{"scenarios":[{"id":"safe-read","title":"A reasonable action","explains":"A normal tool call with a declared intent, from a principal with no trust history yet. Policy and risk both pass, but unknown trust never becomes ALLOW on its own: the action is held for human approval.","expect":"REQUIRE_APPROVAL"},{"id":"prompt-injection","title":"A prompt-injection payload","explains":"The same call, carrying text that tries to override the agent's instructions. The RISK stage screens the payload and denies it.","expect":"denied by risk"},{"id":"malformed-plan","title":"A plan that cannot be reasoned about","explains":"A plan whose steps name no tool. VERIFICATION catches it before ActionProof is asked to prove anything about it -- a malformed plan returning 'nothing to prove' would read as a pass.","expect":"denied by verification"},{"id":"mission-inside","title":"An agent acting inside its signed mission (E38)","explains":"The call declares an owner-signed mission and the goal chain OBJECTIVE -> SUBGOAL -> PLAN -> ACTION that leads to it. The MISSION stage checks the signature and that every step attenuates its parent; this read stays inside the mission, so MISSION allows it (other stages still decide).","expect":"mission: allow"},{"id":"mission-escalation","title":"An agent trying to exceed its mission (E38)","explains":"Same signed mission (read inventory, low risk). The agent asks to WRITE inventory and cites a predicted reward of 1,000,000 and 99% confidence. Optimization cannot create authority: the MISSION stage refuses the call and the decision is BLOCKED.","expect":"BLOCKED by mission"},{"id":"horizon-inside","title":"An action inside an uncertainty-contracted horizon (E7)","explains":"A $5,000 write under a policy allowing 10 steps and $20,000 before re-authorization. CAIN has never seen this tool's outcomes, so uncertainty is 0.5 and the horizon contracts to 5 steps and $10,000. This write fits, so CONSEQUENCE allows it (other stages still decide).","expect":"consequence: allow"},{"id":"horizon-exhausted","title":"An action outside the contracted horizon (E7)","explains":"Same policy, a $15,000 write: inside the nominal $20,000 budget, but outside the $10,000 the horizon contracts to under uncertainty 0.5. Uncertainty contracts authority, never expands it: CONSEQUENCE refuses the call and requires re-authorization.","expect":"BLOCKED by consequence"},{"id":"e42-governed-tool","title":"E42 unified out-of-process tool execution boundary","explains":"Executes an out-of-process tool through the full 16-stage E42 pipeline: CAIO integrity, MGO mission attenuation, counterfactual plan comparison, 4-replica verification quorum QC, proof invalidation graph, atomic commit, and pinned-key MCPGate capability token.","expect":"ALLOW / EXECUTED"}],"how":"POST /fabric/try?scenario=<id>  -- no account, no key, no signup","what_you_get":"the real eleven-stage Trust Decision, the evidence record id, and a URL that verifies that record's integrity","honest_note":"This runs the actual decision path against a throwaway tenant. It is not a mock. It is also not your traffic: to protect a real agent, install the CLI and run `cain init`."}