CAIN-42 · For large organisations
SIEM, chat & alert forwarding
Sends every block and hold to Sentinel, Datadog, Slack or Teams, signed.
Last reviewed 2026-10-01
Live Core platform · Platform feature
What it is
Signed decision events forwarded to Microsoft Sentinel, Datadog, Slack, Teams, Splunk-style webhooks and syslog.
Where it fits
Part of For large organisations: Compliance, private deployment, SIEM and advisory. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Documentation
https://cainstudio.online/docs/siem
Live now
Checked from your browser when this page opened, not from a cached list.
Fire a real decision
Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.
For AI engineers
Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.
Python (zero dependencies)
pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=... # free key: https://cainstudio.online/signup
import cainstudio
@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
... # runs only if CAIN allows this call, with these arguments
try:
transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
print("CAIN unreachable: not run") # fail-closedSee a real decision with no account
cainstudio try # live pipeline, stage by stage
cainstudio try --list # the other attack scenariosMCP clients (Claude Code, Cursor)
claude mcp add --transport http cain https://cainstudio.online/mcpMore: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Policy, law & governance: 966 tested invariants — The rules agents must follow, and how they are enforced.
- Transactions, markets & economics: 664 tested invariants — Agents that buy, sell, bid and pay, within limits.
Related
- Actuarial Cyber Insurance Underwriting Protocol — A protocol for scoring AI-agent risk the way insurers score cyber risk (prototype, no insurer yet).
- Continuous Regulatory Compliance-as-a-Service (EU AI Act & ISO 42001) — Ongoing EU AI Act and ISO 42001 evidence, delivered as a service.
- MCPGate Sovereign Enterprise Appliance (Air-Gapped Kubernetes) — MCPGate as a private appliance for your own Kubernetes or air-gapped network.
- Self-hosted CAIN — Run CAIN inside your own network, next to your agents.
- Single sign-on & SCIM — Sign in with your company login (Okta, Entra, Google) and keep users in sync automatically.
- UsageLedger — Usage metering, tiered pricing and invoices for AI services.
- Autonomous Swarm Fleet Quarantine & Emergency Kill-Switch SLAs — Stop a whole fleet of agents at once, with an agreed response time.
- Confidential Computing Hardware Enclave Remote Attestation Notary — Prove an agent ran inside trusted hardware (planned; no hardware enclave behind it yet).
- Enterprise SIEM & SOC Connectors — Connectors that feed CAIN events into your security operations center.
- Governed Agent Memory & Vector Sanitization Service — Cleans agent memory and vector stores of planted instructions, as a service.
Full documentation
The complete reference, also at /docs/siem.
SIEM forwarding#
Send every CAIN decision to the security tools your team already watches: Splunk, Cortex XSIAM, Datadog, Microsoft Sentinel, or any HTTPS endpoint that accepts JSON. Held actions, blocks and the kill switch can also go to a Slack or Microsoft Teams channel. Each decision is forwarded as it is recorded, with its verdict, its stages and its signed digest, so the event in your SIEM can be checked against the decision record format.
Forwarding is off until a workspace owner turns it on, per destination. It sends your workspace's decisions to a third party, so each destination is opt-in, https only, and authenticated with that collector's own token.
Splunk (HTTP Event Collector)#
Create an HEC token in Splunk, then:
curl -s https://cainstudio.online/fabric/webhooks \
-H "X-API-Key: $CAIN_API_KEY" -H 'content-type: application/json' \
-d '{"url":"https://splunk.example.com:8088/services/collector/event",
"format":"splunk_hec", "auth_token":"<your HEC token>",
"events":["decision.recorded"], "description":"SOC Splunk"}'
Each event arrives as {"event": {...}, "sourcetype": "cain:decision.recorded", "source": "cain42", "time": <epoch>} with Authorization: Splunk <token>.
Cortex XSIAM (HTTP log collector)#
In Cortex XSIAM, create an HTTP log collector with the JSON log format and copy its API key. The collector URL has the form https://api-<your tenant>/logs/v1/event:
curl -s https://cainstudio.online/fabric/webhooks \
-H "X-API-Key: $CAIN_API_KEY" -H 'content-type: application/json' \
-d '{"url":"https://api-<your tenant>/logs/v1/event",
"format":"xsiam", "auth_token":"<collector API key>",
"events":["decision.recorded"], "description":"Cortex XSIAM"}'
Each event is one JSON object followed by a newline, sent with the collector key in the Authorization header.
> Tested against: a local receiver that checks the request shape. Not yet tested against a live > Cortex XSIAM tenant. If your collector shows a different header in its sample request, tell us at > support@cainstudio.online and we will match it.
Datadog (Logs)#
Use a Datadog API key and your site's logs intake URL:
curl -s https://cainstudio.online/fabric/webhooks \
-H "X-API-Key: $CAIN_API_KEY" -H 'content-type: application/json' \
-d '{"url":"https://http-intake.logs.datadoghq.com/api/v2/logs",
"format":"datadog", "auth_token":"<Datadog API key>",
"events":["decision.recorded"], "description":"Datadog"}'
Each event is sent as one log entry (ddsource:cain, service:cain-fabric, tags event:<event> and tenant:<tenant>) whose message is the signed envelope itself, so Datadog parses it as JSON. The key goes in the DD-API-KEY header.
Microsoft Sentinel (Logs Ingestion API)#
Create a data collection endpoint and a data collection rule with a custom stream, for example Custom-CAINDecisions_CL, with the columns TimeGenerated (datetime), Event, CainTenant, DeliveryId, Envelope (string) and Data (dynamic). Then register an Entra app, give it the *Monitoring Metrics Publisher* role on the rule, and pass its credentials as auth_token:
curl -s https://cainstudio.online/fabric/webhooks \
-H "X-API-Key: $CAIN_API_KEY" -H 'content-type: application/json' \
-d '{"url":"https://<endpoint>.ingest.monitor.azure.com/dataCollectionRules/dcr-<immutable id>/streams/Custom-CAINDecisions_CL?api-version=2023-01-01",
"format":"sentinel", "auth_token":"<entra tenant id>:<app client id>:<app client secret>",
"events":["decision.recorded"], "description":"Sentinel"}'
CAIN exchanges the app credentials for an Entra token (client credentials, scope https://monitor.azure.com/.default) and caches it until shortly before it expires. If the exchange fails, nothing is sent and the failure is recorded in the deliveries list. Envelope is the exact signed body, so you can still check CAIN-Signature from a KQL query.
Slack and Microsoft Teams (approvals and alerts)#
Post held actions to the people who approve them:
curl -s https://cainstudio.online/fabric/webhooks \
-H "X-API-Key: $CAIN_API_KEY" -H 'content-type: application/json' \
-d '{"url":"https://hooks.slack.com/services/T000/B000/XXXX", "format":"slack",
"events":["approval.requested","decision.blocked","killswitch.engaged"]}'
For Teams, use a Workflows "post to a channel when a webhook request is received" URL with "format":"teams"; messages arrive as Adaptive Cards. Slack URLs must be on hooks.slack.com, and Teams URLs on *.webhook.office.com, *.logic.azure.com or *.powerplatform.com.
A message names the action, who asked, why it was held, when the hold expires, and the approval id with the command to approve it. It never includes the call's arguments. Text that came from an agent, such as a tool name or a reason, is escaped, so it cannot turn into a link, a fake "Approve" button or an @channel in your channel. Approving still happens in the console or with cainstudio approve, not from the message.
> Tested against: local receivers that check each request shape, including the Entra token exchange. > Not yet tested against live Datadog, Sentinel, Slack or Teams workspaces. If your service shows a > different sample request, tell us at support@cainstudio.online.
Any HTTPS endpoint#
Leave out format (it defaults to cain) to receive the signed JSON envelope that all CAIN webhooks use. Verify each delivery with the signing secret returned once at creation: HMAC-SHA256 over <timestamp>.<raw body>, compared with the v1 value of the CAIN-Signature header. Reject deliveries whose timestamp is more than 5 minutes old.
Events#
| Event | Sent when |
decision.recorded | every recorded decision: the SIEM feed |
decision.blocked | a decision that an enforcing stage blocked |
approval.requested / approval.resolved | an action is held for a person, then approved or denied |
killswitch.engaged / killswitch.released | the workspace kill switch changes |
A decision.recorded event carries: decision_id, created_at, verdict, blocked, enforcing, halted, principal_id, agent_id, service, path, chain_id, outcome, the stages (name, verdict, enforcing), and digest, record_key_id and record_signature.
How forwarding behaves#
- Never slows or fails a decision. Delivery runs after the decision is recorded, detached from it.
- Retries up to 4 attempts with backoff, then records the failure. An endpoint that fails 20 times in
a row is paused (not deleted); see GET /fabric/webhooks/deliveries.
- Cannot be aimed inside our network. The hostname is resolved and every address checked before the
destination is accepted and again before each attempt. Private, loopback and cloud-metadata addresses are refused, the connection goes to the address that was checked, and redirects are not followed.
- Secrets stay put. The collector token and the signing secret are never returned by any endpoint
after creation.
Manage destinations#
curl -s https://cainstudio.online/fabric/webhooks -H "X-API-Key: $CAIN_API_KEY" # list curl -s https://cainstudio.online/fabric/webhooks/deliveries -H "X-API-Key: $CAIN_API_KEY" # recent deliveries curl -s -X DELETE https://cainstudio.online/fabric/webhooks/<endpoint_id> -H "X-API-Key: $CAIN_API_KEY"
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem