# CAIN-42 Evolution 15 — Reference Architecture
## Spatial + Physical Autonomous Intelligence Fabric

Status: **TESTED library, PRE-PRODUCTION.** Implementation: `cain45/l5/spatial_physical.py` (exported from
`cain45/l5/__init__.py`). Tests: `tests/test_cain42_e15_{spatial_physical,adversarial,end_to_end,verifier}.py`.
Clean-room verifier: `scripts/cain45/verify_e15.py`. Evidence:
`clawx-site/evidence/e15-spatial-physical-intelligence-2026-09-28/` (mirrored byte-identically to
`platform-gateway/frontend/proof/bundle/`). CLI: `bin/cain-agent {spatial,world,observation,trajectory,scenario,
simulation,digital-twin,actuator,reality-drift,counterfactual,sensor,safe-state,physical ...}`, `bin/cain-l5 e15-*`.

**CAIN-42 does not become the world model.** E15 is the governance layer between what an autonomous system perceives,
believes, proposes, can do, may cause, is authorized to do, and what the physical world then shows. It is not a
vehicle, a robot, a world model, a simulator or a physical-AI model, it drives nothing, and it does not guarantee
physical safety. The reference robot adapter and kinematic simulator shipped here are test doubles.

### One governed path for DIGITAL, PHYSICAL and HYBRID systems

```
IDENTITY ─ EmbodiedSystem (identity + provenance digests; embodiment → domain, never inferred)
   ↓
PERCEPTION ─ signed SpatialObservation → SensorRegistry (identity, type, key, replay, E12 freshness)
   ↓                                      → E12 ObservationEnvelope (ATTESTED — attested, not true)
EVIDENCE ─ SpatialEntityIdentityRegistry (continuity) → SpatialWorldState (versioned, hash-chained)
   ↓        CrossModalConsistencyEngine (CONSISTENT / INCONSISTENT / DEGRADED / AMBIGUOUS / UNKNOWN)
COGNITION / DECISION ─ E13 effective_authority (intersection of envelopes, never a sum)
   ↓
CAPABILITY ─ E14 effective_capability ∩ SpatialCapabilityBoundary (WHERE / WHEN / UNDER WHAT CONDITIONS)
   ↓          and boundary ⊆ PhysicalAuthorityScope
SPATIAL STATE ─ world authorizable? (fresh, consistent, not invalidated, approved map)
   ↓
TRAJECTORY ─ GovernedTrajectory (a PROPOSAL) → TrajectoryGovernanceEngine → signed TrajectoryApproval
   ↓
CONSEQUENCE ─ PhysicalConsequenceVector → physical limits + E7 gate (unmeasured = worst case)
   ↓
AUTHORIZATION ─ ContinuousPhysicalAuthorization step (signed, single-use, ≤5 s, nine bindings)
   ↓              + E8 GovernanceAuthorizationToken over a CanonicalAction that embeds the nine bindings
EXECUTION ─ PhysicalCommitBoundary: strict live re-check → E8 authorize + commit → ExecutionPermit (≤2 s, one command)
   ↓          → GovernedActuator adapter contract (the only path to an actuator)
OBSERVATION ─ new signed observations → SpatialRealityDriftEngine → revalidate: CONTINUE / REAUTHORIZE / MODIFY / STOP
   ↓
EVIDENCE ─ physical + E8 evidence chains, provenance graph (sensor → … → outcome), reality feedback chain
```

A DIGITAL agent takes the same path with SPATIAL STATE and TRAJECTORY recorded `NOT_APPLICABLE` (never faked) and
executes through the E8 `ActionCommitBoundary.execute`; it cannot register or command an actuator. A HYBRID agent does
both, on one system identity. `architecture_convergence()` runs all three and records each stage's real digest.

### Components (all in `cain45/l5/spatial_physical.py`)

| Spec part | Object | What it does |
|---|---|---|
| 1 | `PhysicalIntelligenceFabric`, `EmbodiedSystem`, `EmbodiedSystemAdapter` | DIGITAL/PHYSICAL/HYBRID domains, registration, orchestration; domain logic lives in adapters |
| 2, 7 | `SpatialWorldState` (spec name `GovernedWorldState`), `WorldStateProvenanceGraph` | versioned, timestamped, hash-chained, replayable, invalidatable world state; projects into the E7 `GovernedWorldState` via `to_e7()`; provenance edges only go forward (sensor → … → outcome) |
| 3 | `SpatialTemporalState`, `Vec3` | X/Y/Z/TIME + velocity, acceleration, orientation, uncertainty; OBSERVED / INFERRED / PREDICTED / SIMULATED / UNKNOWN never collapsed |
| 4 | `SensorEvidence`, `SpatialObservation`, `SensorRegistry` | abstract sensor sources; signed by a registered adapter key; admitted through E12 |
| 5 | `CrossModalConsistencyEngine` | camera/lidar, GNSS/IMU, map/sensor, world-model/raw conflicts; only CONSISTENT can authorize |
| 6 | `SpatialEntityIdentity(Registry)` | continuity, classification-flip and teleport detection, merge / split / revoke, chained ops |
| 8 | `SpatialRealityDriftEngine` | extends the E12 `RealityDriftEngine`; ten drift classes; materiality is policy |
| 9, 10 | `GovernedWorldModel`, `WorldModelRegistry`, `WorldModelOutput` | external model interface; outputs are PREDICTED, CAIN-signed binding to model/config/world/scenario/time |
| 11–13 | `GovernedTrajectory`, `TrajectoryGovernanceEngine`, `TrajectoryPredictionGraph` | proposal → APPROVE / DENY / MODIFY / DEFER / REQUIRE_REEVALUATION / SAFE_STATE / UNKNOWN |
| 14–16 | `PhysicalConsequenceVector`, `PhysicalBlastRadiusEngine`, `PhysicalCounterfactualEngine` | extend E7; UNKNOWN where not measurable; counterfactuals are SIMULATED |
| 17 | `ContinuousPhysicalAuthorization` | AUTHORIZE → LIMITED STEP → OBSERVE → REVALIDATE → CONTINUE / REAUTHORIZE / MODIFY / STOP |
| 18 | `SpatialCapabilityBoundary`, `PhysicalAuthorityScope` | geographic, temporal, environmental, speed/energy, risk, system-state boundaries; ⊆ authority; delegation narrows |
| 19 | `GovernedSafeState` | STOP / HOLD / DISENGAGE / DEGRADE / RETURN / ISOLATE / WAIT_FOR_HUMAN / WAIT_FOR_REAUTHORIZATION; semantics from the adapter or UNKNOWN |
| 20, 21 | `GovernedActuator`, `ActuatorCommand`, `ExecutionPermit`, `PhysicalActionCommit`, `PhysicalCommitBoundary` | the actuator boundary and the E8 extension |
| 22–24 | `GovernedSimulationEnvironment`, `GovernedDigitalTwin`, `SimulationRealityGapEngine` | signed SIMULATED evidence; simulated vs observed delta; LOW / MODERATE / HIGH / UNKNOWN gap |
| 25, 26 | `PhysicalScenario`, `ScenarioMutationEngine`, `PhysicalAdversarialScenario` | provenance-linked scenario lineage; red-team definitions (real-world validation NOT_PERFORMED) |
| 27 | `RealityFeedbackFabric` | append-only chain; corrections supersede, never rewrite |
| 28 | `PhysicalHumanAuthority` | signed, scoped, single-use human acts; two-person override; restriction-only e-stop; audit chain |
| 29 | `EmbodiedSystemHealth` | seven dimensions; strictest action wins; stale or unreported = UNKNOWN |
| 30 | `EmbodiedAutonomyStateMachine` | legal transitions only; AUTHORIZED needs governance + an authorization record |
| 31, 32 | `check_e15_invariants`, `spatial_physical_attack_bench` | P1–P36; 55 scenarios |
| 41, 44 | `end_to_end_demo`, `architecture_convergence` | 19-step run + 7 mutations; digital/physical/hybrid convergence |

