CAIN-42 CAIN Studio

Evidence library · niche

Identity, authority & delegation

Who an agent is, what it may do, and who allowed it. 964 tested invariants.

Last reviewed 2026-10-01

964 of 964 held

Where this niche's rules come from

Test families in this niche

capability (54) · handshake (54) · authorization_binding (49) · aip (48) · revocation (26) · credential (25) · domain (21) · service_passport (21) · non_authority (18) · binding (16) · lease_v2 (15) · protected_key (14) · research (13) · state_machine (11) · cross_domain (11) · delegation (11) · kernel (11) · delegation_attenuation (9) · replay_revocation (9) · moat (9) · risk (6) · failure_class (6) · root_of_trust (6) · telemetry (5) · action (5) · action_binding (4) · config_key (4) · knowledge_revocation (4) · primitive (4) · agency_graph (4) · relationship (4) · delegation_receipt (3) · reassessment (3) · capability_passport (3) · authority_graph (3) · integrity (3) · consistency (3) · soc (3) · lease (3) · operation_kind (3) · event_kind (3) · exhaustion_mode (3) · gap_detector (3) · profile (3) · graph (3) · approval (2) · offline (2) · registration (2) · scientist (2) · radar (2) · federation (1) · intent (1) · tenancy (1) · cross-domain (1) · passport (1) · stage (1) · operation_state (1) · status (1) · environment_query (1) · ip (1) · competitive_gap (1) · authority_algebra (1) · minimum_authority (1) · systemic (1)

