CAIN-42 CAIN Studio

CAIN-42 · See what your agents do

CAIN Trajectory

Spots when an agent's chain of actions drifts somewhere it should not go, even in small steps.

Last reviewed 2026-10-01

Live   Core platform · security

What it is

Agent trajectory monitoring and anomaly detection.

Where it fits

Part of See what your agents do: Every action, every decision, replayed and searchable. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.

Use it

Recorded status: PRODUCTION. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).

Live now

Checked from your browser when this page opened, not from a cached list.

Fire a real decision

Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.

For AI engineers

Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.

Python (zero dependencies)

pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=...   # free key: https://cainstudio.online/signup

import cainstudio

@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
    ...  # runs only if CAIN allows this call, with these arguments

try:
    transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
    print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
    print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
    print("CAIN unreachable: not run")   # fail-closed

See a real decision with no account

cainstudio try          # live pipeline, stage by stage
cainstudio try --list   # the other attack scenarios

MCP clients (Claude Code, Cursor)

claude mcp add --transport http cain https://cainstudio.online/mcp

More: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key

Tested guarantees in this area

Every rule in these niches has its own page with its recorded result.

Related

Full documentation

The complete reference, also at /docs/trajectory.

CAIN Trajectory Documentation#

Status: LIVE + FUNCTIONAL#

Verified 2026-09-08: /fabric/trajectories/ returns 3 trajectories for test tenant.

CAIN Trajectory is fully functional. The core enforcement engine, API, dashboard, and tests are all implemented and working.


What is CAIN Trajectory?#

CAIN Trajectory monitors and verifies the sequence of actions taken by an AI agent, detecting when individually permitted actions combine into an unsafe, unauthorized, or policy-violating trajectory.

Core principle: An action can be allowed while the trajectory is not.

CAIN evaluates both:


Trajectory Model#

A trajectory contains ordered events:

Every event has:


Trajectory States#


Trajectory Policies#

Sequence Constraints#

Trajectory policies define allowed and prohibited sequences:

ALLOW: read_customer_record
ALLOW: summarize_customer_record
DENY: external_upload (after read_customer_record)

Policy Operators#


Real-Time Enforcement#

Trajectory monitoring operates in the execution path via make_cain_decision() in cain_private.py:

AGENT → IDENTITY → CURRENT TRAJECTORY → PROPOSED ACTION
     → CAIN POLICY → TRAJECTORY ANALYSIS → RISK VERIFICATION
     → DECISION → ENFORCEMENT → EXECUTION → EVIDENCE

A trajectory violation MUST prevent the consequential action from executing.

Warning: A dashboard warning after the action already happened is NOT trajectory enforcement.


Verdict Model#

CAIN Trajectory uses the existing CAIN verdict model:


Evidence#

Every consequential trajectory produces durable evidence with cryptographic integrity:


Feature Status#

FeatureStatusNotes
Trajectory observationLIVE + FUNCTIONALAPI verified 2026-09-08
Trajectory state machineLIVE + FUNCTIONALState transitions work
Trajectory policiesLIVE + FUNCTIONALPolicies stored and evaluated
Trajectory enforcement (API)LIVE + FUNCTIONALAPI verified working
Trajectory enforcement (execution path)LIVE + FUNCTIONALEnforced via make_cain_decision()
Trajectory simulationLIVE + FUNCTIONALEvaluate endpoint works
Trajectory replayLIVE + FUNCTIONAL (read-only)Replay endpoint exists
Tenant isolationLIVE + FUNCTIONALVerified - tenant-scoped queries
Evidence integrityLIVE + FUNCTIONALHMAC+hash chain verified
DashboardLIVE + FUNCTIONALShows real trajectory data
CLILIVE + FUNCTIONALcain trajectory commands work
APILIVE + FUNCTIONAL/fabric/trajectories/ verified
Conformance testsLIVE + FUNCTIONALTests exist and pass
MCP IntegrationNOT DEPLOYEDFuture work

API Endpoints#

Create Trajectory#

POST /fabric/trajectories/

Get Trajectory#

GET /fabric/trajectories/{trajectory_id}

List Trajectories#

GET /fabric/trajectories/

Evaluate Action (Simulation)#

POST /fabric/trajectories/{trajectory_id}/evaluate

Make Decision (Enforcement)#

POST /fabric/trajectories/{trajectory_id}/decide

Create Policy#

POST /fabric/trajectories/policies

Get Policy#

GET /fabric/trajectories/policies/{policy_id}

Get Evidence#

GET /fabric/trajectories/{trajectory_id}/evidence

CLI Commands#

# List trajectories
cain trajectory list

# Get a trajectory
cain trajectory get <trajectory_id>

# Create a trajectory
cain trajectory create --identity user1 --agent agent1

# Make a decision
cain trajectory decide <trajectory_id> read_data --tool read_tool

# Evaluate (simulate)
cain trajectory evaluate <trajectory_id> read_data

# List violations
cain trajectory violations

# Replay a trajectory
cain trajectory replay <trajectory_id>

# Get evidence
cain trajectory evidence <trajectory_id>

# Create a policy
cain trajectory policy-create --name "customer-data-policy" --rule "never_after:external_transfer:read_sensitive_data"

# Get a policy
cain trajectory policy <policy_id>

Dashboard#

Access the trajectory dashboard at: /trajectory/dashboard

Features:


Limitations#

1. MCP trajectory tracking not implemented (future work)


See Also#

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem