{
 "schema": "cain42.l5.conformance.v1",
 "generated_at": "2026-09-28T07:03:12Z",
 "overall": "INCOMPLETE",
 "rule": "PASS only where a concrete check supports it; untested is NOT_VERIFIED; partial is INCOMPLETE; a concurrent session owns cain45/l5, so its runtime results are not claimed here.",
 "areas": [
  {
   "area": "IDENTITY \u2014 cryptographic identity + separation",
   "status": "REUSED",
   "evidence": [
    "cain45/identity.py (5 kinds)",
    "cain45/l5/agent_identity.py (active session)",
    "verifier enforces signer key == declared public_key"
   ],
   "gap": "the L5 identity layer is being finalized by a concurrent session; this work verifies it, does not own it"
  },
  {
   "area": "AUTHORITY \u2014 capability / scope / temporal / trust",
   "status": "REUSED",
   "evidence": [
    "clawx/control_plane/envelope.py",
    "cain45/l5/authority.py",
    "verifier re-implements intersection"
   ],
   "gap": "runtime emission of the bundle format is not yet wired by this work"
  },
  {
   "area": "DELEGATION \u2014 anti-escalation, depth, expiry",
   "status": "PASS",
   "evidence": [
    "scope_within / align_policy tests: 6 delegation attacks refused independently"
   ],
   "gap": "delegation graph reconstruction from live evidence is REUSED from clawx AuthorityGraph, not re-verified here"
  },
  {
   "area": "ENFORCEMENT \u2014 independent verification of decisions",
   "status": "PASS",
   "evidence": [
    "tests/test_cain42_l5_authority_verifier.py: ============================== 25 passed in 0.22s =============================="
   ],
   "gap": "the verifier checks a bundle; it does not itself sit in the execution path (MCPGate does)"
  },
  {
   "area": "SECURITY \u2014 identity + authority attack suites (Parts 33/34)",
   "status": "PASS",
   "evidence": [
    "25 deterministic attack cases: forged/altered/replayed/expired/revoked/substituted identity; scope expansion, constraint widening, depth, expiry, revocation, trust floor, policy downgrade, self-authorization, policy-scope, action substitution, cross-tenant, replay, over-authorization"
   ],
   "gap": "these are artifact-level attacks; live end-to-end attacks against the running gateway are covered by the separate deploy gate (SECURITY_LIVE), not here"
  },
  {
   "area": "BYPASS \u2014 declared surfaces (Part 27)",
   "status": "INCOMPLETE",
   "evidence": [
    "CAIN42_L5_BYPASS_REPORT.json"
   ],
   "gap": "messaging/email/secrets are NOT_IMPLEMENTED; the RAW unconfined-process gap is stated, not closed"
  },
  {
   "area": "EVIDENCE \u2014 independent verifier exists and runs",
   "status": "PASS",
   "evidence": [
    "scripts/cain42_l5/verify_authority_bundle_engine_b.py (stdlib + cryptography; 0 CAIN imports)",
    "a second implementation (verify_authority_bundle.py) exists and must agree"
   ],
   "gap": "no third party has reviewed either (same operator)"
  },
  {
   "area": "PERFORMANCE \u2014 identity/authority/delegation/revocation latency",
   "status": "NOT_VERIFIED",
   "evidence": [],
   "gap": "not benchmarked in this work; the runtime's own performance is published separately"
  }
 ],
 "invariants": [
  {
   "id": 1,
   "text": "Identity does not imply authority.",
   "status": "PASS",
   "test": "test_valid_bundle_is_not_invalid + separate authority evaluation"
  },
  {
   "id": 2,
   "text": "Authority cannot exceed delegated scope.",
   "status": "PASS",
   "test": "test_scope_expansion_via_delegation_detected"
  },
  {
   "id": 3,
   "text": "Delegation cannot increase authority.",
   "status": "PASS",
   "test": "test_constraint_widening_via_delegation_detected"
  },
  {
   "id": 4,
   "text": "Expired authority cannot execute.",
   "status": "PASS",
   "test": "test_expired_grant_detected"
  },
  {
   "id": 5,
   "text": "Revoked authority cannot execute.",
   "status": "PASS",
   "test": "test_revoked_grant_detected"
  },
  {
   "id": 6,
   "text": "Modified actions invalidate authorization.",
   "status": "PASS",
   "test": "test_action_substitution_detected"
  },
  {
   "id": 7,
   "text": "Trust degradation cannot increase authority.",
   "status": "PASS",
   "test": "test_trust_floor_bypass_detected"
  },
  {
   "id": 8,
   "text": "Agents cannot authorize themselves.",
   "status": "PASS",
   "test": "test_self_authorization_detected"
  },
  {
   "id": 9,
   "text": "MCPGate cannot execute without valid authorization.",
   "status": "REUSED",
   "test": "enforced by cain/mcp_proxy.py (deploy gate SECURITY_LIVE), verified independently here as a decision object"
  },
  {
   "id": 10,
   "text": "Authorization must be reconstructable from evidence.",
   "status": "PASS",
   "test": "the verifier reconstructs the whole decision from the signed bundle (no runtime)"
  }
 ]
}
