CAIN-42 CAIN Studio

CAIN-42 · See what your agents do

CAIN Drift

Warns you when an agent, model, tool or policy quietly changes.

Last reviewed 2026-10-01

Live   Core platform · infrastructure

What it is

Detect meaningful changes in agents, models, tools, policies, data, behavior, and compliance state before drift becomes an incident.

Where it fits

Part of See what your agents do: Every action, every decision, replayed and searchable. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.

Use it

Recorded status: LIVE. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).

Live now

Checked from your browser when this page opened, not from a cached list.

Fire a real decision

Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.

For AI engineers

Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.

Python (zero dependencies)

pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=...   # free key: https://cainstudio.online/signup

import cainstudio

@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
    ...  # runs only if CAIN allows this call, with these arguments

try:
    transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
    print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
    print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
    print("CAIN unreachable: not run")   # fail-closed

See a real decision with no account

cainstudio try          # live pipeline, stage by stage
cainstudio try --list   # the other attack scenarios

MCP clients (Claude Code, Cursor)

claude mcp add --transport http cain https://cainstudio.online/mcp

More: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key

Tested guarantees in this area

Every rule in these niches has its own page with its recorded result.

Related

Full documentation

The complete reference, also at /docs/drift.

CAIN Drift#

Status: PARTIAL - Baselines, observations, comparisons, findings, evidence, and lifecycle management are operational. CLI and MCP integration pending.

Overview#

CAIN Drift detects meaningful changes in autonomous AI systems before drift becomes an incident. It is part of CAIN Trust Fabric and integrates with existing CAIN infrastructure.

Architecture#

BASELINE → OBSERVE → COMPARE → DETECT → CLASSIFY → CORRELATE → EVIDENCE → IMPACT → GOVERN → REMEDIATE → VERIFY

Key Principle: Drift detects. Governance decides. Enforcement enforces. Evidence records.

Drift Classes#

ClassDescriptionDetects
data_driftStatistical changes in data distributionsPSI, JS divergence, KS test, mean/variance shift
model_driftChanges in AI model configurationProvider, version, temperature, system prompt, tools
tool_driftChanges in tool/MCP configurationsSchema, permissions, endpoint, version, capabilities
policy_driftChanges in authorization policiesRules, risk thresholds, approval requirements
agent_behavior_driftChanges in agent behavior patternsAction frequency, tool selection, denial rate
security_driftChanges in security postureAttack surface, credentials, suspicious activity
compliance_driftChanges in compliance postureCompliance score, open findings
configuration_driftChanges in system configurationConfig changes
trajectory_driftChanges in execution trajectoriesTrajectory patterns
evidence_driftChanges in evidence patternsEvidence volume, types, integrity

API Endpoints#

Health & Status#

GET /fabric/drift/health     - Service health check
GET /fabric/drift/status     - Service status
GET /fabric/drift/stats      - Drift statistics

Baselines#

POST /fabric/drift/baselines           - Create baseline
GET  /fabric/drift/baselines           - List baselines
GET  /fabric/drift/baselines/{id}    - Get baseline
POST /fabric/drift/baselines/{id}/activate   - Activate baseline
POST /fabric/drift/baselines/{id}/archive    - Archive baseline

Detection#

POST /fabric/drift/observe   - Observe current state and detect drift
POST /fabric/drift/compare    - Compare current state against baseline

Findings#

GET  /fabric/drift/findings                    - List findings
GET  /fabric/drift/findings/{id}               - Get finding
GET  /fabric/drift/findings/{id}/history       - Get status history
GET  /fabric/drift/findings/{id}/impact        - Get impact assessment
POST /fabric/drift/findings/{id}/acknowledge   - Acknowledge finding
POST /fabric/drift/findings/{id}/investigate   - Mark investigating
POST /fabric/drift/findings/{id}/mitigate      - Mark mitigated
POST /fabric/drift/findings/{id}/resolve       - Mark resolved
POST /fabric/drift/findings/{id}/accept        - Accept risk
POST /fabric/drift/findings/{id}/false_positive - Mark as false positive

Authentication#

All endpoints require tenant query parameter. Additional authentication may be required for production use.

Finding Lifecycle#

detected → acknowledged → investigating → mitigated → resolved
                                                      ↘ accepted
                                                      ↘ false_positive

Evidence Chain#

Every drift detection produces evidence in the CAIN Evidence Fabric:

{
  "drift_id": "...",
  "tenant": "...",
  "baseline": {...},
  "observation": {...},
  "comparison": {...},
  "finding": {...},
  "classification": "...",
  "severity": "...",
  "metrics": {
    "baseline_value": ...,
    "current_value": ...,
    "delta": ...,
    "delta_percent": ...,
    "threshold": ...,
    "confidence": ...
  },
  "evidence_chain": ["baseline", "observation", "comparison", "finding"]
}

Compliance Integration#

Drift triggers reassessment but does NOT automatically fail controls. The compliance engine determines actual control status.

Severity Levels#

SeverityDescription
criticalCredentials, permissions, or safety config changed
highModel, version, schema, or endpoint changed
mediumDescription, configuration, or state changed
lowMinor changes detected

CLI Commands#

cain drift status --tenant <tenant>
cain drift baselines --tenant <tenant>
cain drift observe --tenant <tenant> --entity-id <id> --current-state <json>
cain drift compare --tenant <tenant> --entity-id <id> --current-state <json>
cain drift findings --tenant <tenant> [--severity <sev>] [--status <status>]
cain drift inspect --tenant <tenant> --finding-id <id>

Limitations#

Production Status#

ComponentStatus
BaselinesOPERATIONAL
ObservationsOPERATIONAL
ComparisonsOPERATIONAL
FindingsOPERATIONAL
EvidenceOPERATIONAL
LifecycleOPERATIONAL
CLIIMPLEMENTED (pending test)
MCPNOT IMPLEMENTED
Portal DocsTHIS DOCUMENT

Contact#

For issues or questions, see CAIN Studio Platform documentation.

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem