CAIN-45 Evolution 1: a ZoD (Zone of Decision) authorized by the live CAIN-42 PBFT cluster, 2026-09-27T22:48:12Z. What happened, all of it recorded in this bundle: - A real production CAIN decision (POST https://cainstudio.online/fabric/try, demo tenant) came back REQUIRE_APPROVAL, quorum-certified by cain-mr-01 at sequence 13377. - Two ZoDs for two instances of one agent were created, attested (software measurement) and approved by a registered HUMAN identity (the run's operator approver; its public key is in ZOD_RUN.json). - Each ZoD's authorization was ordered by the live cluster cain-mr-01 (sequences 13379 and 13380); the hypervisor accepted it only after verifying the commit certificate itself. - Code ran inside ZoD 1 under real confinement (bubblewrap namespaces + cgroup v2) and probed its own boundary: uid 65534, pid 2, egress "Network is unreachable", host source tree invisible, /usr read-only. - A tool call went through CAIN's real MCPGate interceptor to a sandbox key-value tool server. - 10 attacks were refused, each with a signed DENIED entry: authorize on a REQUIRE_APPROVAL decision without a human approval; use instance-001's grant inside instance-002's ZoD; grant a capability outside the ZoD's set; call a tool outside the ZoD's tool set; forged grant (capability rewritten after signing); act without presenting the security context; child ZoD asking for more than its parent; use a terminated ZoD's grant; security-context substitution (model swapped mid-run); revalidate with the substituted context. Both ZoDs were terminated. 45 evidence entries, hash-chained and signed. Verify (Python 3.8+, pip install cryptography, no CAIN code): B=https://clawx.click/evidence/cain45-zod-live-2026-09-27 for f in ZOD_RUN.json EVIDENCE_CHAIN.json decision.json qcs.json membership.json approval.json; do curl -so $f "$B/$f"; done for v in verify_cain45_zod verify_pbft_qc_bundle; do curl -so $v.py "$B/$v.py.txt"; done python3 verify_cain45_zod.py . Expect 10 PASS lines and VERIFIED. Edit any certificate, evidence entry, decision, approval or quorum signature and it prints NOT VERIFIED. The quorum certificates can also be fetched live: GET https://cainstudio.online/api/v1/live-cluster/qc/. Not established in Evolution 1 (stated, not hidden): - seccomp syscall filtering; allowlisted network egress (only deny-all exists, and a ZoD asking for any egress destination is refused); hardware-backed attestation (software measurement only, no TPM/TEE here); break-glass; a trust/risk-aware scheduler - the hypervisor as a deployed service in front of customer agents: this run used it as a library on the gateway host, operator-run. The approval is the operator's, not a customer's. The CAIN decision is a public demo decision (its trust stage was "unknown", hence REQUIRE_APPROVAL). - the tool server is a sandbox; no customer system was touched.