CAIN-42 CAIN Studio

Evidence library · niche

Identity, authority & delegation

Who an agent is, what it may do, and who allowed it. 964 tested invariants.

Last reviewed 2026-10-01

964 of 964 held

Where this niche's rules come from

Test families in this niche

capability (54) · handshake (54) · authorization_binding (49) · aip (48) · revocation (26) · credential (25) · domain (21) · service_passport (21) · non_authority (18) · binding (16) · lease_v2 (15) · protected_key (14) · research (13) · state_machine (11) · cross_domain (11) · delegation (11) · kernel (11) · delegation_attenuation (9) · replay_revocation (9) · moat (9) · risk (6) · failure_class (6) · root_of_trust (6) · telemetry (5) · action (5) · action_binding (4) · config_key (4) · knowledge_revocation (4) · primitive (4) · agency_graph (4) · relationship (4) · delegation_receipt (3) · reassessment (3) · capability_passport (3) · authority_graph (3) · integrity (3) · consistency (3) · soc (3) · lease (3) · operation_kind (3) · event_kind (3) · exhaustion_mode (3) · gap_detector (3) · profile (3) · graph (3) · approval (2) · offline (2) · registration (2) · scientist (2) · radar (2) · federation (1) · intent (1) · tenancy (1) · cross-domain (1) · passport (1) · stage (1) · operation_state (1) · status (1) · environment_query (1) · ip (1) · competitive_gap (1) · authority_algebra (1) · minimum_authority (1) · systemic (1)

Where these come from

Rules 601–750 of 964

IDRuleBundleResult
I-AIP-REQUESTmessage REQUESTE27held
I-AIP-DELEGATEmessage DELEGATEE27held
I-AIP-AUTHORIZEmessage AUTHORIZEE27held
I-AIP-EXECUTEmessage EXECUTEE27held
I-AIP-RECEIPTmessage RECEIPTE27held
I-AIP-REVOKEmessage REVOKEE27held
I-AIP-QUARANTINEmessage QUARANTINEE27held
I-AIP-RECOVERmessage RECOVERE27held
I-AIP-ADAPTER-a2aadapter a2a mappedE27held
I-AIP-ADAPTER-browseradapter browser mappedE27held
I-AIP-ADAPTER-cliadapter cli mappedE27held
I-AIP-ADAPTER-cloud_apiadapter cloud_api mappedE27held
I-AIP-ADAPTER-computer_useadapter computer_use mappedE27held
I-AIP-ADAPTER-containeradapter container mappedE27held
I-AIP-ADAPTER-databaseadapter database mappedE27held
I-AIP-ADAPTER-deploymentadapter deployment mappedE27held
I-AIP-ADAPTER-event_streamadapter event_stream mappedE27held
I-AIP-ADAPTER-filesystemadapter filesystem mappedE27held
I-AIP-ADAPTER-grpcadapter grpc mappedE27held
I-AIP-ADAPTER-httpadapter http mappedE27held
I-AIP-ADAPTER-jsonrpcadapter jsonrpc mappedE27held
I-AIP-ADAPTER-local_ipcadapter local_ipc mappedE27held
I-AIP-ADAPTER-mcpadapter mcp mappedE27held
I-AIP-ADAPTER-message_queueadapter message_queue mappedE27held
I-AIP-ADAPTER-shelladapter shell mappedE27held
I-AIP-ADAPTER-websocketadapter websocket mappedE27held
I-GOAL-delegation_distortiongoal signal delegation_distortionE27held
I-RESEARCH-LOOP-CAPABILITY_PROPOSALloop CAPABILITY_PROPOSALE27held
I-RESEARCH-not-rulehypothesis is not an authorization ruleE27held
I-RISK-authority_escalationforecast authority_escalationE27held
I-RISK-capability_driftforecast capability_driftE27held
I-RISK-delegation_explosionforecast delegation_explosionE27held
I-TELEM-authorizationtelemetry authorizationE27held
I-TELEM-delegationtelemetry delegationE27held
I-TELEM-credentialtelemetry credentialE27held
I-TENANT-isolationcross-tenant evidence isolatedE27held
I-CONSIST-identityconsistency identityE27held
I-CONSIST-authorityconsistency authorityE27held
I-CONSIST-revocationconsistency revocationE27held
I-SOC-authorization_failuresfeed authorization_failuresE27held
I-SOC-identity_failuresfeed identity_failuresE27held
I-SOC-revocationsfeed revocationsE27held
I-ADAPTER-AIP-a2aadapter a2a AIPE27held
I-ADAPTER-AIP-browseradapter browser AIPE27held
I-ADAPTER-AIP-cliadapter cli AIPE27held
I-ADAPTER-AIP-cloud_apiadapter cloud_api AIPE27held
I-ADAPTER-AIP-computer_useadapter computer_use AIPE27held
I-ADAPTER-AIP-containeradapter container AIPE27held
I-ADAPTER-AIP-databaseadapter database AIPE27held
I-ADAPTER-AIP-deploymentadapter deployment AIPE27held
I-ADAPTER-AIP-event_streamadapter event_stream AIPE27held
I-ADAPTER-AIP-filesystemadapter filesystem AIPE27held
I-ADAPTER-AIP-grpcadapter grpc AIPE27held
I-ADAPTER-AIP-httpadapter http AIPE27held
I-ADAPTER-AIP-jsonrpcadapter jsonrpc AIPE27held
I-ADAPTER-AIP-local_ipcadapter local_ipc AIPE27held
I-ADAPTER-AIP-mcpadapter mcp AIPE27held
I-ADAPTER-AIP-message_queueadapter message_queue AIPE27held
I-ADAPTER-AIP-shelladapter shell AIPE27held
I-ADAPTER-AIP-websocketadapter websocket AIPE27held
E28-I33a key already bound to an identity cannot register again (clone)E28held
E28-I35declaring an unregistered capability is refusedE28held
E28-I52an unknown delegation dimension is refusedE28held
E28-I53an omitted dimension is inherited, never widenedE28held
E28-I54a parent without downstream delegation cannot delegateE28held
E28-I55delegation beyond max depth is refusedE28held
E28-I56a child cannot outlive its parentE28held
E28-I57a tampered delegation token is detected in the chainE28held
E28-I58revoking a delegation revokes every descendant tokenE28held
E28-I59the execution count bound is enforcedE28held
E28-I60the economic budget bound is enforcedE28held
E28-I61a region outside the grant is refusedE28held
E28-I62risk that is not measured is refused, not assumed lowE28held
E28-I76local authority is requested AND federated AND local sponsor AND home ceilingE28held
E28-I79a revoked identity cannot renew its leaseE28held
E28-I80renewal re-signs against the current identity and policyE28held
E28-I81the lease action budget is enforcedE28held
E28-I88the passport is signed and every section carries an epistemic labelE28held
E29-S-AUTHORIZEa veto at AUTHORIZE aborts the transaction and no later stage runsE29held
E30-STATE-AUTHORIZEDonly the listed states reach AUTHORIZED, by the listed actorE30held
E30-STATE-REVOKEDonly the listed states reach REVOKED, by the listed actorE30held
E31-AF-identitychanging identity breaks the proof-carrying action bindingE31held
E31-AF-capabilitychanging capability breaks the proof-carrying action bindingE31held
E31-AF-delegationchanging delegation breaks the proof-carrying action bindingE31held
E31-AF-authoritychanging authority breaks the proof-carrying action bindingE31held
E31-FC-AUTHORIZATION_DENIEDfailure class AUTHORIZATION_DENIED is assigned only from matching evidenceE31held
E31-FC-AUTHORIZATION_EXPIREDfailure class AUTHORIZATION_EXPIRED is assigned only from matching evidenceE31held
E31-FC-AUTHORIZATION_REVOKEDfailure class AUTHORIZATION_REVOKED is assigned only from matching evidenceE31held
E31-FC-INSUFFICIENT_AUTHORITYfailure class INSUFFICIENT_AUTHORITY is assigned only from matching evidenceE31held
E31-FC-CAPABILITY_MISMATCHfailure class CAPABILITY_MISMATCH is assigned only from matching evidenceE31held
E31-FC-IDENTITY_FAILUREfailure class IDENTITY_FAILURE is assigned only from matching evidenceE31held
E31-HS-identity_capabilitiesidentity_capabilities: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-authentication_methodauthentication_method: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-authorization_capabilitiesauthorization_capabilities: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-delegation_modeldelegation_model: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-revocation_mechanismrevocation_mechanism: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-enforcement_boundaryenforcement_boundary: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-evidence_capabilitiesevidence_capabilities: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-proof_formatproof_format: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-policy_modelpolicy_model: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-protocol_bindingsprotocol_bindings: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-failure_behaviorfailure_behavior: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-fail_closedfail_closed: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-supported_guaranteessupported_guarantees: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-HS-unsupported_guaranteesunsupported_guarantees: a declaration alone never exceeds OBSERVED; probes decideE31held
E31-XD-readtranslating read never widens authority in domain BE31held
E31-XD-listtranslating list never widens authority in domain BE31held
E31-XD-querytranslating query never widens authority in domain BE31held
E31-XD-observetranslating observe never widens authority in domain BE31held
E31-XD-notifytranslating notify never widens authority in domain BE31held
E31-XD-writetranslating write never widens authority in domain BE31held
E31-XD-createtranslating create never widens authority in domain BE31held
E31-XD-sendtranslating send never widens authority in domain BE31held
E31-XD-submittranslating submit never widens authority in domain BE31held
E31-XD-executetranslating execute never widens authority in domain BE31held
E31-XD-configuretranslating configure never widens authority in domain BE31held
E31-RR-gate_replayreplay/revocation: gate_replay on every protocolE31held
E31-RR-identity_revokedreplay/revocation: identity_revoked on every protocolE31held
E31-RR-proof_revokedreplay/revocation: proof_revoked on every protocolE31held
E31-RR-expiredreplay/revocation: expired on every protocolE31held
E31-RR-supersededreplay/revocation: superseded on every protocolE31held
E31-RR-past_proof_future_actionreplay/revocation: past_proof_future_action on every protocolE31held
E31-RR-proof_for_other_actionreplay/revocation: proof_for_other_action on every protocolE31held
E31-RR-quarantinedreplay/revocation: quarantined on every protocolE31held
E31-RR-known_then_vs_nowreplay/revocation: known_then_vs_now on every protocolE31held
E31-AL-confidenceconfidence creates no authority on any protocolE31held
E31-AL-consensusconsensus creates no authority on any protocolE31held
E31-AL-reputationreputation creates no authority on any protocolE31held
E31-AL-predictionprediction creates no authority on any protocolE31held
E31-AL-simulationsimulation creates no authority on any protocolE31held
E31-AL-rewardreward creates no authority on any protocolE31held
E31-AL-prior_successprior_success creates no authority on any protocolE31held
E31-AL-governance_proofgovernance_proof creates no authority on any protocolE31held
E32-CFG-deny_prefixesadding a deny_prefixes restriction is never authority driftE32held
E32-CFG-secret_patternsadding a secret_patterns restriction is never authority driftE32held
E32-CFG-rate_limitadding a rate_limit restriction is never authority driftE32held
E32-CFG-world_model_gateadding a world_model_gate restriction is never authority driftE32held
E32-PROT-evaluatorevaluator is outside what learning may changeE32held
E32-PROT-hidden_evaluationhidden_evaluation is outside what learning may changeE32held
E32-PROT-verifierverifier is outside what learning may changeE32held
E32-PROT-rollbackrollback is outside what learning may changeE32held
E32-PROT-trust_roottrust_root is outside what learning may changeE32held
E32-PROT-evidenceevidence is outside what learning may changeE32held
E32-PROT-e8e8 is outside what learning may changeE32held
E32-PROT-sandbox_policysandbox_policy is outside what learning may changeE32held
E32-PROT-promotion_gatepromotion_gate is outside what learning may changeE32held
E32-PROT-authorityauthority is outside what learning may changeE32held
E32-PROT-self_reference_firewallself_reference_firewall is outside what learning may changeE32held
E32-PROT-meta_governancemeta_governance is outside what learning may changeE32held
E32-PROT-loop_policyloop_policy is outside what learning may changeE32held

1 2 3 4 5 6 7

Other niches

Consensus & distributed systems · Attacks, threats & containment · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem