{
  "schema": "cain42.cag_l5.verification_matrix.v1",
  "designation": "CAG-L5 = CAIN Autonomous Governance Level 5, a CAIN-specific governance designation, NOT SAE Level 5",
  "statement": "CAIN-42 governs L5-class autonomous AI systems that route their actions through it. This matrix shows, capability by capability, what is verified on the live path and what is not.",
  "statuses": {
    "VERIFIED": "exercised on the live production gateway and checked by a clean-room verifier",
    "PARTIAL": "implemented and tested, verified offline or in part; not fully exercised live",
    "NOT VERIFIED": "no evidence"
  },
  "rows": [
    {
      "capability": "Agent identity",
      "status": "VERIFIED",
      "evidence": "live production gateway run (CAIN42_CAG_L5_HOSTED_LIVE_RUN.json)",
      "what_it_shows": "cases C (unsigned), D (another agent's key), E (replay) refused on the live gateway"
    },
    {
      "capability": "Dynamic authority",
      "status": "VERIFIED",
      "evidence": "live production gateway run (CAIN42_CAG_L5_HOSTED_LIVE_RUN.json)",
      "what_it_shows": "cases F (system does not hold it) and H (subagent WRITE) refused; authority is the intersection of agent, delegator, system and lease"
    },
    {
      "capability": "Continuous authorization",
      "status": "PARTIAL",
      "evidence": "library tests + clean-room verifier on a published bundle (l5-trajectory-system-2026-09-28)",
      "what_it_shows": "live: every decision re-checks a governance-signed lease bound to agent, trajectory and plan; expiry, material change and trust drop are tested in the library, not tripped live"
    },
    {
      "capability": "Trajectory governance",
      "status": "PARTIAL",
      "evidence": "library tests + clean-room verifier on a published bundle (l5-trajectory-system-2026-09-28)",
      "what_it_shows": "13 fail-open paths fixed and regression-tested; the independent verifier recomputes 9 adversarial requests; not exercised as a long live trajectory"
    },
    {
      "capability": "System governance",
      "status": "VERIFIED",
      "evidence": "live production gateway run (CAIN42_CAG_L5_HOSTED_LIVE_RUN.json)",
      "what_it_shows": "hosted gateway: unregistered tenant denied (B), system scope (F), model swap (G) and unlisted tool (I) refused; governance state certified by cain-mr-01"
    },
    {
      "capability": "Resource governance",
      "status": "VERIFIED",
      "evidence": "live production gateway run (CAIN42_CAG_L5_HOSTED_LIVE_RUN.json)",
      "what_it_shows": "case F: an agent-held grant outside the system's resource ceiling is refused"
    },
    {
      "capability": "MCP enforcement",
      "status": "PARTIAL",
      "evidence": "hosted verdict endpoint + SDK SystemGate (library)",
      "what_it_shows": "the hosted /fabric/mcp/enforce decides and returns a signed commitment; the caller's MCPGate/SystemGate executes; the live MCPGate proxy run (C42-MCPGATE-ENFORCES) did not use the system governor"
    },
    {
      "capability": "Risk governance",
      "status": "PARTIAL",
      "evidence": "library tests + clean-room verifier on a published bundle (l5-trajectory-system-2026-09-28)",
      "what_it_shows": "blast radius and two-operator step-up are tested (Tests K, SYS-11); no irreversible action was run live"
    },
    {
      "capability": "Trust governance",
      "status": "PARTIAL",
      "evidence": "live production gateway run (CAIN42_CAG_L5_HOSTED_LIVE_RUN.json) + library tests + clean-room verifier on a published bundle (l5-trajectory-system-2026-09-28)",
      "what_it_shows": "live: trust comes only from cluster-certified state; trust degradation is tested in the library"
    },
    {
      "capability": "Containment",
      "status": "VERIFIED",
      "evidence": "live production gateway run (CAIN42_CAG_L5_HOSTED_LIVE_RUN.json)",
      "what_it_shows": "case J: emergency MCP execution freeze refused calls; one-operator recovery refused (HTTP 400), two-operator recovery restored ALLOW (case K)"
    },
    {
      "capability": "Evidence fabric",
      "status": "VERIFIED",
      "evidence": "live production gateway run (CAIN42_CAG_L5_HOSTED_LIVE_RUN.json)",
      "what_it_shows": "every decision signed (8/8 valid), 18-event hash-linked chain verifies, the cluster's public record names the certified state digest"
    },
    {
      "capability": "Independent verification",
      "status": "PARTIAL",
      "evidence": "clean-room verifiers (no CAIN imports)",
      "what_it_shows": "independent IMPLEMENTATION, same operator: no third party has reviewed or reproduced CAIN-42"
    }
  ],
  "counts": {
    "VERIFIED": 6,
    "PARTIAL": 6,
    "NOT VERIFIED": 0
  },
  "limits": [
    "operator self-test tenant and a scripted agent: no customer, no LLM agent governed end to end",
    "one operator, one provider; no hardware attestation; no third-party review"
  ]
}
