CAIN-42 CAIN Studio

CAIN-42 · Stop risky actions

CAIN Control

The rulebook: decides allow, hold for approval, or block for every action an agent proposes.

Last reviewed 2026-10-01

Live   Core platform · security

What it is

Authorization engine with policy evaluation and risk assessment.

Where it fits

Part of Stop risky actions: Make AI agents ask before they delete, pay, email or run anything dangerous. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.

Use it

Recorded status: PRODUCTION. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).

Live now

Checked from your browser when this page opened, not from a cached list.

Fire a real decision

Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.

For AI engineers

Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.

Python (zero dependencies)

pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=...   # free key: https://cainstudio.online/signup

import cainstudio

@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
    ...  # runs only if CAIN allows this call, with these arguments

try:
    transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
    print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
    print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
    print("CAIN unreachable: not run")   # fail-closed

See a real decision with no account

cainstudio try          # live pipeline, stage by stage
cainstudio try --list   # the other attack scenarios

MCP clients (Claude Code, Cursor)

claude mcp add --transport http cain https://cainstudio.online/mcp

More: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key

Tested guarantees in this area

Every rule in these niches has its own page with its recorded result.

Related

Full documentation

The complete reference, also at /docs/control.

CAIN Control Documentation#

Status: PRODUCTION#

CAIN Control is production-ready. It provides the authorization layer that answers WHAT an actor is allowed to do, UNDER WHAT CONDITIONS, and WHO CAN STOP IT.


What is CAIN Control?#

CAIN Control is the permission and control layer for CAIN Trust Fabric:

IDENTITY → CONTROL → POLICY → RISK → DECISION → ENFORCEMENT → ACTION → EVIDENCE

Core Capabilities#

Agent Controls#

Tool Controls#

Policy Management#

Kill Switch#


Architecture#

┌─────────────────────────────────────────────────────────────────┐
│                     CAIN Control                                  │
├─────────────────────────────────────────────────────────────────┤
│  Control Engine                                                  │
│  ├── Agent state management (active/paused/killed)              │
│  ├── Tool enable/disable                                        │
│  ├── Policy evaluation                                          │
│  ├── Kill switch                                                │
│  └── Rate limiting                                              │
│                                                                  │
│  Control API                                                    │
│  ├── /fabric/control/agents/*    - Agent controls              │
│  ├── /fabric/control/tools/*     - Tool controls                │
│  ├── /fabric/control/policies/* - Policy management            │
│  ├── /fabric/control/kill-switch - Emergency stop              │
│  └── /fabric/control/evaluate    - Control decisions           │
│                                                                  │
│  Integration                                                    │
│  └── CAIN Identity → CAIN Control → CAIN Enforcement           │
└─────────────────────────────────────────────────────────────────┘

API Reference#

Kill Switch#

# Check kill switch status
curl https://cainstudio.online/fabric/control/kill-switch \
  -H "X-API-Key: your-key"

# Activate kill switch
curl -X POST https://cainstudio.online/fabric/control/kill-switch/activate \
  -H "X-API-Key: your-key" \
  -H "Content-Type: application/json" \
  -d '{"reason": "security incident"}'

# Deactivate kill switch
curl -X POST https://cainstudio.online/fabric/control/kill-switch/deactivate \
  -H "X-API-Key: your-key"

Agent Controls#

# Pause an agent
curl -X POST https://cainstudio.online/fabric/control/agents/agent:xxx/pause \
  -H "X-API-Key: your-key" \
  -H "Content-Type: application/json" \
  -d '{"reason": "maintenance"}'

# Resume an agent
curl -X POST https://cainstudio.online/fabric/control/agents/agent:xxx/resume \
  -H "X-API-Key: your-key"

# Kill an agent (permanent)
curl -X POST https://cainstudio.online/fabric/control/agents/agent:xxx/kill \
  -H "X-API-Key: your-key" \
  -H "Content-Type: application/json" \
  -d '{"reason": "compromised"}'

# List agent controls
curl https://cainstudio.online/fabric/control/agents \
  -H "X-API-Key: your-key"

Tool Controls#

# Create tool control
curl -X POST https://cainstudio.online/fabric/control/tools/my-tool \
  -H "X-API-Key: your-key" \
  -H "Content-Type: application/json" \
  -d '{
    "risk_level": "high",
    "requires_approval": true,
    "allowed_agents": ["agent:xxx"],
    "allowed_identities": ["urn:cain:identity:agent:yyy"]
  }'

# Disable tool
curl -X POST https://cainstudio.online/fabric/control/tools/my-tool/disable \
  -H "X-API-Key: your-key" \
  -H "Content-Type: application/json" \
  -d '{"reason": "vulnerability found"}'

# Enable tool
curl -X POST https://cainstudio.online/fabric/control/tools/my-tool/enable \
  -H "X-API-Key: your-key"

Policies#

# Create policy
curl -X POST https://cainstudio.online/fabric/control/policies \
  -H "X-API-Key: your-key" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "high-risk-tool-policy",
    "description": "Restricts high-risk tool usage",
    "rules": [
      {"action": "tool:write", "risk_level": "high", "requires_approval": true}
    ]
  }'

# Activate policy
curl -X POST https://cainstudio.online/fabric/control/policies/pol:xxx/activate \
  -H "X-API-Key: your-key"

# Rollback policy
curl -X POST https://cainstudio.online/fabric/control/policies/pol:xxx/rollback?version=2 \
  -H "X-API-Key: your-key"

Control Evaluation#

# Evaluate (records decision)
curl -X POST https://cainstudio.online/fabric/control/evaluate \
  -H "X-API-Key: your-key" \
  -H "Content-Type: application/json" \
  -d '{
    "identity_id": "urn:cain:identity:agent:xxx",
    "agent_id": "agent:yyy",
    "action": "tool:read",
    "tool": "my-tool"
  }'

# Simulate (no recording, no execution)
curl -X POST https://cainstudio.online/fabric/control/simulate \
  -H "X-API-Key: your-key" \
  -H "Content-Type: application/json" \
  -d '{
    "identity_id": "urn:cain:identity:agent:xxx",
    "agent_id": "agent:yyy",
    "action": "tool:read",
    "tool": "my-tool"
  }'

Fail-Closed Behavior#

CAIN Control is fail-closed. The following ALWAYS result in DENY:

Only ALLOW permits execution.


Integration with CAIN Enforcement#

CAIN Control integrates with make_cain_decision in CAIN Private:

Request Action
    ↓
CAIN Identity (verify WHO)
    ↓
CAIN Control (verify WHAT allowed)
    ↓
CAIN Enforcement (ALLOW/DENY)
    ↓
Execute or Block
    ↓
Evidence

Security Properties#

PropertyImplementation
Fail-closedUnknown/error = DENY
Kill switchTenant-wide, immediate
Tenant isolationTenant from API key hash
Audit trailFull decision and action history
No bypassControl is enforcement gate

See Also#

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem