CAIN-42 Evolution #6: authority leases on the LIVE CAIN-42 PBFT cluster, 2026-09-28T03:25:07Z. What happened (all of it is in this bundle): - A real production CAIN decision (POST https://cainstudio.online/fabric/try, demo tenant) came back REQUIRE_APPROVAL, quorum-certified by cain-mr-01 (4 nodes, 4 regions, f=1, quorum 3). - For each of 9 lease conditions, a fresh CAIN-45 ZoD (the agent's authority lease) was authorized by the live cluster cain-mr-01, with an operator approval. One tool call then SUCCEEDED under that authority. - The condition was then tripped, and the next call was REFUSED and the tool did not run: lease TTL expires | trust falls below the floor | agent identity changes (model swapped) tool schema changes after authorization (rug-pull) | security context changes trajectory fork / substitution | explicit revocation | required evidence disappears delegating parent quarantined (the child ZoD loses its authority too) - Every authorization's quorum certificate (3 of 4 Ed25519 node signatures) is in qcs.json. Every step is in a hash-chained evidence log signed by that run's hypervisor. Verify in seconds (Python 3.8+, pip install cryptography, no CAIN code): B=https://clawx.click/evidence/e6-live-lease-2026-09-28 for f in LEASE_RUN.json EVIDENCE_CHAINS.json decision.json qcs.json membership.json; do curl -so $f "$B/$f"; done for v in verify_e6_lease verify_pbft_qc_bundle; do curl -so $v.py "$B/$v.py.txt"; done python3 verify_e6_lease.py . Expect "48/48 checks" and VERIFIED. Edit any certificate, evidence entry, refusal reason, sequence, quorum signature or any field of a result row (they are hypervisor-signed and cross-checked against the chain) and it prints NOT VERIFIED. The same QCs can be fetched live: GET https://cainstudio.online/api/v1/live-cluster/qc/ Status: LIVE-CLUSTER-VERIFIED for the authority on these 9 conditions. For 8 of them the refusal is derived from the signed evidence chain. For "required evidence disappears" it is SELF-REPORTED: the log was deleted, so the refusal rests on a result row signed by the hypervisor key, not on an outside observation. The invalidation checks run in the CAIN-45 hypervisor (a library on the gateway host, operator-run), not inside the cluster nodes. Not covered (stated, not hidden): invalidation on policy change, epoch change, membership change, risk-budget or blast-radius-budget exhaustion (no mechanism exists yet). The tool-schema case is refused by the "exactly one registered tool identity" rule. The tool server is a sandbox key-value store, and the tenant is the demo tenant, not a customer. One writer per evidence database. Production status: PRE-PRODUCTION.