CAIN-42 Evolution #7: authority lapses on policy, cluster membership/epoch and risk/blast-radius budgets -- on authority from the LIVE CAIN-42 cluster cain-mr-01, 2026-09-28T03:37:45Z. Evolution #6 (e6-live-lease-2026-09-28) showed 9 lease conditions. It listed 5 it did not implement: policy change, epoch change, membership change, risk budget, blast-radius budget. This run covers them. Each case: a fresh CAIN-45 hypervisor; a ZoD whose authorization the live cluster ordered (quorum certificate, 3 of 4 Ed25519 signers, checked by the hypervisor itself and again by the verifier below); one tool call that succeeds; then the condition is tripped and the next call is refused, with the tool never running. policy root changes REAL the policy root the ZoD was authorized under is replaced policy source unreadable REAL the policy source fails; unknown is refused, never "unchanged" risk budget exhausted REAL risk_budget=1 (consequential actions); the 2nd call is refused blast-radius budget exhausted REAL blast_radius_budget=1; a CALL_MCP_TOOL is class C1, weight 1 delegate exhausts its parent's budget REAL a child's calls are charged to its parent too; once the parent's budget is spent the child is refused, although its own budget is not -- splitting work across delegates cannot multiply authority cluster epoch changes INJECTED cluster membership changes INJECTED } the live cluster was NOT re-keyed (that would mean cluster membership cannot be established INJECTED / re-keying production); the hypervisor's view of the membership was replaced after authorization What is live about membership: at authorization every ZoD binds the cluster's real configuration -- its hash is recomputed by the hypervisor from the membership body, and at least a quorum of replicas must report exactly that hash -- and the hypervisor re-reads it from the cluster before every action (see live_membership_reads in LEASE_RUN.json). The verifier recomputes the same hash from membership.json and checks that every ZoD certificate and every commit QC in this bundle carry it. Verify (Python 3.8+, pip install cryptography, no CAIN code): B=https://clawx.click/evidence/e7-lease-2026-09-28 for f in LEASE_RUN.json EVIDENCE_CHAINS.json decision.json qcs.json membership.json; do curl -so $f "$B/$f"; done for v in verify_e7_lease verify_pbft_qc_bundle; do curl -so $v.py "$B/$v.py.txt"; done python3 verify_e7_lease.py . Expect 60/60 checks and VERIFIED. The same files are at https://cainstudio.online/proof/bundle/e7-lease-2026-09-28/ and https://mcpgate.online/proof/bundle/e7-lease-2026-09-28/. Tampering is caught: a result row that disagrees with its signed chain, a lowered budget in a certificate, a swapped membership binding, or a deleted refusal each give NOT VERIFIED. The quorum certificates can be fetched live: GET https://cainstudio.online/api/v1/live-cluster/qc/. Not established here (stated, not hidden): - a real membership or epoch change on the live cluster (INJECTED above) - enforcement ON the cluster nodes: the lapse logic is the hypervisor library on the gateway host; the cluster supplies the authority that lapses - budgets for anything but CALL_MCP_TOOL in this run (the classes C0-C4 are implemented and unit-tested) - customer traffic: demo tenant, sandbox tool server, operator approval key generated for the run