CAIN-42 Evolution 30 — Governed Machine Autonomy

TESTED integration library · not hosted · not third-party reviewed · ephemeral keys.

Intelligence proposes; CAIN decides; E8 commits; evidence remembers. Governance coverage is reported honestly: paths CAIN is not in are UNCONTROLLED or UNKNOWN.

Invariants 166/166; scenarios 889/889 held; mutation 11/11 killed; TypeScript SDK INTACT (tamper BROKEN); tests 11 passed / 0 failed; clean-room verifier INTACT (1187/1187).

End-to-end autonomy proof

StepResult
AGENTOK
IDENTITYOK
PERCEPTIONOK
MEMORYOK
REASONINGOK
PLANNINGOK
CAPABILITYOK
DELEGATIONOK
NEGOTIATIONOK
CONTRACTOK
AUTHORITYOK
RISKOK
CONSEQUENCEOK
AUTHORIZATIONOK
TRANSACTIONOK
E8OK
EXECUTIONOK
ENVIRONMENTOK
OBSERVATIONOK
EVIDENCEOK
LEARNINGOK
SELF_TESTOK
SELF_IMPROVEMENT_PROPOSALOK
GOVERNANCE_REVIEWOK
CANARYOK
PROMOTIONOK
REJECTIONOK
CONTINUOUS_REAUTHORIZATIONOK

Scenario categories

CategoryHeld
protocol_integration109/109
self_improvement103/103
identity_delegation164/164
economic101/101
memory_perception101/101
supply_chain103/103
multi_agent103/103
world_action105/105

Governance coverage

PathClass
hosted gateway /fabric decisions (cainstudio.online)ENFORCED
MCPGate proxy on the live cluster cain-mr-02 (operator test)ENFORCED
hosted MCPGate on customer tool callsPARTIALLY_ENFORCED
E25-E30 library actions inside one processENFORCED
self-hosted SDK guard / MCP proxyPARTIALLY_ENFORCED
agent sandbox (namespaces, cgroups, seccomp)ENFORCED
kernel eBPF enforcementUNCONTROLLED
tool calls that do not pass through CAINUNCONTROLLED
physical actuators, robots, vehiclesUNCONTROLLED
third-party agents on the open internetUNKNOWN
hourly cluster health proofsMONITORED
public evidence inventory crawlOBSERVED