{
  "schema": "cain42.evolution10.proof.v1",
  "title": "CAIN-42 EVOLUTION-10-PROOF -- Collective Agent Governance Fabric",
  "generated_at": "2026-09-28T23:08:59+00:00",
  "commit": "3106ea9e1626871a44d15b879d1a864ca6846e6e",
  "bundle_name": "e10-collective-governance-2026-09-28",
  "modules": {
    "e10_collective": {
      "path": "cain45/l5/collective.py",
      "sha256": "66a8f836e62749525b4c0f051df3d550d31e753d9041f42f31fefc563e97e20a"
    },
    "e10_collective_passport_extension": {
      "path": "cain45/l5/passport.py",
      "sha256": "f73bbb438a86e2ad7d267d4f3b7bb12d83c245c81e64ba6c8eca6821905302d3"
    },
    "e10_control_plane": {
      "path": "cain45/l5/__init__.py",
      "sha256": "64156f70c30ff27d6d150436f56ffbd8260f13caede908b4570d4281b96366c2"
    },
    "e10_cli": {
      "path": "scripts/cain45/cain_agent_cli.py",
      "sha256": "54928f453b739cc6f8388a42c6b969ba01351ef9543af1995dc91168774edac3"
    }
  },
  "tests": {
    "tests/test_cain42_e10_collective.py": "7e149db98ae7b86bcfcee152a7f6d55bcedb10051452373a33c419f51663bfb0",
    "tests/test_cain42_e10_adversarial.py": "469d1b43fd56cfc8cc4cbe25ae59e3a51b9bf75e86998d6f37b930feba9b3b42",
    "tests/test_cain42_e10_end_to_end.py": "e3ed5f3cc95f60eb9f3d54353b6a0d1c9920e8f41747818134e37f25c642e437"
  },
  "test_run": {
    "command": "python3 -m pytest tests/test_cain42_e10_collective.py tests/test_cain42_e10_adversarial.py tests/test_cain42_e10_end_to_end.py -q",
    "summary": "============================== 47 passed in 0.76s ==============================",
    "passed": 47,
    "failed": 0,
    "returncode": 0,
    "transcript_tail": [
      "============================= test session starts ==============================",
      "collected 47 items",
      "",
      "tests/test_cain42_e10_collective.py .................................    [ 70%]",
      "tests/test_cain42_e10_adversarial.py .........                           [ 89%]",
      "tests/test_cain42_e10_end_to_end.py .....                                [100%]",
      "",
      "============================== 47 passed in 0.76s =============================="
    ]
  },
  "invariants": {
    "evolution": 10,
    "fabric": "cain42.l5.collective",
    "checks": [
      {
        "id": "C1",
        "invariant": "COLLECTIVE AUTHORITY NEVER EXCEEDS POLICY CEILING",
        "holds": true,
        "detail": [
          [
            "READ",
            "db"
          ]
        ]
      },
      {
        "id": "C2",
        "invariant": "COLLECTIVE AUTHORITY NEVER EXCEEDS MEMBER AUTHORITY ENVELOPE",
        "holds": true,
        "detail": [
          [
            "READ",
            "db"
          ]
        ]
      },
      {
        "id": "C3",
        "invariant": "DELEGATION CANNOT INCREASE AUTHORITY",
        "holds": true,
        "detail": "delegation bounded"
      },
      {
        "id": "C4",
        "invariant": "CONSENSUS CANNOT INDEPENDENTLY CREATE AUTHORITY",
        "holds": true,
        "detail": {
          "mode": "SINGLE_AGENT",
          "votes": {
            "a": "APPROVE",
            "b": "APPROVE"
          },
          "required": 1,
          "outcome": "CONSENSUS_REACHED",
          "authorized": false,
          "authority": "NONE",
          "note": "consensus is evidence for the governance step, never authorization by itself",
          "constraints_satisfied": true,
          "requires_governance_authorization": true
        }
      },
      {
        "id": "C5",
        "invariant": "COLLECTIVE MEMBERSHIP CHANGES INVALIDATE AFFECTED STATE",
        "holds": true,
        "detail": "membership change moves the collective state root"
      },
      {
        "id": "C6",
        "invariant": "REVOKED AGENTS CANNOT EXERCISE COLLECTIVE AUTHORITY",
        "holds": true,
        "detail": "revoked member is known"
      },
      {
        "id": "C7",
        "invariant": "COLLECTIVE BUDGETS ARE CONSERVED",
        "holds": true,
        "detail": "BUDGET_CONSERVATION_VIOLATED:money=120.0>100.0"
      },
      {
        "id": "C8",
        "invariant": "COLLECTIVE CAPABILITIES ARE PROVENANCE-BOUND",
        "holds": true,
        "detail": "UNPROVEN"
      },
      {
        "id": "C9",
        "invariant": "MEMORY CANNOT CREATE COLLECTIVE AUTHORITY",
        "holds": true,
        "detail": "memory claim is not authority"
      },
      {
        "id": "C10",
        "invariant": "UNKNOWN EVIDENCE CANNOT BECOME VERIFIED AUTOMATICALLY",
        "holds": true,
        "detail": "UNKNOWN -> VERIFIED refused without evidence"
      },
      {
        "id": "C11",
        "invariant": "COLLECTIVE STATE TRANSITIONS ARE AUTHENTICATED",
        "holds": true,
        "detail": "refused"
      },
      {
        "id": "C12",
        "invariant": "COLLECTIVE TRANSACTIONS CANNOT SILENTLY BYPASS GOVERNANCE",
        "holds": true,
        "detail": "refused"
      },
      {
        "id": "C13",
        "invariant": "COMBINATION RISK IS EVALUATED BEFORE CONSEQUENTIAL COMMITMENT",
        "holds": true,
        "detail": "HIGH_RISK"
      },
      {
        "id": "C14",
        "invariant": "COLLECTIVE TRUST DEGRADATION CAN REDUCE AUTHORITY",
        "holds": true,
        "detail": 0.2
      },
      {
        "id": "C15",
        "invariant": "COLLECTIVE SELF-EVOLUTION CANNOT SELF-AUTHORIZE",
        "holds": true,
        "detail": {
          "collective_id": "coll:1",
          "kind": "new_policy",
          "detail": {},
          "requires_evolution_gate": true,
          "self_authorized": false,
          "authority": "NONE",
          "note": "collective self-improvement cannot self-grant authority"
        }
      },
      {
        "id": "C16",
        "invariant": "SYBIL IDENTITIES CANNOT MANUFACTURE TRUST AUTOMATICALLY",
        "holds": true,
        "detail": {
          "members": 100,
          "principals": 1,
          "independent_lineages": 1,
          "funding_sources": 1,
          "independent_trust_sources": 1,
          "multiplicity_ratio": 100.0,
          "multiplicity_state": "CRITICAL",
          "authority": "NONE",
          "note": "independence is counted from principal + lineage + funding, never from identity count"
        }
      },
      {
        "id": "C17",
        "invariant": "COLLECTIVE CONSENSUS IS NOT EQUIVALENT TO CAIN AUTHORIZATION",
        "holds": true,
        "detail": "CONSENSUS_REACHED"
      },
      {
        "id": "C18",
        "invariant": "EVERY CONSEQUENTIAL COLLECTIVE ACTION HAS ATTRIBUTABLE PROVENANCE",
        "holds": true,
        "detail": [
          "m"
        ]
      },
      {
        "id": "C19",
        "invariant": "DISSOLVED COLLECTIVES CANNOT EXECUTE",
        "holds": true,
        "detail": "DISSOLVED"
      },
      {
        "id": "C20",
        "invariant": "EVIDENCE RECORDS THE ACTUAL COLLECTIVE STATE USED FOR AUTHORIZATION",
        "holds": true,
        "detail": "checkpoint binds the collective state root"
      }
    ],
    "failed": [],
    "all_hold": true,
    "checked": 20
  },
  "attack_bench": {
    "bench": "CAIN-Collective-Governance-Bench",
    "attacks": {
      "delegation_laundering": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": [
          "link 1: capability/resource escalated beyond parent"
        ]
      },
      "quorum_manipulation": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "mode": "QUORUM",
          "votes": {
            "a": "APPROVE"
          },
          "required": 3,
          "outcome": "CONSENSUS_FAILED",
          "authorized": false,
          "authority": "NONE",
          "note": "consensus is evidence for the governance step, never authorization by itself",
          "constraints_satisfied": true,
          "requires_governance_authorization": true
        }
      },
      "sybil_expansion": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "members": 100,
          "principals": 1,
          "independent_lineages": 1,
          "funding_sources": 1,
          "independent_trust_sources": 1,
          "multiplicity_ratio": 100.0,
          "multiplicity_state": "CRITICAL",
          "authority": "NONE",
          "note": "independence is counted from principal + lineage + funding, never from identity count"
        }
      },
      "coordinated_privilege_escalation": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "combination_state": "HIGH_RISK",
          "triggered": [
            {
              "rule": [
                "credential_read",
                "data_read",
                "deployment_execute",
                "infrastructure_access"
              ],
              "state": "HIGH_RISK",
              "why": "exfiltration-and-deploy chain",
              "contributors": {
                "credential_read": [
                  "B:READ:cred:secrets"
                ],
                "data_read": [
                  "A:READ:db:customers"
                ],
                "deployment_execute": [
                  "D:EXECUTE:deploy:prod"
                ],
                "infrastructure_access": [
                  "C:ADMIN:infra:cluster"
                ]
              }
            }
          ],
          "sources": {
            "data_read": [
              "A:READ:db:customers"
            ],
            "credential_read": [
              "B:READ:cred:secrets"
            ],
            "infrastructure_access": [
              "C:ADMIN:infra:cluster"
            ],
            "deployment_execute": [
              "D:EXECUTE:deploy:prod"
            ]
          },
          "evaluated_before_commitment": true,
          "authority": "NONE",
          "note": "each contributing action may be individually permitted; the combination is what is judged"
        }
      },
      "harmful_action_combination": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "combination_state": "HIGH_RISK",
          "triggered": [
            {
              "rule": [
                "credential_read",
                "data_read",
                "deployment_execute",
                "infrastructure_access"
              ],
              "state": "HIGH_RISK",
              "why": "exfiltration-and-deploy chain",
              "contributors": {
                "credential_read": [
                  "B:READ:cred:secrets"
                ],
                "data_read": [
                  "A:READ:db:customers"
                ],
                "deployment_execute": [
                  "D:EXECUTE:deploy:prod"
                ],
                "infrastructure_access": [
                  "C:ADMIN:infra:cluster"
                ]
              }
            }
          ],
          "sources": {
            "data_read": [
              "A:READ:db:customers"
            ],
            "credential_read": [
              "B:READ:cred:secrets"
            ],
            "infrastructure_access": [
              "C:ADMIN:infra:cluster"
            ],
            "deployment_execute": [
              "D:EXECUTE:deploy:prod"
            ]
          },
          "evaluated_before_commitment": true,
          "authority": "NONE",
          "note": "each contributing action may be individually permitted; the combination is what is judged"
        }
      },
      "collective_memory_poisoning": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "relationship": "CLAIMS_AUTHORITY",
          "authority": "NONE"
        }
      },
      "shared_resource_abuse": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "allocated": false,
          "reason": "BUDGET_CONSERVATION_VIOLATED:money=120.0>100.0",
          "authority": "NONE"
        }
      },
      "budget_splitting": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": []
      },
      "circular_authorization": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "state": "CRITICAL",
          "reasons": [
            "CIRCULAR_APPROVAL",
            "IDENTITY_SPLITTING"
          ],
          "circular_governance": true,
          "reciprocal_authorization": false,
          "authority": "NONE"
        }
      },
      "reciprocal_delegation": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "state": "CRITICAL",
          "reasons": [
            "CIRCULAR_APPROVAL",
            "RECIPROCAL_AUTHORIZATION"
          ],
          "circular_governance": true,
          "reciprocal_authorization": true,
          "authority": "NONE"
        }
      },
      "agent_impersonation": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": [
          "PASSPORT_MISMATCH:agent_id"
        ]
      },
      "passport_substitution": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": [
          "PASSPORT_MISMATCH:runtime_composition_fingerprint"
        ]
      },
      "collective_state_rollback": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "before": "cbe90646d29ff1caf45db18ebf2ef30f3d6e1e82ecacf759219649a6e3e0dfe8",
          "after": "e0047ab9866dd4f7d64043d5fa8aa94987f71ed1fa9ae58386ad6bb0a5b1fb97"
        }
      },
      "provenance_fork": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "classification": "UNAUTHORIZED_FORK",
          "diverges": true,
          "common_prefix_ok": true,
          "branch_a": "agent:1",
          "branch_b": "agent:1",
          "authority": "NONE"
        }
      },
      "policy_fragmentation": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": []
      },
      "role_escalation": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": "a role cannot carry authority"
      },
      "coordinated_tool_poisoning": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": [
          "skill",
          "tool",
          "mcp_server",
          "permission",
          "policy",
          "authority",
          "execution_boundary"
        ]
      },
      "coordinated_mcp_abuse": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": [
          "mcp_tool:t1"
        ]
      },
      "collective_objective_drift": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "state": "SUSPICIOUS",
          "findings": [
            "collective_objective_drift"
          ],
          "certainty": "HEURISTIC",
          "authority": "NONE"
        }
      },
      "systemic_blast_radius_escalation": {
        "blocked": true,
        "state": "REFUSED",
        "evidence": {
          "individual": 0.1,
          "collective": 0.2,
          "dependency": 0.2,
          "cascading": 0.3,
          "systemic": 0.95,
          "aggregate": 0.95,
          "classification": "SYSTEMIC",
          "authority": "NONE",
          "requires_stronger_approval": true
        }
      }
    },
    "blocked": 20,
    "total": 20,
    "all_blocked": true,
    "authority": "NONE",
    "note": "each attack returns a machine-readable refusal/classification; nothing is recorded as blocked-by-proof"
  },
  "schemas": {
    "AgentCollective": {
      "fields": [
        "collective_id",
        "creator",
        "objective",
        "policy_ceiling",
        "capability_ceiling",
        "authority_envelope",
        "resource_budget",
        "parent",
        "now"
      ],
      "canonical": true
    },
    "CollectiveState": {
      "fields": [
        "membership",
        "roles",
        "active_tasks",
        "pending_proposals",
        "current_objective",
        "resource_allocation",
        "budgets",
        "trust_state",
        "risk_state",
        "shared_memory_root",
        "world_state_root",
        "trajectory_root",
        "governance_root",
        "provenance_root",
        "evidence_root",
        "lifecycle"
      ],
      "canonical": true
    },
    "CollectiveContract": {
      "fields": [
        "contract_id",
        "version",
        "objective",
        "members",
        "roles",
        "allowed_actions",
        "prohibited_actions",
        "resource_ceiling",
        "token_budget",
        "financial_budget",
        "time_limit",
        "delegation_ceiling",
        "capability_ceiling",
        "evidence_requirements",
        "termination_conditions",
        "recovery_conditions",
        "signature_b64",
        "issuer",
        "issuer_public_key_b64",
        "activated",
        "revoked",
        "activated_body"
      ],
      "canonical": true
    },
    "CollectiveRole": {
      "fields": [
        "name",
        "responsibilities",
        "authority"
      ],
      "canonical": true
    },
    "CollectiveTrustVector": {
      "fields": [
        "values"
      ],
      "canonical": true
    },
    "CollectivePassport": {
      "fields": [
        "collective_id",
        "parent_agent",
        "members",
        "delegation_tree",
        "shared_resources",
        "shared_budget",
        "capability_ceiling",
        "creator",
        "member_passport_digests",
        "membership_policy",
        "role_assignments",
        "authority_envelope",
        "objective",
        "resource_budget",
        "collective_policy",
        "formation_event",
        "provenance_root",
        "current_state",
        "version",
        "expires_at",
        "revoked",
        "signature_b64",
        "issuer",
        "issuer_public_key_b64"
      ],
      "canonical": true
    }
  },
  "limitations": [
    "TESTED library: the collective fabric is part of the L5 kernel library on the operator host; it is not a hosted orchestration service and it runs no agents.",
    "It governs collectives; it is NOT an agent framework, an orchestration framework or a message bus.",
    "Coordination volume is never treated as malicious by itself; emergent/collusion findings are HEURISTIC.",
    "Attestation is over software/configuration digests and supplied measurements, NOT hardware attestation.",
    "Sybil resistance counts independent principal + lineage + funding sources; it cannot detect a single principal that also fabricates distinct lineages and funding.",
    "Transaction guarantees cover the governed evidence/state layer only; external systems are not claimed to support rollback (compensating controls instead).",
    "No framework adapter is published, so none is described as supported.",
    "No third party has reviewed this bundle; the clean-room verifier shares no CAIN imports but was written by the same operator.",
    "Performance numbers are a single in-process run on the build host with the stated workload."
  ],
  "performance": {
    "conditions": {
      "host": "vultr",
      "machine": "x86_64",
      "processor": "",
      "cpu_count": 2,
      "python": "3.14.4",
      "os": "Linux-7.0.0-30-generic-x86_64-with-glibc2.43",
      "topology": "single process, in-process library calls",
      "workload": {
        "formation": "create a 5-member collective",
        "passport": "sign+verify a collective passport",
        "combination_risk": "4-action harmful combination",
        "coordination": "50-message coordination graph",
        "checkpoint": "bind a collective state root",
        "transaction": "full governed transaction",
        "derived_authority": "7-envelope intersection"
      },
      "samples_per_case": 2000,
      "unit": "microseconds"
    },
    "results": {
      "collective_formation": {
        "p50_us": 98.408,
        "p95_us": 214.713,
        "p99_us": 1996.651,
        "max_us": 9379.15,
        "mean_us": 167.274,
        "samples": 2000
      },
      "collective_passport_sign": {
        "p50_us": 152.146,
        "p95_us": 341.267,
        "p99_us": 2407.737,
        "max_us": 35873.972,
        "mean_us": 258.58,
        "samples": 2000
      },
      "collective_passport_verify": {
        "p50_us": 162.071,
        "p95_us": 1270.565,
        "p99_us": 4023.487,
        "max_us": 14726.109,
        "mean_us": 339.261,
        "samples": 2000
      },
      "combination_risk_eval": {
        "p50_us": 4.34,
        "p95_us": 5.105,
        "p99_us": 13.845,
        "max_us": 1662.742,
        "mean_us": 6.498,
        "samples": 2000
      },
      "coordination_graph": {
        "p50_us": 11.545,
        "p95_us": 12.658,
        "p99_us": 22.128,
        "max_us": 1951.98,
        "mean_us": 14.301,
        "samples": 2000
      },
      "collective_authorization": {
        "p50_us": 3.785,
        "p95_us": 4.169,
        "p99_us": 8.748,
        "max_us": 932.549,
        "mean_us": 4.465,
        "samples": 2000
      },
      "revocation_propagation": {
        "p50_us": 9.038,
        "p95_us": 14.112,
        "p99_us": 37.235,
        "max_us": 2078.494,
        "mean_us": 14.26,
        "samples": 2000
      },
      "checkpoint_create": {
        "p50_us": 35770.372,
        "p95_us": 93457.863,
        "p99_us": 148879.041,
        "max_us": 422850.375,
        "mean_us": 44930.065,
        "samples": 2000
      },
      "collective_transaction": {
        "p50_us": 12.591,
        "p95_us": 19.353,
        "p99_us": 53.061,
        "max_us": 6037.757,
        "mean_us": 19.938,
        "samples": 2000
      }
    },
    "note": "single host, single operator, in-process; not a production benchmark; no extrapolation"
  },
  "environment_class": "operator host, single process, pre-production",
  "laws": [
    "ONE TRUSTED AGENT DOES NOT CREATE A TRUSTED COLLECTIVE",
    "CONSENSUS DOES NOT EQUAL AUTHORIZATION",
    "COLLECTIVE AUTHORITY MUST BE DERIVED, NEVER INVENTED",
    "COLLECTIVE BUDGETS MUST BE CONSERVED",
    "SYBIL IDENTITIES MUST NOT MANUFACTURE TRUST",
    "COLLECTIVE SELF-EVOLUTION MUST NOT SELF-AUTHORIZE",
    "UNKNOWN MUST REMAIN UNKNOWN"
  ],
  "evidence_level": "TESTED",
  "signer_public_key_b64": "Cn1rpN1m01j0czb3AcL1aqUVEzYNSSWhqceVSGYouBY=",
  "signature_b64": "hYkU6Aw9omCqL/DtY1go05ruv63dJZyr2GpPMHSDWDmyzGiFezw5Wng2C2SEebFWsjbYa2DuT2ASKhj6WoyYDA=="
}