Where these come from

Rules 751–900 of 964

IDRuleBundleResult
E32-PROT-tolerancestolerances is outside what learning may changeE32held
E32-SCI-authorizethe governance scientist may not authorizeE32held
E32-SCI-expand_authoritythe governance scientist may not expand_authorityE32held
E32-NONAUTH-consensusconsensus creates no authorityE32held
E32-NONAUTH-ensemble_agreementensemble_agreement creates no authorityE32held
E32-NONAUTH-world_model_agreementworld_model_agreement creates no authorityE32held
E32-NONAUTH-research_consensusresearch_consensus creates no authorityE32held
E32-NONAUTH-collective_votecollective_vote creates no authorityE32held
E32-NONAUTH-reputationreputation creates no authorityE32held
E32-NONAUTH-economic_valueeconomic_value creates no authorityE32held
E32-NONAUTH-historical_successhistorical_success creates no authorityE32held
E32-NONAUTH-rewardreward creates no authorityE32held
E32-NONAUTH-confidenceconfidence creates no authorityE32held
E32-KREV-predictioninvalidated evidence propagates to predictionE32held
E32-KREV-improvementinvalidated evidence propagates to improvementE32held
E32-KREV-policyinvalidated evidence propagates to policyE32held
E32-KREV-unrelated_untouchedinvalidated evidence propagates to unrelated_untouchedE32held
E33-STATE-AUTHORIZEno state can be skipped after AUTHORIZEE33held
E33-KIND-access_credentialaccess_credential is executed only through E8E33held
E33-KIND-delegate_capabilitydelegate_capability is executed only through E8E33held
E33-KIND-create_capabilitycreate_capability is routed to E29 AgentCapabilityMarketplace conformanceE33held
E33-EVENT-capability_requestcapability_request events chain and verifyE33held
E33-EVENT-authorization_requestauthorization_request events chain and verifyE33held
E33-EVENT-delegationdelegation events chain and verifyE33held
E33-EXHAUST-STOPexhaustion mode STOP never increases authorityE33held
E33-EXHAUST-REAUTHORIZEexhaustion mode REAUTHORIZE never increases authorityE33held
E33-EXHAUST-DEGRADED_MODEexhaustion mode DEGRADED_MODE never increases authorityE33held
E33-LEASE-identitya lease without identity is refusedE33held
E33-LEASE-scopea lease without scope is refusedE33held
E33-LEASE-capabilitiesa lease without capabilities is refusedE33held
E33-LEASE-authoritya lease without authority is refusedE33held
E33-LEASE-budgeta lease without budget is refusedE33held
E33-LEASE-not_aftera lease without not_after is refusedE33held
E33-LEASE-max_actionsa lease without max_actions is refusedE33held
E33-LEASE-risk_thresholda lease without risk_threshold is refusedE33held
E33-LEASE-trajectorya lease without trajectory is refusedE33held
E33-LEASE-economica lease without economic is refusedE33held
E33-LEASE-physicala lease without physical is refusedE33held
E33-LEASE-geographica lease without geographic is refusedE33held
E33-LEASE-delegationa lease without delegation is refusedE33held
E33-LEASE-model_runtimea lease without model_runtime is refusedE33held
E33-LEASE-evidence_requirementsa lease without evidence_requirements is refusedE33held
E33-MOAT-identity_continuityidentity_continuity is not claimed as an established market moatE33held
E33-HANDSHAKE-IDENTITYan unknown IDENTITY stops the handshakeE33held
E33-HANDSHAKE-CAPABILITYan unknown CAPABILITY stops the handshakeE33held
E33-HANDSHAKE-AUTHORITYan unknown AUTHORITY stops the handshakeE33held
E33-HANDSHAKE-POLICYan unknown POLICY stops the handshakeE33held
E33-HANDSHAKE-EVIDENCEan unknown EVIDENCE stops the handshakeE33held
E33-HANDSHAKE-ENFORCEMENTan unknown ENFORCEMENT stops the handshakeE33held
E33-HANDSHAKE-PROOFan unknown PROOF stops the handshakeE33held
E33-HANDSHAKE-REVOCATIONan unknown REVOCATION stops the handshakeE33held
E33-HANDSHAKE-RECOVERYan unknown RECOVERY stops the handshakeE33held
E33-GAP-authority_gapthe gap detector knows authority_gapE33held
E33-GAP-revocation_gapthe gap detector knows revocation_gapE33held
E33-GAP-identity_gapthe gap detector knows identity_gapE33held
E33-RESEARCH-R1research item R1 has provenance and no authorityE33held
E33-RESEARCH-R2research item R2 has provenance and no authorityE33held
E33-RESEARCH-R3research item R3 has provenance and no authorityE33held
E33-RESEARCH-R4research item R4 has provenance and no authorityE33held
E33-RESEARCH-R5research item R5 has provenance and no authorityE33held
E33-RESEARCH-R6research item R6 has provenance and no authorityE33held
E33-RESEARCH-R7research item R7 has provenance and no authorityE33held
E33-RESEARCH-R8research item R8 has provenance and no authorityE33held
E33-RESEARCH-R9research item R9 has provenance and no authorityE33held
E33-RESEARCH-R10research item R10 has provenance and no authorityE33held
E33-RESEARCH-R11research item R11 has provenance and no authorityE33held
E34-STATUS-REVOKEDREVOKED is a reachable proof status, never a scoreE34held
E34-PRIM-identitythe identity proof primitive exists and binds fieldsE34held
E34-PRIM-capabilitythe capability proof primitive exists and binds fieldsE34held
E34-PRIM-delegationthe delegation proof primitive exists and binds fieldsE34held
E34-PRIM-authoritythe authority proof primitive exists and binds fieldsE34held
E34-HANDSHAKE-IDENTITYhandshake step IDENTITY is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-CAPABILITYhandshake step CAPABILITY is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-DELEGATIONhandshake step DELEGATION is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-AUTHORITYhandshake step AUTHORITY is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-POLICYhandshake step POLICY is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-EVIDENCEhandshake step EVIDENCE is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-ENFORCEMENThandshake step ENFORCEMENT is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-PROOFhandshake step PROOF is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-REVOCATIONhandshake step REVOCATION is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-RECOVERYhandshake step RECOVERY is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-CONFORMANCEhandshake step CONFORMANCE is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-HANDSHAKE-ECONOMYhandshake step ECONOMY is required; unknown yields GOVERNANCE_UNKNOWNE34held
