other niches
Consensus & distributed systems · Attacks, threats & containment · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem