CAIN-42 CAIN Studio

Evidence library · niche

Core guarantees

Fail-closed basics that every other area relies on. 377 tested invariants.

Last reviewed 2026-10-01

377 of 377 held

Where this niche's rules come from

Test families in this niche

action (32) · state_machine (17) · relationship (14) · operation_state (12) · integrity (11) · swe (10) · hardware (9) · cognitive (9) · plan_check_act (9) · r2e (8) · radar (8) · graph (8) · research (7) · telemetry (7) · research_to_implementation (7) · federation (6) · translation (6) · fabric_component (6) · tech_radar (5) · environment_query (5) · profile (5) · risk (4) · operation_kind (4) · trajectory (4) · agency_graph (4) · environment (4) · intent (3) · moat (3) · swarm (3) · match (3) · competitive_gap (3) · f2t (3) · replay (2) · offline (2) · reassessment (2) · cross_domain (2) · failure_to_test (2) · composition (2) · soc (1) · developer (1) · gap_detector (1) · status (1) · conflict (1) · engine_mesh (1) · perimeter (1) · recursion (1) · scheduler (1) · architecture (1) · evaluation (1) · health (1) · systemic (1)

Where these come from

Rules 1–150 of 377

IDRuleBundleResult
G24execution cannot imply successE19held
G25outcome must be independently observedE19held
G36every consequential action reaches E8E19held
G38every action has current state bindingE19held
G43uncertainty cannot silently become certaintyE19held
G44unknown cannot silently become allowE19held
G45stale confidence cannot remain authoritativeE19held
G58goal termination invalidates dependent actionsE19held
G65security failure fails closedE19held
G66sequential execution remains possibleE19held
G68legitimate adaptation remains possibleE19held
G74local tests do not equal multi-host verificationE19held
G75internal verification does not equal third-party verificationE19held
G77UNKNOWN remains UNKNOWNE19held
G78UNVERIFIED remains UNVERIFIEDE19held
G80CLAIMED remains CLAIMEDE19held
G82no hidden execution pathE19held
G93state transition is deterministic where specifiedE19held
G100security correctness takes precedence over green testsE19held
G103an adaptation's risk is boundedE19held
G107a human-supervised system is capped at SUPERVISEDE19held
I27dissolved institutions cannot executeE20held
I36institutional goals inherit constraintsE20held
I38child agents inherit bounded constraintsE20held
I41collusion detection is not certaintyE20held
I47institutional state is auditableE20held
I51UNKNOWN never silently becomes ALLOWE20held
I54every consequential institutional action reaches E8E20held
I55a token never skips an E20 verdictE20held
I56verdicts re-run after token issuance (TOCTOU)E20held
I57E19 invalidation applies to institutional actionsE20held
I58institutional powers are not E8 operationsE20held
I60legitimate sequential action is not replayE20held
I71resources are conserved through every flowE20held
I75termination is a governed cascadeE20held
I78each inheritance dimension is independently boundedE20held
I84circular validation is detectedE20held
I85absence of a collusion signal is UNKNOWNE20held
I90a resolver is never a partyE20held
I91the audit reconstructs the institutionE20held
I103append-only audit cannot be removedE20held
I107competition grants nothingE20held
I113local tests do not equal multi-host verificationE20held
I114internal verification does not equal third-party verificationE20held
I118the end-to-end scenario is deterministicE20held
D11unsupported claims remain unsupportedE21held
D13failed experiments remain auditableE21held
D18hypothetical remains hypotheticalE21held
D52unknown does not become allowE21held
D61no experiment bypasses E8E21held
D64no research institution bypasses E8E21held
D70clean-room verification remains independentE21held
D73unverified claims remain unverifiedE21held
D74unknown claims remain unknownE21held
D75third-party verification is never implied without third-party verificationE21held
D77legitimate experimentation remains possibleE21held
D78legitimate scientific disagreement remains possibleE21held
D80legitimate hypothesis diversity remains possibleE21held
D84execution does not become success automaticallyE21held
D85success does not retroactively validate every assumptionE21held
D96research state is replayableE21held
D97research state is auditableE21held
D99research state is independently verifiableE21held
D103a claimed basis never changes an execution decisionE21held
D106every E21 action reaches E8 through E20 and E19E21held
D107a token never skips an E21 verdictE21held
D108E21 verdicts re-checked after token issueE21held
D109E8 tokens are single-use through E21E21held
D117reviewers are independent of researchersE21held
D119two independent reviews are requiredE21held
D125competing tracks have distinct controllersE21held
D126commit-reveal prevents copied answersE21held
D129correlation is never labelled causationE21held
D133experiments inherit institutional constraintsE21held
D141strategy stages cannot be skippedE21held
D145research bounties move no real moneyE21held
D146bounties pay only for supported discoveriesE21held
D150public E21 text avoids forbidden claimsE21held
D151E21 is COMPLETE only when every gate holdsE21held
D152search depth, branching and nodes are boundedE21held
META-I046common-mode failures remain visibleE23held
META-I047architectural diversity does not imply independenceE23held
META-I049provider diversity does not imply independenceE23held
META-I050process diversity does not imply independenceE23held
META-I053governed search rejects more-capable-but-less-governable candidatesE23held
META-I055the reference architecture has zero unknownsE23held
META-I061every generation records the ten required fieldsE23held
META-I065the E23 execution decision is bound to a recorded E19 decisionE23held
META-I067benign changes have a bounded blast radiusE23held
META-P002every compiled candidate binds ACTION to E8 (all depth-2 candidates)E23held
META-P004every compiled candidate keeps at least one verifier (all depth-2 candidates)E23held
META-P005every compiled candidate's capabilities are inside the ceiling (all depth-2 candidates)E23held
META-P006every compiled candidate has bounded network access (all depth-2 candidates)E23held
META-P008every compiled candidate has bounded persistence (all depth-2 candidates)E23held
META-P009every compiled candidate has bounded subagents (all depth-2 candidates)E23held
META-P014the sandbox is deterministic for every candidate (all depth-2 candidates)E23held
META-P018compiled capabilities are always ceiling ∩ declared (all depth-2 candidates)E23held
META-P019the architecture digest changes whenever a component changes (all depth-2 candidates)E23held
META-S-self-what-i-knowan assertion answering 'WHAT I KNOW' lands in exactly that answerE23held
META-S-self-what-i-think-i-knowan assertion answering 'WHAT I THINK I KNOW' lands in exactly that answerE23held
META-S-self-what-i-observedan assertion answering 'WHAT I OBSERVED' lands in exactly that answerE23held
META-S-self-what-i-inferredan assertion answering 'WHAT I INFERRED' lands in exactly that answerE23held
META-S-self-what-i-do-not-knowan assertion answering 'WHAT I DO NOT KNOW' lands in exactly that answerE23held
META-S-mode-read_onlymode READ_ONLY removes consequential capabilitiesE23held
NET-I045unknown execution state remains unknownE24held
NET-I054a legitimately re-attested agent is restored with its history intactE24held
NET-I057VERIFIED is not translated as HIGHE24held
NET-S-plugin-rollbacka rolled-back plugin is refusedE24held
NET-S-skill-rollbacka rolled-back skill is refusedE24held
NET-S-prompt-rollbacka rolled-back prompt is refusedE24held
NET-S-code-rollbacka rolled-back code is refusedE24held
NET-S-agent-rollbacka rolled-back agent is refusedE24held
NET-L05NET-L05 EXECUTION IS NOT SUCCESSE24held
I-TX-IDENTIFIEDCREATED->IDENTIFIEDE25held
I-TX-INTENT_RECEIVEDCREATED->INTENT_RECEIVED refusedE25held
I-TX-RISK_EVALUATEDCREATED->RISK_EVALUATED refusedE25held
I-TX-EXECUTION_PREPAREDCREATED->EXECUTION_PREPARED refusedE25held
I-TX-EXECUTINGCREATED->EXECUTING refusedE25held
I-TX-EXECUTEDCREATED->EXECUTED refusedE25held
I-TX-OUTCOME_RECORDEDCREATED->OUTCOME_RECORDED refusedE25held
I-TX-ABORTEDCREATED->ABORTEDE25held
I-TX-ROLLED_BACKCREATED->ROLLED_BACK refusedE25held
I-TX-EXPIREDCREATED->EXPIREDE25held
I-TX-SUPERSEDEDCREATED->SUPERSEDED refusedE25held
I-REPLAY-noncesame nonce refusedE25held
I-REPLAY-seqlower sequence refusedE25held
I-RISK-escalaterisk above threshold escalatesE25held
I-HW-TPM-unknownTPM without verifier is UNKNOWNE26held
I-HW-TEE-unknownTEE without verifier is UNKNOWNE26held
I-HW-CONFIDENTIAL_VM-unknownCONFIDENTIAL_VM without verifier is UNKNOWNE26held
I-HW-PLATFORM-unknownPLATFORM without verifier is UNKNOWNE26held
I-HW-GPU-unknownGPU without verifier is UNKNOWNE26held
I-HW-DPU-unknownDPU without verifier is UNKNOWNE26held
I-HW-SMARTNIC-unknownSMARTNIC without verifier is UNKNOWNE26held
I-HW-CLOUD_PROVIDER-unknownCLOUD_PROVIDER without verifier is UNKNOWNE26held
I-HW-TPM-failedTPM bad quote failsE26held
I-FED-samesame domain refusedE26held
I-FED-wildcardwildcard refusedE26held
I-FED-readfederated readE26held
I-FED-writefederated writeE26held
I-FED-expiryexpired federation refusedE26held
I-TRANS-spiffe-cainspiffe->cainE26held
I-TRANS-cain-authzencain->authzenE26held
I-TRANS-cain-a2acain->a2aE26held
I-TRANS-x509-cainx509->cainE26held
I-TRANS-jwt-cainjwt->cainE26held
I-OFFLINE-audiencewrong audience refusedE26held
I-OFFLINE-expiredexpired refusedE26held
I-REASSESS-environment_changetrigger environment_changeE26held
I-REASSESS-security_eventtrigger security_eventE26held

1 2 3

Other niches

Consensus & distributed systems · Attacks, threats & containment · Identity, authority & delegation · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem