Evidence library · niche
Core guarantees
Fail-closed basics that every other area relies on. 377 tested invariants.
Last reviewed 2026-10-01
377 of 377 held
Test families in this niche
action (32) · state_machine (17) · relationship (14) · operation_state (12) · integrity (11) · swe (10) · hardware (9) · cognitive (9) · plan_check_act (9) · r2e (8) · radar (8) · graph (8) · research (7) · telemetry (7) · research_to_implementation (7) · federation (6) · translation (6) · fabric_component (6) · tech_radar (5) · environment_query (5) · profile (5) · risk (4) · operation_kind (4) · trajectory (4) · agency_graph (4) · environment (4) · intent (3) · moat (3) · swarm (3) · match (3) · competitive_gap (3) · f2t (3) · replay (2) · offline (2) · reassessment (2) · cross_domain (2) · failure_to_test (2) · composition (2) · soc (1) · developer (1) · gap_detector (1) · status (1) · conflict (1) · engine_mesh (1) · perimeter (1) · recursion (1) · scheduler (1) · architecture (1) · evaluation (1) · health (1) · systemic (1)
Where these come from
- CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric: 54
- CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform: 40
- CAIN-42 Evolution 27 -- Agentic Internet Control Plane: 36
- CAIN-42 Evolution 21 -- Governed Open-Ended Intelligence Fabric: 35
- CAIN-42 Evolution 33 -- Governed Agentic Operating Fabric: 29
- CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric: 26
- CAIN-42 Evolution 20 -- Governed Agentic Civilization Fabric: 24
- CAIN-42 Evolution 23 -- Governed Meta-Intelligence Fabric: 24
- CAIN-42 Evolution 19 -- Governed Autonomy Operating Fabric: 21
- CAIN-42 Evolution 36 -- Machine Agency Exchange Fabric: 20
- CAIN-42 Evolution 41 -- Machine Agency Exchange Fabric: 18
- CAIN-42 Evolution 25 -- Universal Machine Agency Fabric: 14
- CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric: 9
- CAIN-42 Evolution 30 -- Governed Machine Autonomy Fabric: 7
- CAIN-42 Evolution 32 -- Governed Autonomy Learning Fabric: 7
- CAIN-42 Evolution 37 -- Autonomous Execution Mesh: 5
- CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency: 4
- CAIN-42 Evolution 39 -- Governed Agent Factory: 4
Rules 1–150 of 377
| ID | Rule | Bundle | Result |
|---|---|---|---|
| G24 | execution cannot imply success | E19 | held |
| G25 | outcome must be independently observed | E19 | held |
| G36 | every consequential action reaches E8 | E19 | held |
| G38 | every action has current state binding | E19 | held |
| G43 | uncertainty cannot silently become certainty | E19 | held |
| G44 | unknown cannot silently become allow | E19 | held |
| G45 | stale confidence cannot remain authoritative | E19 | held |
| G58 | goal termination invalidates dependent actions | E19 | held |
| G65 | security failure fails closed | E19 | held |
| G66 | sequential execution remains possible | E19 | held |
| G68 | legitimate adaptation remains possible | E19 | held |
| G74 | local tests do not equal multi-host verification | E19 | held |
| G75 | internal verification does not equal third-party verification | E19 | held |
| G77 | UNKNOWN remains UNKNOWN | E19 | held |
| G78 | UNVERIFIED remains UNVERIFIED | E19 | held |
| G80 | CLAIMED remains CLAIMED | E19 | held |
| G82 | no hidden execution path | E19 | held |
| G93 | state transition is deterministic where specified | E19 | held |
| G100 | security correctness takes precedence over green tests | E19 | held |
| G103 | an adaptation's risk is bounded | E19 | held |
| G107 | a human-supervised system is capped at SUPERVISED | E19 | held |
| I27 | dissolved institutions cannot execute | E20 | held |
| I36 | institutional goals inherit constraints | E20 | held |
| I38 | child agents inherit bounded constraints | E20 | held |
| I41 | collusion detection is not certainty | E20 | held |
| I47 | institutional state is auditable | E20 | held |
| I51 | UNKNOWN never silently becomes ALLOW | E20 | held |
| I54 | every consequential institutional action reaches E8 | E20 | held |
| I55 | a token never skips an E20 verdict | E20 | held |
| I56 | verdicts re-run after token issuance (TOCTOU) | E20 | held |
| I57 | E19 invalidation applies to institutional actions | E20 | held |
| I58 | institutional powers are not E8 operations | E20 | held |
| I60 | legitimate sequential action is not replay | E20 | held |
| I71 | resources are conserved through every flow | E20 | held |
| I75 | termination is a governed cascade | E20 | held |
| I78 | each inheritance dimension is independently bounded | E20 | held |
| I84 | circular validation is detected | E20 | held |
| I85 | absence of a collusion signal is UNKNOWN | E20 | held |
| I90 | a resolver is never a party | E20 | held |
| I91 | the audit reconstructs the institution | E20 | held |
| I103 | append-only audit cannot be removed | E20 | held |
| I107 | competition grants nothing | E20 | held |
| I113 | local tests do not equal multi-host verification | E20 | held |
| I114 | internal verification does not equal third-party verification | E20 | held |
| I118 | the end-to-end scenario is deterministic | E20 | held |
| D11 | unsupported claims remain unsupported | E21 | held |
| D13 | failed experiments remain auditable | E21 | held |
| D18 | hypothetical remains hypothetical | E21 | held |
| D52 | unknown does not become allow | E21 | held |
| D61 | no experiment bypasses E8 | E21 | held |
| D64 | no research institution bypasses E8 | E21 | held |
| D70 | clean-room verification remains independent | E21 | held |
| D73 | unverified claims remain unverified | E21 | held |
| D74 | unknown claims remain unknown | E21 | held |
| D75 | third-party verification is never implied without third-party verification | E21 | held |
| D77 | legitimate experimentation remains possible | E21 | held |
| D78 | legitimate scientific disagreement remains possible | E21 | held |
| D80 | legitimate hypothesis diversity remains possible | E21 | held |
| D84 | execution does not become success automatically | E21 | held |
| D85 | success does not retroactively validate every assumption | E21 | held |
| D96 | research state is replayable | E21 | held |
| D97 | research state is auditable | E21 | held |
| D99 | research state is independently verifiable | E21 | held |
| D103 | a claimed basis never changes an execution decision | E21 | held |
| D106 | every E21 action reaches E8 through E20 and E19 | E21 | held |
| D107 | a token never skips an E21 verdict | E21 | held |
| D108 | E21 verdicts re-checked after token issue | E21 | held |
| D109 | E8 tokens are single-use through E21 | E21 | held |
| D117 | reviewers are independent of researchers | E21 | held |
| D119 | two independent reviews are required | E21 | held |
| D125 | competing tracks have distinct controllers | E21 | held |
| D126 | commit-reveal prevents copied answers | E21 | held |
| D129 | correlation is never labelled causation | E21 | held |
| D133 | experiments inherit institutional constraints | E21 | held |
| D141 | strategy stages cannot be skipped | E21 | held |
| D145 | research bounties move no real money | E21 | held |
| D146 | bounties pay only for supported discoveries | E21 | held |
| D150 | public E21 text avoids forbidden claims | E21 | held |
| D151 | E21 is COMPLETE only when every gate holds | E21 | held |
| D152 | search depth, branching and nodes are bounded | E21 | held |
| META-I046 | common-mode failures remain visible | E23 | held |
| META-I047 | architectural diversity does not imply independence | E23 | held |
| META-I049 | provider diversity does not imply independence | E23 | held |
| META-I050 | process diversity does not imply independence | E23 | held |
| META-I053 | governed search rejects more-capable-but-less-governable candidates | E23 | held |
| META-I055 | the reference architecture has zero unknowns | E23 | held |
| META-I061 | every generation records the ten required fields | E23 | held |
| META-I065 | the E23 execution decision is bound to a recorded E19 decision | E23 | held |
| META-I067 | benign changes have a bounded blast radius | E23 | held |
| META-P002 | every compiled candidate binds ACTION to E8 (all depth-2 candidates) | E23 | held |
| META-P004 | every compiled candidate keeps at least one verifier (all depth-2 candidates) | E23 | held |
| META-P005 | every compiled candidate's capabilities are inside the ceiling (all depth-2 candidates) | E23 | held |
| META-P006 | every compiled candidate has bounded network access (all depth-2 candidates) | E23 | held |
| META-P008 | every compiled candidate has bounded persistence (all depth-2 candidates) | E23 | held |
| META-P009 | every compiled candidate has bounded subagents (all depth-2 candidates) | E23 | held |
| META-P014 | the sandbox is deterministic for every candidate (all depth-2 candidates) | E23 | held |
| META-P018 | compiled capabilities are always ceiling ∩ declared (all depth-2 candidates) | E23 | held |
| META-P019 | the architecture digest changes whenever a component changes (all depth-2 candidates) | E23 | held |
| META-S-self-what-i-know | an assertion answering 'WHAT I KNOW' lands in exactly that answer | E23 | held |
| META-S-self-what-i-think-i-know | an assertion answering 'WHAT I THINK I KNOW' lands in exactly that answer | E23 | held |
| META-S-self-what-i-observed | an assertion answering 'WHAT I OBSERVED' lands in exactly that answer | E23 | held |
| META-S-self-what-i-inferred | an assertion answering 'WHAT I INFERRED' lands in exactly that answer | E23 | held |
| META-S-self-what-i-do-not-know | an assertion answering 'WHAT I DO NOT KNOW' lands in exactly that answer | E23 | held |
| META-S-mode-read_only | mode READ_ONLY removes consequential capabilities | E23 | held |
| NET-I045 | unknown execution state remains unknown | E24 | held |
| NET-I054 | a legitimately re-attested agent is restored with its history intact | E24 | held |
| NET-I057 | VERIFIED is not translated as HIGH | E24 | held |
| NET-S-plugin-rollback | a rolled-back plugin is refused | E24 | held |
| NET-S-skill-rollback | a rolled-back skill is refused | E24 | held |
| NET-S-prompt-rollback | a rolled-back prompt is refused | E24 | held |
| NET-S-code-rollback | a rolled-back code is refused | E24 | held |
| NET-S-agent-rollback | a rolled-back agent is refused | E24 | held |
| NET-L05 | NET-L05 EXECUTION IS NOT SUCCESS | E24 | held |
| I-TX-IDENTIFIED | CREATED->IDENTIFIED | E25 | held |
| I-TX-INTENT_RECEIVED | CREATED->INTENT_RECEIVED refused | E25 | held |
| I-TX-RISK_EVALUATED | CREATED->RISK_EVALUATED refused | E25 | held |
| I-TX-EXECUTION_PREPARED | CREATED->EXECUTION_PREPARED refused | E25 | held |
| I-TX-EXECUTING | CREATED->EXECUTING refused | E25 | held |
| I-TX-EXECUTED | CREATED->EXECUTED refused | E25 | held |
| I-TX-OUTCOME_RECORDED | CREATED->OUTCOME_RECORDED refused | E25 | held |
| I-TX-ABORTED | CREATED->ABORTED | E25 | held |
| I-TX-ROLLED_BACK | CREATED->ROLLED_BACK refused | E25 | held |
| I-TX-EXPIRED | CREATED->EXPIRED | E25 | held |
| I-TX-SUPERSEDED | CREATED->SUPERSEDED refused | E25 | held |
| I-REPLAY-nonce | same nonce refused | E25 | held |
| I-REPLAY-seq | lower sequence refused | E25 | held |
| I-RISK-escalate | risk above threshold escalates | E25 | held |
| I-HW-TPM-unknown | TPM without verifier is UNKNOWN | E26 | held |
| I-HW-TEE-unknown | TEE without verifier is UNKNOWN | E26 | held |
| I-HW-CONFIDENTIAL_VM-unknown | CONFIDENTIAL_VM without verifier is UNKNOWN | E26 | held |
| I-HW-PLATFORM-unknown | PLATFORM without verifier is UNKNOWN | E26 | held |
| I-HW-GPU-unknown | GPU without verifier is UNKNOWN | E26 | held |
| I-HW-DPU-unknown | DPU without verifier is UNKNOWN | E26 | held |
| I-HW-SMARTNIC-unknown | SMARTNIC without verifier is UNKNOWN | E26 | held |
| I-HW-CLOUD_PROVIDER-unknown | CLOUD_PROVIDER without verifier is UNKNOWN | E26 | held |
| I-HW-TPM-failed | TPM bad quote fails | E26 | held |
| I-FED-same | same domain refused | E26 | held |
| I-FED-wildcard | wildcard refused | E26 | held |
| I-FED-read | federated read | E26 | held |
| I-FED-write | federated write | E26 | held |
| I-FED-expiry | expired federation refused | E26 | held |
| I-TRANS-spiffe-cain | spiffe->cain | E26 | held |
| I-TRANS-cain-authzen | cain->authzen | E26 | held |
| I-TRANS-cain-a2a | cain->a2a | E26 | held |
| I-TRANS-x509-cain | x509->cain | E26 | held |
| I-TRANS-jwt-cain | jwt->cain | E26 | held |
| I-OFFLINE-audience | wrong audience refused | E26 | held |
| I-OFFLINE-expired | expired refused | E26 | held |
| I-REASSESS-environment_change | trigger environment_change | E26 | held |
| I-REASSESS-security_event | trigger security_event | E26 | held |
Other niches
Consensus & distributed systems · Attacks, threats & containment · Identity, authority & delegation · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem