TESTED library · not hosted · not third-party reviewed.
Every consequential thing an agent does — call a tool, send a message, run code, create a helper agent, change its memory, pay — becomes one governed operation with one lifecycle, checked and committed at E8 and carrying a signed proof. An existing agent can be governed through a small sidecar without importing any CAIN code.
Invariants 581/581; scenarios 2029/2029 held; mutation 12/12; tests 11 passed / 0 failed; clean-room verifier INTACT (2603/2603).
| Step | Result |
|---|---|
| MACHINE_INTELLIGENCE | OK |
| INTENT | OK |
| IDENTITY | OK |
| CAPABILITY | OK |
| AUTHORITY | OK |
| POLICY | OK |
| EVIDENCE | OK |
| WORLD_STATE | OK |
| RISK | OK |
| CONSEQUENCE | OK |
| AUTHORIZATION | OK |
| E8 | OK |
| ENFORCEMENT | OK |
| EXECUTION | OK |
| REALITY | OK |
| PROOF | OK |
| VERIFICATION | OK |
| LEARNING | OK |
| INCIDENT_SUCCESS_DRIFT | OK |
| GOVERNANCE_EVOLUTION | OK |
| SANDBOX | OK |
| ADVERSARIAL_TEST | OK |
| CLEAN_ROOM_VERIFICATION | OK |
| CANARY | OK |
| PROMOTION | OK |
| NEW_GOVERNANCE_STATE | OK |
| NEXT_OPERATION | OK |
| Runtime | Status | Basis |
|---|---|---|
| generic_llm_agent | ENFORCED | any agent that sends operations through the ABI/sidecar is governed by E33->E8 |
| mcp_agent | ENFORCED | MCP reference adapter through E25/E8 (in-process; MCPGate is the hosted MCP boundary) |
| a2a_agent | ENFORCED | A2A reference adapter through E25/E8 (in-process) |
| coding_agent | PARTIAL | run_code/terminal ops are governed; arbitrary code execution is limited to a whitelisted runner |
| browser_agent | PARTIAL | browser ops governed through the reference adapter; no real browser integration |
| computer_use_agent | PARTIAL | computer_use ops governed through the reference adapter; no real desktop |
| workflow_agent | UNKNOWN | no workflow-engine carrier |
| multi_agent_system | PARTIAL | collective limits from E10/E17/E20; communication graph governed only for messages sent as operations |
| research_agent | SIMULATED | E32 sandbox only |
| physical_robotic_system | UNKNOWN | physical environments are UNENFORCED: refused |
| enterprise_automation | UNKNOWN | no integration |
| cloud_agent | PARTIAL | cloud_api reference adapter; no real cloud account |
| Category | Held |
|---|---|
| identity | 66/66 |
| authority | 100/100 |
| delegation | 54/54 |
| capability | 62/62 |
| policy | 56/56 |
| memory | 63/63 |
| evidence | 92/92 |
| proof | 88/88 |
| verifier | 90/90 |
| communication | 84/84 |
| collective | 110/110 |
| economic | 78/78 |
| transaction | 60/60 |
| supply_chain | 139/139 |
| model | 72/72 |
| runtime | 59/59 |
| world_model | 60/60 |
| physical_action | 72/72 |
| computer_use | 78/78 |
| self_improvement | 75/75 |
| governance_loop | 152/152 |
| recursive | 64/64 |
| recovery | 55/55 |
| partition | 62/62 |
| byzantine | 70/70 |
| insider | 68/68 |