# CAIN-42 Evolution 15 — Spatial & Physical Governance
## How the world state, trajectories, simulation and physical actions are governed

**Laws** (each is an executable invariant): perception is not truth · model output is not authority · simulation is
not reality · prediction is not fact · capability is not authority · a trajectory is a proposal until governed · a
physical action requires governed authorization · unknown never becomes allow · outside the enforcement boundary:
UNCONTROLLED / UNVERIFIED / UNKNOWN.

### Digital, physical, hybrid

`EmbodiedSystem.system_type` follows from the embodiment (vehicle, robot, drone, industrial machine, warehouse system,
smart space → PHYSICAL; digital agent → DIGITAL; hybrid agent → HYBRID); a mismatch is refused. Only PHYSICAL and
HYBRID systems get a world state and actuators. The fabric keeps no vehicle or robot logic: safe-state semantics,
actuation and sensing come from an `EmbodiedSystemAdapter` the integrator supplies.

### World-state model (spatial + temporal)

- Components are `SpatialTemporalState`s: position/velocity/acceleration/orientation/uncertainty at a timestamp, a
  kind (object, agent, obstacle, infrastructure, terrain, road geometry, lane, boundary, zone, destination), a
  classification, provenance (the observation digest) and a fact layer.
- Only OBSERVED and INFERRED describe the current world. PREDICTED and SIMULATED states are kept beside it, tagged;
  UNKNOWN is neither.
- Every mutation (ingest, apply, relationship, environment, map, consistency, invalidate, revalidate) bumps the
  version, appends a hash-chained history entry holding the resulting state digest, and appends a replayable log op.
  Time never goes backwards, for the world or per sensor or per component.
- The digest binds components, relationships, environment, map digest, consistency, invalidation and an
  `observation_root` over every ingested observation.
- `is_authorizable` requires: not invalidated, fresh (dynamic components too), CONSISTENT, and an approved map.
  `revalidate` requires fresh consistent evidence ingested after the invalidation.
- `to_e7()` projects the real components into the E7 `GovernedWorldState`.

### Sensors and consistency

Sensors register (id, type, source identity, public key, system, tenant) once; re-registration is refused. Admission
checks registration, revocation, type/source match, signature, replay, integrity state, E12 freshness (future-dated,
clock-conflicted, expired) and per-sensor monotonic time, then emits an E12 `ObservationEnvelope` marked ATTESTED.
Consistency compares observations of the same entity across *different* sensor families (presence, location,
classification, world-model claim vs raw) and flags stale/degraded inputs and missing required modalities.

### Trajectories

`GovernedTrajectory` carries origin, path, destination, one timestamp per point, velocity/acceleration profiles,
predicted interactions, constraints, confidence, uncertainty, source model and bindings. Its digest excludes the
informational `authorization_state`; authority lives only in a fabric-signed `TrajectoryApproval` bound to the
trajectory digest and world-state digest. The engine checks, in order: required inputs (else UNKNOWN), timing coverage
and monotonicity, end time, past start (allowed only as a continuation of the current, unrevoked plan), world
authorizability, tenant, authority, capability, policy, obstructions within clearance, conflicts and forks with other
live approvals, declared-vs-implied speed, speed cap (MODIFY proposes a slower new trajectory), uncertainty (DEFER),
consequence, environment and system health (SAFE_STATE). It never falls through to APPROVE.

### World-model and simulation interfaces

External world models register (id, version, model/config/artifact digests, provenance, evaluation evidence,
deployment state). Their outputs must be PREDICTED; CAIN signs a binding to model version, model digest, config
digest, world-state digest, scenario digest and timestamp; any change forces REVALIDATE. External simulators register
(id, version, digest); each run records scenario, environment, world state, model versions, policy version, actions,
trajectory, outcome and failures, signed by CAIN and marked SIMULATED with `proves_real_world_safety: false`. The digital
twin holds observed, simulated, model and expected layers side by side and reports `simulation_reality_delta` only
where both exist. The sim-to-real gap engine classifies LOW / MODERATE / HIGH / UNKNOWN.

### Physical consequences

`PhysicalConsequenceVector` holds collision, human, environmental, infrastructure, financial and operational exposure,
persistence, propagation, reversibility, uncertainty, time-to-impact, affected entities and spatial extent. A dimension
not supplied is UNKNOWN and scored as worst case. `govern()` applies the physical limits and the E7 gate (E7 STEP_UP →
human approval required; DENY → refusal). The blast-radius engine reports footprint, duration, affected entities,
humans in the footprint and downstream systems, or UNKNOWN for all of them when the world state is stale or invalid.
Counterfactual alternatives (CONTINUE, STOP, SLOW, YIELD, REROUTE, WAIT, CHANGE_TRAJECTORY, SAFE_STATE) are SIMULATED;
without a predictor every alternative is UNKNOWN and nothing is recommended.

### Continuous authorization and the actuator boundary

1. APPROVE → the fabric issues one `PhysicalAuthorizationStep` (signed, ≤5 s, single use, scope-limited) bound to the
   nine live digests and the world-state version, and an E8 token for a `CanonicalAction` that embeds them.
2. `execute` recomputes all nine bindings from the live objects, checks the step, runs E8 authorize and commit (token
   spend), consumes the step, and issues an `ExecutionPermit` (≤2 s) for exactly one command digest.
3. `GovernedActuator.submit` accepts only that permit, once, for that command, within limits, in a nominal safety
   state; the adapter's result becomes signed-over evidence.
4. `observe` ingests new observations, runs drift detection against the expected world and the planned trajectory,
   and revalidates: CONTINUE, REAUTHORIZE (state advanced; decide the next step), MODIFY (the trajectory must change)
   or STOP (material drift, health, expiry, unknown → invalidate world, revoke approvals and steps, adapter safe state
   WAIT_FOR_REAUTHORIZATION).
5. A refused commit invalidates the plan (approval + steps revoked, system UNCERTAIN): the only way forward is a fresh
   governed decision.

### Humans, health, state machine

Human acts are Ed25519-signed over (act, human, subject, operation, resource, reason, time, nonce), checked for role,
scope (E13 intersection), freshness and replay, and audited in a hash chain. Health is reported per dimension; policy
maps levels to CONTINUE / LIMIT (halves the speed cap) / REQUIRE_REAUTHORIZATION / PAUSE / REVOKE, and the health action
is bound into the risk digest. The autonomy state machine only lets AUTHORIZED be entered from governance with an
authorization record, and only AUTHORIZED can execute.

### Status of every capability

See `CAPABILITY_STATUS` in the module (and `status.capability_status` in the signed proof): the library components are
TESTED; counterfactuals, the reference simulator and red-team definitions are SIMULATED; real adapters and a hosted
service are NOT_IMPLEMENTED; systems outside the boundary are UNCONTROLLED.
