CAIN-45 Evolution 1: a ZoD (Zone of Decision) authorized by the live CAIN-42 PBFT cluster, 2026-09-27T22:48:12Z.

What happened, all of it recorded in this bundle:
  - A real production CAIN decision (POST https://cainstudio.online/fabric/try, demo tenant) came back
    REQUIRE_APPROVAL, quorum-certified by cain-mr-01 at sequence 13377.
  - Two ZoDs for two instances of one agent were created, attested (software measurement) and approved by a
    registered HUMAN identity (the run's operator approver; its public key is in ZOD_RUN.json).
  - Each ZoD's authorization was ordered by the live cluster cain-mr-01 (sequences 13379 and
    13380); the hypervisor accepted it only after verifying the commit certificate itself.
  - Code ran inside ZoD 1 under real confinement (bubblewrap namespaces + cgroup v2) and probed its own
    boundary: uid 65534, pid 2, egress "Network is unreachable", host source tree invisible, /usr read-only.
  - A tool call went through CAIN's real MCPGate interceptor to a sandbox key-value tool server.
  - 10 attacks were refused, each with a signed DENIED entry: authorize on a REQUIRE_APPROVAL decision without a human approval; use instance-001's grant inside instance-002's ZoD; grant a capability outside the ZoD's set; call a tool outside the ZoD's tool set; forged grant (capability rewritten after signing); act without presenting the security context; child ZoD asking for more than its parent; use a terminated ZoD's grant; security-context substitution (model swapped mid-run); revalidate with the substituted context.
    Both ZoDs were terminated. 45 evidence entries, hash-chained and signed.

Verify (Python 3.8+, pip install cryptography, no CAIN code):
  B=https://clawx.click/evidence/cain45-zod-live-2026-09-27
  for f in ZOD_RUN.json EVIDENCE_CHAIN.json decision.json qcs.json membership.json approval.json; do curl -so $f "$B/$f"; done
  for v in verify_cain45_zod verify_pbft_qc_bundle; do curl -so $v.py "$B/$v.py.txt"; done
  python3 verify_cain45_zod.py .
  Expect 10 PASS lines and VERIFIED. Edit any certificate, evidence entry, decision, approval or quorum
  signature and it prints NOT VERIFIED. The quorum certificates can also be fetched live:
  GET https://cainstudio.online/api/v1/live-cluster/qc/<sequence>.

Not established in Evolution 1 (stated, not hidden):
  - seccomp syscall filtering; allowlisted network egress (only deny-all exists, and a ZoD asking for any
    egress destination is refused); hardware-backed attestation (software measurement only, no TPM/TEE here);
    break-glass; a trust/risk-aware scheduler
  - the hypervisor as a deployed service in front of customer agents: this run used it as a library on the
    gateway host, operator-run. The approval is the operator's, not a customer's. The CAIN decision is a
    public demo decision (its trust stage was "unknown", hence REQUIRE_APPROVAL).
  - the tool server is a sandbox; no customer system was touched.
