{"scenarios":[{"id":"safe-read","title":"A reasonable action","explains":"A normal tool call with a declared intent, from a principal with no trust history yet. Policy and risk both pass, but unknown trust never becomes ALLOW on its own: the action is held for human approval.","expect":"REQUIRE_APPROVAL"},{"id":"prompt-injection","title":"A prompt-injection payload","explains":"The same call, carrying text that tries to override the agent's instructions. The RISK stage screens the payload and denies it.","expect":"denied by risk"},{"id":"malformed-plan","title":"A plan that cannot be reasoned about","explains":"A plan whose steps name no tool. VERIFICATION catches it before ActionProof is asked to prove anything about it -- a malformed plan returning 'nothing to prove' would read as a pass.","expect":"denied by verification"},{"id":"mission-inside","title":"An agent acting inside its signed mission (E38)","explains":"The call declares an owner-signed mission and the goal chain OBJECTIVE -> SUBGOAL -> PLAN -> ACTION that leads to it. The MISSION stage checks the signature and that every step attenuates its parent; this read stays inside the mission, so MISSION allows it (other stages still decide).","expect":"mission: allow"},{"id":"mission-escalation","title":"An agent trying to exceed its mission (E38)","explains":"Same signed mission (read inventory, low risk). The agent asks to WRITE inventory and cites a predicted reward of 1,000,000 and 99% confidence. Optimization cannot create authority: the MISSION stage refuses the call and the decision is BLOCKED.","expect":"BLOCKED by mission"},{"id":"horizon-inside","title":"An action inside an uncertainty-contracted horizon (E7)","explains":"A $5,000 write under a policy allowing 10 steps and $20,000 before re-authorization. CAIN has never seen this tool's outcomes, so uncertainty is 0.5 and the horizon contracts to 5 steps and $10,000. This write fits, so CONSEQUENCE allows it (other stages still decide).","expect":"consequence: allow"},{"id":"horizon-exhausted","title":"An action outside the contracted horizon (E7)","explains":"Same policy, a $15,000 write: inside the nominal $20,000 budget, but outside the $10,000 the horizon contracts to under uncertainty 0.5. Uncertainty contracts authority, never expands it: CONSEQUENCE refuses the call and requires re-authorization.","expect":"BLOCKED by consequence"},{"id":"governance-program-allowed","title":"A call governed by a quorum-certified GOV-IR program (E15)","explains":"The call carries a GOV-IR program proof: a governance program approved by 2 of 3 constitutional authorities and activated by a 4-replica Byzantine quorum, evaluated against quorum-certified governance state. The GOVERNANCE stage verifies both quorum certificates, re-executes the program byte-for-byte and checks it governs exactly this tool and these arguments: ALLOW (other stages still decide).","expect":"governance: allow"},{"id":"governance-program-reauth","title":"A governed call without its quorum-issued lease (E15)","explains":"Same program, same agent, same tool, but the agent has no lease from the governance quorum. The program's LEASE_CHECK sends it to REAUTH; a governance program can narrow, never grant, so the GOVERNANCE stage refuses the call and the decision is BLOCKED.","expect":"BLOCKED by governance"},{"id":"prediction-inside","title":"An action independent models predict is safe (E16)","explains":"A $100 treasury transfer. Two registered models of different lineage, each of which earned VALIDATED trust from reconciled outcomes, sign predictions bound to a quorum-certified world root. Both predict the treasury stays above its $100,000 floor with low uncertainty, so the PREDICTION stage allows it (other stages still decide). Prediction is never authority.","expect":"prediction: allow"},{"id":"prediction-outside","title":"An action the models predict breaks the safety envelope (E16)","explains":"Same world, same models, a $950,000 transfer. Both models predict the treasury falls below its $100,000 floor. A prediction can only restrict: the PREDICTION stage refuses the call and the decision is BLOCKED.","expect":"BLOCKED by prediction"},{"id":"autonomy-certified","title":"An agent acting under its signed autonomy certificate and lease (L5)","explains":"The call carries a signed autonomy certificate binding one exact agent configuration (identity, model, policy, tools) to a 12-dimension autonomy vector, plus a 60-second lease for this tool. The configuration matches and execution autonomy is L3, so AUTONOMY allows it (other stages still decide). An autonomy level is never authority.","expect":"autonomy: allow"},{"id":"autonomy-substituted","title":"Same agent key, swapped model: a different agent (L5)","explains":"Same certificate, same lease, same key, but the agent is now running an unreviewed model version. The certificate binds the exact configuration, so this is a different agent: the AUTONOMY stage refuses the call and the decision is BLOCKED.","expect":"BLOCKED by autonomy"},{"id":"federation-inside","title":"A call from another organization inside its co-signed federation (E37)","explains":"Organization A's agent asks organization B to read inventory. Both organizations co-signed a federation and a contract covering inventory.read, inside B's own authority. FEDERATION allows it (other stages still decide).","expect":"federation: allow"},{"id":"federation-transfer","title":"Another organization's evidence is not permission (E37)","explains":"Same federation. A now asks to WRITE B's inventory. B's own authority includes writes, and A's signed assurance lists inventory.write in its scope, but the federation only covers reads. Authority does not transfer across organizations: FEDERATION refuses the call and the decision is BLOCKED.","expect":"BLOCKED by federation"},{"id":"continuity-permit","title":"An action every replica re-checked at one ordered position (ACP, E02)","explains":"The call presents an Authority Continuity Protocol permit: a 4-replica PBFT cluster ordered the agent's signed request and every replica re-checked its authority chain at that position; 3 of 4 signed matching receipts. The call is exactly the authorized transfer, so CONTINUITY allows it (other stages still decide). A local ALLOW alone never executes anything.","expect":"continuity: allow"},{"id":"continuity-confused-deputy","title":"A valid permit used for different arguments (ACP, E02)","explains":"Same quorum-signed permit for 100 EUR, but the call asks to transfer 5,000 EUR. The permit covers exactly the authorized parameters, so CONTINUITY refuses it (confused-deputy guard) and the decision is BLOCKED.","expect":"BLOCKED by continuity"},{"id":"coherence-matched","title":"Two independent proofs about the same agent (proof coherence)","explains":"The call carries a GOV-IR program decision and an autonomy certificate, both naming agent-1. Each proof passes its own stage, and COHERENCE confirms they speak about one subject (other stages still decide).","expect":"coherence: allow"},{"id":"coherence-mixed","title":"Valid proofs about different agents, stitched into one call (proof coherence)","explains":"Same GOV-IR decision for agent-1, but the autonomy certificate belongs to agent-x. Each proof is valid on its own and passes its own stage; together they describe two actors for one action. COHERENCE refuses the call and the decision is BLOCKED.","expect":"BLOCKED by coherence"},{"id":"e42-governed-tool","title":"E42 unified out-of-process tool execution boundary","explains":"Executes an out-of-process tool through the full 16-stage E42 pipeline: CAIO integrity, MGO mission attenuation, counterfactual plan comparison, 4-replica verification quorum QC, proof invalidation graph, atomic commit, and pinned-key MCPGate capability token.","expect":"ALLOW / EXECUTED"}],"how":"POST /fabric/try?scenario=<id>  -- no account, no key, no signup","what_you_get":"the real eleven-stage Trust Decision, the evidence record id, and a URL that verifies that record's integrity","honest_note":"This runs the actual decision path against a throwaway tenant. It is not a mock. It is also not your traffic: to protect a real agent, install the CLI and run `cain init`."}