CAIN-42 Evolution #6: authority leases on the LIVE CAIN-42 PBFT cluster, 2026-09-28T03:25:07Z.

What happened (all of it is in this bundle):
  - A real production CAIN decision (POST https://cainstudio.online/fabric/try, demo tenant) came back
    REQUIRE_APPROVAL, quorum-certified by cain-mr-01 (4 nodes, 4 regions, f=1, quorum 3).
  - For each of 9 lease conditions, a fresh CAIN-45 ZoD (the agent's authority lease) was authorized by the
    live cluster cain-mr-01, with an operator approval. One tool call then SUCCEEDED under that authority.
  - The condition was then tripped, and the next call was REFUSED and the tool did not run:
      lease TTL expires | trust falls below the floor | agent identity changes (model swapped)
      tool schema changes after authorization (rug-pull) | security context changes
      trajectory fork / substitution | explicit revocation | required evidence disappears
      delegating parent quarantined (the child ZoD loses its authority too)
  - Every authorization's quorum certificate (3 of 4 Ed25519 node signatures) is in qcs.json. Every
    step is in a hash-chained evidence log signed by that run's hypervisor.

Verify in seconds (Python 3.8+, pip install cryptography, no CAIN code):
  B=https://clawx.click/evidence/e6-live-lease-2026-09-28
  for f in LEASE_RUN.json EVIDENCE_CHAINS.json decision.json qcs.json membership.json; do curl -so $f "$B/$f"; done
  for v in verify_e6_lease verify_pbft_qc_bundle; do curl -so $v.py "$B/$v.py.txt"; done
  python3 verify_e6_lease.py .
  Expect "48/48 checks" and VERIFIED. Edit any certificate, evidence entry, refusal reason, sequence, quorum
  signature or any field of a result row (they are hypervisor-signed and cross-checked against the chain)
  and it prints NOT VERIFIED. The same QCs can be fetched live:
  GET https://cainstudio.online/api/v1/live-cluster/qc/<sequence>

Status: LIVE-CLUSTER-VERIFIED for the authority on these 9 conditions. For 8 of them the refusal is derived
from the signed evidence chain. For "required evidence disappears" it is SELF-REPORTED: the log was deleted,
so the refusal rests on a result row signed by the hypervisor key, not on an outside observation. The invalidation checks run in the
CAIN-45 hypervisor (a library on the gateway host, operator-run), not inside the cluster nodes.

Not covered (stated, not hidden): invalidation on policy change, epoch change, membership change, risk-budget
or blast-radius-budget exhaustion (no mechanism exists yet). The tool-schema case is refused by the
"exactly one registered tool identity" rule. The tool server is a sandbox key-value store, and the tenant is
the demo tenant, not a customer. One writer per evidence database. Production status: PRE-PRODUCTION.
