{
 "authority": "NONE",
 "cloud": {
  "analytics": "NOT DEPLOYED",
  "conformance": "NOT DEPLOYED",
  "evidence": "NOT DEPLOYED",
  "federation": "NOT DEPLOYED",
  "governance_learning": "NOT DEPLOYED",
  "identity": "NOT DEPLOYED",
  "incident_response": "NOT DEPLOYED",
  "marketplace": "NOT DEPLOYED",
  "policy": "NOT DEPLOYED",
  "proof": "NOT DEPLOYED",
  "research": "NOT DEPLOYED",
  "trust": "NOT DEPLOYED"
 },
 "gateway_surfaces": {
  "a2a": "TESTED (reference adapter)",
  "api": "TESTED (http/rest reference adapter)",
  "browser": "TESTED (reference adapter; no real browser)",
  "cloud": "TESTED (cloud_api reference adapter; no real account)",
  "code": "PARTIAL (whitelisted pure-function runner only)",
  "computer_use": "TESTED (reference adapter; no real desktop)",
  "databases": "TESTED (reference adapter)",
  "financial_systems": "PARTIAL (E29 synthetic TEST units; no payment rail)",
  "http": "TESTED (reference adapter)",
  "mcp": "TESTED (E25 reference adapter; MCPGate is the hosted MCP boundary)",
  "physical_interfaces": "NOT IMPLEMENTED (physical environments are refused)",
  "tools": "TESTED (sealed executors)"
 },
 "governance_os": {
  "kernels": {
   "authority": {
    "authority": "NONE",
    "evolution": "E28/E30",
    "implementation": "identity_fabric delegation + autonomy_kernel.AutonomyGradientEngine",
    "interface": "cain.gabi/1.0#authority"
   },
   "capability": {
    "authority": "NONE",
    "evolution": "E29",
    "implementation": "transaction_fabric.AgentCapabilityMarketplace",
    "interface": "cain.gabi/1.0#capability"
   },
   "communication": {
    "authority": "NONE",
    "evolution": "E33",
    "implementation": "operating_fabric.CAINCommunicationGovernanceFabric",
    "interface": "cain.gabi/1.0#communication"
   },
   "conformance": {
    "authority": "NONE",
    "evolution": "E31",
    "implementation": "governance_proof.CAINGovernanceConformanceEngine",
    "interface": "cain.gabi/1.0#conformance"
   },
   "evidence": {
    "authority": "NONE",
    "evolution": "E8/E30",
    "implementation": "kernel evidence chain + UniversalActionReceiptChain",
    "interface": "cain.gabi/1.0#evidence"
   },
   "evolution": {
    "authority": "NONE",
    "evolution": "E32",
    "implementation": "learning_fabric.CAINEvolutionPromotionGate",
    "interface": "cain.gabi/1.0#evolution"
   },
   "execution": {
    "authority": "NONE",
    "evolution": "E25/E8",
    "implementation": "agency_fabric sealed executors + ActionCommitBoundary",
    "interface": "cain.gabi/1.0#execution"
   },
   "identity": {
    "authority": "NONE",
    "evolution": "E28",
    "implementation": "identity_fabric.CAINExecutionIdentityFabric",
    "interface": "cain.gabi/1.0#identity"
   },
   "learning": {
    "authority": "NONE",
    "evolution": "E32",
    "implementation": "learning_fabric / learning_loop",
    "interface": "cain.gabi/1.0#learning"
   },
   "memory": {
    "authority": "NONE",
    "evolution": "E30/E32",
    "implementation": "autonomy_kernel.GovernedMemoryFabric + learning_fabric.CAINGovernedExperienceMemory",
    "interface": "cain.gabi/1.0#memory"
   },
   "policy": {
    "authority": "NONE",
    "evolution": "E25/E32",
    "implementation": "agency_fabric.UniversalPolicyCompiler + learning_fabric.GovernanceStateStore",
    "interface": "cain.gabi/1.0#policy"
   },
   "proof": {
    "authority": "NONE",
    "evolution": "E31",
    "implementation": "governance_proof.CAINGovernanceProofKernel",
    "interface": "cain.gabi/1.0#proof"
   },
   "reasoning_governance": {
    "authority": "NONE",
    "evolution": "E13",
    "implementation": "decision integrity library (structured decisions, no private reasoning)",
    "interface": "cain.gabi/1.0#reasoning_governance"
   },
   "recovery": {
    "authority": "NONE",
    "evolution": "E29/E32",
    "implementation": "MachineRecoveryController + CAINGovernanceSelfRepairEngine",
    "interface": "cain.gabi/1.0#recovery"
   },
   "risk": {
    "authority": "NONE",
    "evolution": "E29/E30",
    "implementation": "CounterpartyRiskEngine + causal consequence",
    "interface": "cain.gabi/1.0#risk"
   },
   "telemetry": {
    "authority": "NONE",
    "evolution": "E33",
    "implementation": "operating_fabric.CAINAgentEventFabric",
    "interface": "cain.gabi/1.0#telemetry"
   },
   "transaction": {
    "authority": "NONE",
    "evolution": "E29",
    "implementation": "transaction_fabric.CAINTransactionFabric",
    "interface": "cain.gabi/1.0#transaction"
   },
   "world_state": {
    "authority": "NONE",
    "evolution": "E30",
    "implementation": "autonomy_kernel.WorldActionGovernanceFabric",
    "interface": "cain.gabi/1.0#world_state"
   }
  },
  "note": "governance substrate for machine agency; does not replace any host operating system"
 },
 "moat_graph": {
  "foundations": {
   "conformance_ecosystem": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "developer_sdk": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "edge_deployment": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "enterprise_integration": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "ABSENT"
   },
   "evidence_history": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "failure_corpus": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "governance_datasets": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "ABSENT"
   },
   "governance_infrastructure": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "governance_proofs": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "identity_continuity": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "incident_intelligence": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "integration_ecosystem": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "machine_reputation": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "policy_portability": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "protocol_interoperability": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "research_ip": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "standards_participation": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "ABSENT"
   },
   "switching_costs": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "ABSENT"
   },
   "transaction_history": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "ABSENT"
   },
   "trust_federation": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   },
   "verification_tooling": {
    "market_moat": "NOT ESTABLISHED",
    "technical_foundation": "PRESENT"
   }
  },
  "note": "no customers, integrations, adoption or standards participation are claimed"
 },
 "moat_placement": {
  "extends": [
   "all seven moats as one operation lifecycle; no new moat"
  ],
  "new_moat": false
 },
 "products": {
  "CAIN Agent Passport": {
   "implementation": "identity_fabric passports (E28)",
   "status": "TESTED library"
  },
  "CAIN Conformance": {
   "implementation": "E31 G0-G8 + E33 operating bench",
   "status": "TESTED; CAIN internal profile, not a certification"
  },
  "CAIN Edge": {
   "implementation": "operating_services.CAINEdgeGovernanceNode",
   "status": "TESTED library; no edge device"
  },
  "CAIN Evolution": {
   "implementation": "learning_fabric / learning_loop (E32)",
   "status": "TESTED; simulated learning"
  },
  "CAIN Governance Cloud": {
   "implementation": "architecture only",
   "status": "NOT DEPLOYED"
  },
  "CAIN Governance Gateway": {
   "implementation": "operating_fabric.CAINGovernedMachineOperationKernel",
   "status": "MCPGate is LIVE for MCP; the broader gateway is an in-process library"
  },
  "CAIN Governance Proof": {
   "implementation": "governance_proof (E31)",
   "status": "TESTED library"
  },
  "CAIN Governance Sidecar": {
   "implementation": "operating_sidecar (stdio JSON)",
   "status": "TESTED locally"
  },
  "CAIN Incident": {
   "implementation": "operating_services.CAINIncidentCommandFabric",
   "status": "TESTED library"
  },
  "CAIN Machine Economy": {
   "implementation": "E29 treasury/escrow/contracts",
   "status": "TESTED; synthetic units"
  },
  "CAIN Research": {
   "implementation": "learning_fabric research ingestion + radar",
   "status": "TESTED library"
  },
  "CAIN Transactions": {
   "implementation": "transaction_fabric (E29)",
   "status": "TESTED; synthetic units"
  },
  "CAIN Trust Network": {
   "implementation": "E29 federation + E31 translation",
   "status": "TESTED library"
  },
  "CAIN Verify": {
   "implementation": "verify_e31.py / verify_e33.py / cain-verify.ts",
   "status": "TESTED; not independently used"
  }
 },
 "research_radar": {
  "items": [
   {
    "claim": "Delegated Agent Authorization Protocol: DID-based agent identity, OAuth-style consent grants, signed JWT grant tokens, revocation, policy engine",
    "id": "R1",
    "kind": "IETF Internet-Draft (individual)",
    "maturity": "DRAFT (not a standard)",
    "opportunity": "map CAIN delegation token fields to DAAP claims in the GovernanceABI",
    "relevance": "delegation + revocation model comparable to E28/E33 leases",
    "security": "online revocation dependency; token theft",
    "source": "https://datatracker.ietf.org/doc/draft-mishra-oauth-agent-grants/"
   },
   {
    "claim": "AI agents should reuse SPIFFE, WIMSE, OAuth and OpenID SSF, preserving user/system context in audit trails",
    "id": "R2",
    "kind": "IETF Internet-Draft (individual)",
    "maturity": "DRAFT",
    "opportunity": "SPIFFE-ID mapping in the ABI identity interface",
    "relevance": "identity carriers for CAIN execution identity",
    "security": "context loss across hops",
    "source": "https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/"
   },
   {
    "claim": "AI Agent Standards Initiative (CAISI) covering agent security, interoperability and identity",
    "id": "R3",
    "kind": "NIST programme page",
    "maturity": "PROGRAMME (no final standard)",
    "opportunity": "align CAIN conformance vocabulary",
    "relevance": "public framing for agent identity/authorization",
    "security": "n/a",
    "source": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative"
   },
   {
    "claim": "demonstration project for agent identity and authorization using OAuth 2.0, SPIFFE/SPIRE and MCP",
    "id": "R4",
    "kind": "NIST NCCoE concept paper (initial public draft)",
    "maturity": "CONCEPT PAPER",
    "opportunity": "sidecar/gateway conformance profile",
    "relevance": "MCP + identity + authorization is the CAIN gateway space",
    "security": "n/a",
    "source": "https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd"
   },
   {
    "claim": "ActGov: tool calls abstracted into finite policy records, permitted only inside a task-scoped authorization boundary",
    "id": "R5",
    "kind": "arXiv preprint",
    "maturity": "PREPRINT",
    "opportunity": "compare against the canonical operation record",
    "relevance": "same shape as the E33 operation kernel's scoped authorization",
    "security": "abstraction gaps between record and real call",
    "source": "https://arxiv.org/abs/2609.24446v2"
   },
   {
    "claim": "AgentSpec: customizable runtime enforcement rules for LLM agents",
    "id": "R6",
    "kind": "arXiv preprint",
    "maturity": "PREPRINT",
    "opportunity": "adapter that imports AgentSpec-style rules as overlay config",
    "relevance": "runtime enforcement baseline",
    "security": "rule bypass through unmodelled tools",
    "source": "https://arxiv.org/pdf/2503.18666"
   },
   {
    "claim": "survey of evidence tracing and execution provenance in LLM agents",
    "id": "R7",
    "kind": "arXiv preprint (survey)",
    "maturity": "PREPRINT",
    "opportunity": "gap analysis vs the survey taxonomy",
    "relevance": "E31 proofs / E33 event fabric",
    "security": "n/a",
    "source": "https://arxiv.org/pdf/2606.04990"
   },
   {
    "claim": "AP2 'whisper' attacks: signing the transaction but not the decision; proposes a binding defense",
    "id": "R8",
    "kind": "arXiv preprint",
    "maturity": "PREPRINT",
    "opportunity": "invariant: payment operation binds the authorization digest (CAIN already binds action digests)",
    "relevance": "E29/E33 economic runtime: bind decision to transaction",
    "security": "decision/transaction decoupling",
    "source": "https://arxiv.org/pdf/2609.11757"
   },
   {
    "claim": "AIP: agent identity protocol for verifiable delegation across MCP and A2A",
    "id": "R9",
    "kind": "arXiv preprint",
    "maturity": "PREPRINT",
    "opportunity": "federation/translation test vectors",
    "relevance": "portable identity across protocols (E28)",
    "security": "cross-protocol confusion",
    "source": "https://arxiv.org/pdf/2603.24775"
   },
   {
    "claim": "detecting covert coordination in latent multi-agent communication (sequential monitor, AUROC reported by authors)",
    "id": "R10",
    "kind": "arXiv preprint",
    "maturity": "PREPRINT",
    "opportunity": "CAIN detects structural covert paths (unexpected channel graph edges); content steganalysis NOT implemented",
    "relevance": "E33 communication governance / covert channels",
    "security": "covert channels in benign-looking text",
    "source": "https://arxiv.org/abs/2608.19161"
   },
   {
    "claim": "multi-agent collusion detection with activation probes (NARCBENCH)",
    "id": "R11",
    "kind": "arXiv preprint",
    "maturity": "PREPRINT",
    "opportunity": "none directly: CAIN has no access to model activations",
    "relevance": "collective governance",
    "security": "collusion",
    "source": "https://arxiv.org/pdf/2604.01151"
   }
  ],
  "method": "web search listings; abstracts/snippets only; full texts NOT read; reproducibility NOT CHECKED",
  "swept_at": "2026-09-30"
 },
 "runtime_adapters": {
  "a2a_agent": {
   "basis": "A2A reference adapter through E25/E8 (in-process)",
   "status": "ENFORCED"
  },
  "browser_agent": {
   "basis": "browser ops governed through the reference adapter; no real browser integration",
   "status": "PARTIAL"
  },
  "cloud_agent": {
   "basis": "cloud_api reference adapter; no real cloud account",
   "status": "PARTIAL"
  },
  "coding_agent": {
   "basis": "run_code/terminal ops are governed; arbitrary code execution is limited to a whitelisted runner",
   "status": "PARTIAL"
  },
  "computer_use_agent": {
   "basis": "computer_use ops governed through the reference adapter; no real desktop",
   "status": "PARTIAL"
  },
  "enterprise_automation": {
   "basis": "no integration",
   "status": "UNKNOWN"
  },
  "generic_llm_agent": {
   "basis": "any agent that sends operations through the ABI/sidecar is governed by E33->E8",
   "status": "ENFORCED"
  },
  "mcp_agent": {
   "basis": "MCP reference adapter through E25/E8 (in-process; MCPGate is the hosted MCP boundary)",
   "status": "ENFORCED"
  },
  "multi_agent_system": {
   "basis": "collective limits from E10/E17/E20; communication graph governed only for messages sent as operations",
   "status": "PARTIAL"
  },
  "physical_robotic_system": {
   "basis": "physical environments are UNENFORCED: refused",
   "status": "UNKNOWN"
  },
  "research_agent": {
   "basis": "E32 sandbox only",
   "status": "SIMULATED"
  },
  "workflow_agent": {
   "basis": "no workflow-engine carrier",
   "status": "UNKNOWN"
  }
 },
 "schema": "cain42.e33.registers.v1",
 "sdk_targets": {
  "go": "NOT IMPLEMENTED",
  "grpc": "NOT IMPLEMENTED",
  "python": "IMPLEMENTED (cain45.l5.operating_sdk over the ABI)",
  "rest": "NOT IMPLEMENTED (no hosted E33 endpoint)",
  "stdio_sidecar": "IMPLEMENTED (JSON lines over a subprocess)",
  "typescript": "IMPLEMENTED for verification only (sdk/typescript/cain-verify.ts)"
 },
 "technology_radar_flags": {
  "improves_governance": [
   "R1",
   "R3",
   "R4",
   "R5",
   "R6",
   "R7"
  ],
  "interoperability": [
   "R1",
   "R2",
   "R4",
   "R9"
  ],
  "new_attack_surface": [
   "R8",
   "R10",
   "R11"
  ]
 }
}
