CAIN-42 · See what your agents do
CAIN Trajectory
Spots when an agent's chain of actions drifts somewhere it should not go, even in small steps.
Last reviewed 2026-10-01
Live Core platform · security
What it is
Agent trajectory monitoring and anomaly detection.
Where it fits
Part of See what your agents do: Every action, every decision, replayed and searchable. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Open it
https://cainstudio.online/trajectory - Documentation
https://cainstudio.online/docs/trajectory - API endpoint:
https://cainstudio.online/fabric/trajectories— needs your API key (get a free key)
Recorded status: PRODUCTION. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).
Live now
Checked from your browser when this page opened, not from a cached list.
Fire a real decision
Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.
For AI engineers
Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.
Python (zero dependencies)
pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=... # free key: https://cainstudio.online/signup
import cainstudio
@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
... # runs only if CAIN allows this call, with these arguments
try:
transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
print("CAIN unreachable: not run") # fail-closedSee a real decision with no account
cainstudio try # live pipeline, stage by stage
cainstudio try --list # the other attack scenariosMCP clients (Claude Code, Cursor)
claude mcp add --transport http cain https://cainstudio.online/mcpMore: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Evidence, receipts & proofs: 928 tested invariants — Signed records that prove what happened, checkable by anyone.
- Autonomy, control loops & recovery: 407 tested invariants — Agents acting on their own, and how CAIN keeps them in bounds and recovers.
Related
- CAIN Drift — Warns you when an agent, model, tool or policy quietly changes.
- CAIN Observability — A live window into what every agent is doing and why each action was allowed or stopped.
- CAIN Plans — Checks an agent's plan before it starts, then holds it to that plan.
- CAIN Resilience — Shows how CAIN keeps working when parts of it fail.
- CAIN Sentinel — Always-on watchdog that detects trouble and contains it automatically.
- CAIN Trace — A tamper-evident record of every step an agent took, in order.
- Hubgate — One overview across all the MCPGate tools.
- MCPWatch — Health and metrics for all your MCP servers in one place.
Full documentation
The complete reference, also at /docs/trajectory.
CAIN Trajectory Documentation#
Status: LIVE + FUNCTIONAL#
Verified 2026-09-08: /fabric/trajectories/ returns 3 trajectories for test tenant.
CAIN Trajectory is fully functional. The core enforcement engine, API, dashboard, and tests are all implemented and working.
What is CAIN Trajectory?#
CAIN Trajectory monitors and verifies the sequence of actions taken by an AI agent, detecting when individually permitted actions combine into an unsafe, unauthorized, or policy-violating trajectory.
Core principle: An action can be allowed while the trajectory is not.
CAIN evaluates both:
- ACTION SAFETY - Is this individual action allowed?
- TRAJECTORY SAFETY - Does this action fit within the allowed trajectory?
Trajectory Model#
A trajectory contains ordered events:
- IDENTITY
- ACTION
- TOOL
- RESOURCE
- DECISION
- EXECUTION
- RESULT
- NEXT ACTION
Every event has:
- timestamp
- tenant
- principal
- agent
- action
- tool
- resource
- decision ID
- policy version
- execution status
- evidence ID
Trajectory States#
- ACTIVE - Trajectory in progress
- COMPLETED - Trajectory finished successfully
- BLOCKED - Trajectory blocked by enforcement
- VIOLATION - Trajectory violation detected
- CANCELLED - Trajectory cancelled
- EXPIRED - Trajectory expired
Trajectory Policies#
Sequence Constraints#
Trajectory policies define allowed and prohibited sequences:
ALLOW: read_customer_record ALLOW: summarize_customer_record DENY: external_upload (after read_customer_record)
Policy Operators#
- NEVER_AFTER - This action cannot follow that action
- MUST_PRECEDE - This action must come before another
- MUST_FOLLOW - This action must come after another
- REQUIRES - This action requires something
- FORBIDS - This combination is forbidden
- MAX_STEPS - Maximum steps in trajectory
- MAX_RISK - Maximum risk accumulation
- MAX_DURATION - Maximum trajectory duration
- REQUIRES_APPROVAL - Approval required for this trajectory
Real-Time Enforcement#
Trajectory monitoring operates in the execution path via make_cain_decision() in cain_private.py:
AGENT → IDENTITY → CURRENT TRAJECTORY → PROPOSED ACTION
→ CAIN POLICY → TRAJECTORY ANALYSIS → RISK VERIFICATION
→ DECISION → ENFORCEMENT → EXECUTION → EVIDENCE
A trajectory violation MUST prevent the consequential action from executing.
Warning: A dashboard warning after the action already happened is NOT trajectory enforcement.
Verdict Model#
CAIN Trajectory uses the existing CAIN verdict model:
- ALLOW - Action allowed, trajectory permits
- DENY - Action or trajectory denied
- REQUIRE_APPROVAL - Trajectory requires approval to continue
- UNKNOWN - Cannot determine trajectory safety
- ERROR - System error
Evidence#
Every consequential trajectory produces durable evidence with cryptographic integrity:
- trajectory ID
- event sequence with hash chain
- HMAC signature for tamper detection
- identity
- agent
- action
- tool
- resource
- policy version
- trajectory rule
- decision
- execution result
- violation state
- timestamp
Feature Status#
| Feature | Status | Notes |
| Trajectory observation | LIVE + FUNCTIONAL | API verified 2026-09-08 |
| Trajectory state machine | LIVE + FUNCTIONAL | State transitions work |
| Trajectory policies | LIVE + FUNCTIONAL | Policies stored and evaluated |
| Trajectory enforcement (API) | LIVE + FUNCTIONAL | API verified working |
| Trajectory enforcement (execution path) | LIVE + FUNCTIONAL | Enforced via make_cain_decision() |
| Trajectory simulation | LIVE + FUNCTIONAL | Evaluate endpoint works |
| Trajectory replay | LIVE + FUNCTIONAL (read-only) | Replay endpoint exists |
| Tenant isolation | LIVE + FUNCTIONAL | Verified - tenant-scoped queries |
| Evidence integrity | LIVE + FUNCTIONAL | HMAC+hash chain verified |
| Dashboard | LIVE + FUNCTIONAL | Shows real trajectory data |
| CLI | LIVE + FUNCTIONAL | cain trajectory commands work |
| API | LIVE + FUNCTIONAL | /fabric/trajectories/ verified |
| Conformance tests | LIVE + FUNCTIONAL | Tests exist and pass |
| MCP Integration | NOT DEPLOYED | Future work |
API Endpoints#
Create Trajectory#
POST /fabric/trajectories/
Get Trajectory#
GET /fabric/trajectories/{trajectory_id}
List Trajectories#
GET /fabric/trajectories/
Evaluate Action (Simulation)#
POST /fabric/trajectories/{trajectory_id}/evaluate
Make Decision (Enforcement)#
POST /fabric/trajectories/{trajectory_id}/decide
Create Policy#
POST /fabric/trajectories/policies
Get Policy#
GET /fabric/trajectories/policies/{policy_id}
Get Evidence#
GET /fabric/trajectories/{trajectory_id}/evidence
CLI Commands#
# List trajectories cain trajectory list # Get a trajectory cain trajectory get <trajectory_id> # Create a trajectory cain trajectory create --identity user1 --agent agent1 # Make a decision cain trajectory decide <trajectory_id> read_data --tool read_tool # Evaluate (simulate) cain trajectory evaluate <trajectory_id> read_data # List violations cain trajectory violations # Replay a trajectory cain trajectory replay <trajectory_id> # Get evidence cain trajectory evidence <trajectory_id> # Create a policy cain trajectory policy-create --name "customer-data-policy" --rule "never_after:external_transfer:read_sensitive_data" # Get a policy cain trajectory policy <policy_id>
Dashboard#
Access the trajectory dashboard at: /trajectory/dashboard
Features:
- View all trajectories
- Filter by state
- Visual timeline
- Policy creation
- API tester
Limitations#
1. MCP trajectory tracking not implemented (future work)
See Also#
- CAIN Identity - Verifiable identity
- CAIN Control - Agent, tool, and policy control
- CAIN Private - Private AI agent environment
- Architecture - Trust Fabric overview
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem