TESTED PRE-PRODUCTION no third-party review
Governs the behaviour of agent collectives: formation, membership, roles, contracts, budgets, combination risk, emergent behaviour, collusion, Sybil resistance, collective memory and epistemic state, trust, decisions, transactions, revocation and incident response. ONE TRUSTED AGENT DOES NOT CREATE A TRUSTED COLLECTIVE. CONSENSUS DOES NOT EQUAL AUTHORIZATION.
============================== 47 passed in 0.76s ==============================.| # | Invariant | Result |
|---|---|---|
| C1 | COLLECTIVE AUTHORITY NEVER EXCEEDS POLICY CEILING | HOLDS |
| C2 | COLLECTIVE AUTHORITY NEVER EXCEEDS MEMBER AUTHORITY ENVELOPE | HOLDS |
| C3 | DELEGATION CANNOT INCREASE AUTHORITY | HOLDS |
| C4 | CONSENSUS CANNOT INDEPENDENTLY CREATE AUTHORITY | HOLDS |
| C5 | COLLECTIVE MEMBERSHIP CHANGES INVALIDATE AFFECTED STATE | HOLDS |
| C6 | REVOKED AGENTS CANNOT EXERCISE COLLECTIVE AUTHORITY | HOLDS |
| C7 | COLLECTIVE BUDGETS ARE CONSERVED | HOLDS |
| C8 | COLLECTIVE CAPABILITIES ARE PROVENANCE-BOUND | HOLDS |
| C9 | MEMORY CANNOT CREATE COLLECTIVE AUTHORITY | HOLDS |
| C10 | UNKNOWN EVIDENCE CANNOT BECOME VERIFIED AUTOMATICALLY | HOLDS |
| C11 | COLLECTIVE STATE TRANSITIONS ARE AUTHENTICATED | HOLDS |
| C12 | COLLECTIVE TRANSACTIONS CANNOT SILENTLY BYPASS GOVERNANCE | HOLDS |
| C13 | COMBINATION RISK IS EVALUATED BEFORE CONSEQUENTIAL COMMITMENT | HOLDS |
| C14 | COLLECTIVE TRUST DEGRADATION CAN REDUCE AUTHORITY | HOLDS |
| C15 | COLLECTIVE SELF-EVOLUTION CANNOT SELF-AUTHORIZE | HOLDS |
| C16 | SYBIL IDENTITIES CANNOT MANUFACTURE TRUST AUTOMATICALLY | HOLDS |
| C17 | COLLECTIVE CONSENSUS IS NOT EQUIVALENT TO CAIN AUTHORIZATION | HOLDS |
| C18 | EVERY CONSEQUENTIAL COLLECTIVE ACTION HAS ATTRIBUTABLE PROVENANCE | HOLDS |
| C19 | DISSOLVED COLLECTIVES CANNOT EXECUTE | HOLDS |
| C20 | EVIDENCE RECORDS THE ACTUAL COLLECTIVE STATE USED FOR AUTHORIZATION | HOLDS |
| Attack | Result |
|---|---|
| delegation_laundering | REFUSED |
| quorum_manipulation | REFUSED |
| sybil_expansion | REFUSED |
| coordinated_privilege_escalation | REFUSED |
| harmful_action_combination | REFUSED |
| collective_memory_poisoning | REFUSED |
| shared_resource_abuse | REFUSED |
| budget_splitting | REFUSED |
| circular_authorization | REFUSED |
| reciprocal_delegation | REFUSED |
| agent_impersonation | REFUSED |
| passport_substitution | REFUSED |
| collective_state_rollback | REFUSED |
| provenance_fork | REFUSED |
| policy_fragmentation | REFUSED |
| role_escalation | REFUSED |
| coordinated_tool_poisoning | REFUSED |
| coordinated_mcp_abuse | REFUSED |
| collective_objective_drift | REFUSED |
| systemic_blast_radius_escalation | REFUSED |
What this does not show: semantic certainty (emergent/collusion findings are HEURISTIC); hardware attestation; detection of a single principal that also fabricates distinct lineages and funding; external-system rollback; or any third-party review.
Signer (ephemeral): Cn1rpN1m01j0czb3AcL1aqUVEzYNSSWhqceVSGYouBY=