### How E15 extends the existing stack (no parallel layers)

- **E7**: `PhysicalConsequenceVector.to_e7()` feeds `consequence_governance.consequence_vector`; `govern()` runs the E7
  `gate`. `SpatialWorldState.to_e7()` projects every real component into the E7 `GovernedWorldState`.
- **E8**: `PhysicalActionCommit.to_canonical_action()` puts the nine digests into the `CanonicalAction` (so the E8 action
  hash commits to them) and into its roots; the fabric issues a standard `GovernanceAuthorizationToken`; the
  `ActionCommitBoundary` authorizes, re-checks at commit and spends the token. E15 always supplies every E8 root
  (`e8_current`), so E8's "absent = unchanged" leniency never applies to a physical action. Emergency stops use E8
  `EmergencyControls`; two-person override uses E8 `MultiPartyAuthorization` after E15 verifies each signature.
- **E12**: every sensor observation becomes an E12 `ObservationEnvelope` and passes E12 `freshness`; drift extends E12
  `RealityDriftEngine`; memory classification uses E12 `classify_memory`.
- **E13**: authority is `decision.effective_authority` over the envelopes plus the request; human delegation uses
  `reasoning_cannot_increase_authority`.
- **E14**: capability is `capability.effective_capability` over the eight E14 envelopes, then narrowed by the spatial
  boundary.

### Mapping to the canonical 7-moat doctrine (extends existing moats; creates none)

| Moat | E15 contribution |
|---|---|
| #2 Security-context continuity | spatial identity continuity; sensor identity; tenant checks on every object |
| #4 Execution provenance & attestation | world-state history chain, provenance graph to outcome, nine-binding commit, permit, evidence chains (software keys; hardware attestation UNKNOWN) |
| #5 Predictive trust & blast radius | trajectory prediction graph, physical consequence vector, physical blast radius, counterfactuals, sim-to-real gap |
| #7 Autonomous trust control loop | continuous physical authorization, drift → invalidation → re-evaluation / safe state, reality feedback |

`docs/architecture/CAIN-7-MOATS.md` is unchanged: it is owner-reviewed, and E7–E14 did not edit it either. Adding the
row above is a proposal for the project owner.

### Verification and reproduction

```
python3 -m pytest tests/test_cain42_e15_spatial_physical.py tests/test_cain42_e15_adversarial.py \
                  tests/test_cain42_e15_end_to_end.py tests/test_cain42_e15_verifier.py -q
bin/cain-agent physical audit          # P1..P36
bin/cain-agent physical bench          # CAIN-42-E15-Spatial-Physical-Bench
bin/cain-l5 e15-simulate               # the 19-step end-to-end run + 7 mutations
python3 scripts/cain45/build_evolution15_bundle.py
python3 clawx-site/evidence/e15-spatial-physical-intelligence-2026-09-28/verify_e15.py.txt \
        clawx-site/evidence/e15-spatial-physical-intelligence-2026-09-28     # no CAIN imports
```

### Limitations (see LIMITATIONS.md in the bundle)

Real sensor / vehicle / robot / actuator integration: NOT_IMPLEMENTED. Hardware attestation: UNKNOWN. Multi-host:
UNVERIFIED. Large-scale simulation: NOT_IMPLEMENTED. World-model accuracy, semantic truth, sim-to-real fidelity:
UNKNOWN. Third-party reproduction and real-world attack validation: NOT_PERFORMED. Vulnerability intelligence:
UNKNOWN. Hosted E15 service: NOT_IMPLEMENTED. Systems outside the enforcement boundary: UNCONTROLLED / UNVERIFIED /
UNKNOWN. E15 alone does not achieve the E42 direction.