E34-MOAT-agent_identitymoat agent_identity is technical only, not a market moatE34held
E34-MOAT-identity_continuitymoat identity_continuity is technical only, not a market moatE34held
E34-MOAT-delegation_provenancemoat delegation_provenance is technical only, not a market moatE34held
E35-RISK-authorityrisk dimension authority is separateE35held
E35-RISK-capabilityrisk dimension capability is separateE35held
E35-RISK-delegationrisk dimension delegation is separateE35held
E35-QUERY-authority_chainsenvironment query authority_chains existsE35held
E35-PROFILE-revocabilityagentic profile dimension revocability existsE35held
E35-PROFILE-delegation_depthagentic profile dimension delegation_depth existsE35held
E35-PROFILE-capability_surfaceagentic profile dimension capability_surface existsE35held
E35-RADAR-agent_identityradar topic agent_identity existsE35held
E35-RADAR-agent_authorizationradar topic agent_authorization existsE35held
E35-IP-autonomy_leasesIP primitive autonomy_leases existsE35held
E35-MOAT-agent_identitymoat agent_identity is technical, not a market moatE35held
E35-MOAT-identity_continuitymoat identity_continuity is technical, not a market moatE35held
E35-MOAT-delegation_provenancemoat delegation_provenance is technical, not a market moatE35held
E35-INTEGRITY-identityintegrity monitor watches identityE35held
E35-INTEGRITY-authorityintegrity monitor watches authorityE35held
E35-ROOT-identityroot of trust identity existsE35held
E35-ROOT-policyroot of trust policy existsE35held
E35-ROOT-evidenceroot of trust evidence existsE35held
E35-ROOT-proofroot of trust proof existsE35held
E35-ROOT-verifierroot of trust verifier existsE35held
E35-ROOT-enforcementroot of trust enforcement existsE35held
E36-DOMAIN-SERVICE-IDENTITYsigned domain SERVICE-IDENTITY is definedE36held
E36-DOMAIN-SERVICE-PASSPORTsigned domain SERVICE-PASSPORT is definedE36held
E36-DOMAIN-CAPABILITYsigned domain CAPABILITY is definedE36held
E36-DOMAIN-PAYMENT-AUTHORIZATIONsigned domain PAYMENT-AUTHORIZATION is definedE36held
E36-DOMAIN-REVOCATIONsigned domain REVOCATION is definedE36held
E36-PASSPORT-service_ida passport without service_id is refusedE36held
E36-PASSPORT-owner_ida passport without owner_id is refusedE36held
E36-PASSPORT-operator_ida passport without operator_id is refusedE36held
E36-PASSPORT-agent_ida passport without agent_id is refusedE36held
E36-PASSPORT-model_ida passport without model_id is refusedE36held
E36-PASSPORT-runtime_ida passport without runtime_id is refusedE36held
E36-PASSPORT-capability_seta passport without capability_set is refusedE36held
E36-PASSPORT-governance_profilea passport without governance_profile is refusedE36held
E36-PASSPORT-conformance_profilea passport without conformance_profile is refusedE36held
E36-PASSPORT-proof_profilea passport without proof_profile is refusedE36held
E36-PASSPORT-service_versiona passport without service_version is refusedE36held
E36-PASSPORT-uptime_evidencea passport without uptime_evidence is refusedE36held
E36-PASSPORT-incident_historya passport without incident_history is refusedE36held
E36-PASSPORT-recovery_historya passport without recovery_history is refusedE36held
E36-PASSPORT-security_historya passport without security_history is refusedE36held
E36-PASSPORT-pricing_modela passport without pricing_model is refusedE36held
E36-PASSPORT-supported_protocolsa passport without supported_protocols is refusedE36held
E36-PASSPORT-authorization_modela passport without authorization_model is refusedE36held
E36-PASSPORT-revocation_endpointa passport without revocation_endpoint is refusedE36held
E36-PASSPORT-service_limitsa passport without service_limits is refusedE36held
E36-PASSPORT-unknown_surfacea passport without unknown_surface is refusedE36held
E36-TELEMETRY-authoritytelemetry metric authority existsE36held
E36-TELEMETRY-delegationtelemetry metric delegation existsE36held
E36-AGENCY-NODE-capabilityagency graph node capability existsE36held
E36-AGENCY-NODE-identityagency graph node identity existsE36held
E36-AGENCY-NODE-authorityagency graph node authority existsE36held
E36-AGENCY-EDGE-DELEGATESagency graph edge DELEGATES existsE36held
E36-REVOKE-compromised_identityrevocation trigger compromised_identity existsE36held
E36-REVOKE-proof_failurerevocation trigger proof_failure existsE36held
E36-REVOKE-policy_violationrevocation trigger policy_violation existsE36held
E36-REVOKE-contract_violationrevocation trigger contract_violation existsE36held
E36-REVOKE-supply_chain_compromiserevocation trigger supply_chain_compromise existsE36held
E36-REVOKE-malicious_behaviorrevocation trigger malicious_behavior existsE36held
E36-REVOKE-governance_driftrevocation trigger governance_drift existsE36held
E36-REVOKE-certificate_expirationrevocation trigger certificate_expiration existsE36held
E36-REVOKE-severe_reliability_degradationrevocation trigger severe_reliability_degradation existsE36held
E36-MOAT-machine_service_passportsmoat machine_service_passports is technical onlyE36held
E36-COMPETITOR-agent_identity_platformscompetitor category agent_identity_platforms makes no claimE36held

1 2 3 4 5 6 7

Other niches

Consensus & distributed systems · Attacks, threats & containment · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem