{
 "attack_engine": {
  "classes": 6,
  "findings": 0,
  "iterations": 1500
 },
 "claims": [
  {
   "cases": 1,
   "claim": "INV-E3-01 prediction cannot create authority: gate never turns DENY into ALLOW (3000 random cases)",
   "result": "PASS",
   "tests": [
    "test_prediction_never_creates_authority_property"
   ]
  },
  {
   "cases": 1,
   "claim": "INV-E3-02 historical success cannot lower a forecast (raise-only history)",
   "result": "PASS",
   "tests": [
    "test_history_of_success_never_lowers_a_forecast"
   ]
  },
  {
   "cases": 1,
   "claim": "INV-E3-03 model consensus cannot lower risk; unseen mitigations do not count",
   "result": "PASS",
   "tests": [
    "test_model_consensus_does_not_lower_risk"
   ]
  },
  {
   "cases": 3,
   "claim": "INV-E3-04 unknown never permits: forecaster crash / malformed / non-canonical forecast -> receipted DENY",
   "result": "PASS",
   "tests": [
    "test_forecaster_crash_fails_closed_and_observe_mode_records",
    "test_malformed_forecast_is_denied",
    "test_noncanonical_forecast_is_a_receipted_denial_not_a_crash"
   ]
  },
  {
   "cases": 3,
   "claim": "INV-E3-05 stale predictions cannot reach execution (policy, model set, validity window) -- E8 refuses",
   "result": "PASS",
   "tests": [
    "test_stale_forecast_cannot_reach_execution[expiry]",
    "test_stale_forecast_cannot_reach_execution[model]",
    "test_stale_forecast_cannot_reach_execution[policy]"
   ]
  },
  {
   "cases": 3,
   "claim": "INV-E3-06 a forecast denial happens before anything runs and spends no use",
   "result": "PASS",
   "tests": [
    "test_dangerous_exec_is_denied_by_forecast_before_anything_runs[argv0-FORECAST_IMPACT_DATA]",
    "test_dangerous_exec_is_denied_by_forecast_before_anything_runs[argv1-FORECAST_IMPACT_NETWORK]",
    "test_dangerous_exec_is_denied_by_forecast_before_anything_runs[argv2-FORECAST_UNQUANTIFIED_HIGH_IMPACT]"
   ]
  },
  {
   "cases": 4,
   "claim": "INV-E3-07 autonomy budget: consumed atomically, never exceeded (threads and blue/green processes), per agent",
   "result": "PASS",
   "tests": [
    "test_autonomy_budget_is_consumed_and_cannot_be_exceeded",
    "test_blue_green_processes_share_the_budget",
    "test_budget_override_is_per_agent",
    "test_concurrent_invocations_never_overspend_budget"
   ]
  },
  {
   "cases": 1,
   "claim": "INV-E3-08 agents cannot change the policy or budget that governs them; operator credential required",
   "result": "PASS",
   "tests": [
    "test_api_forecast_policy_is_operator_only_and_never_agent"
   ]
  },
  {
   "cases": 2,
   "claim": "INV-E3-09 reality diverging from prediction ends the authorization (revoke) or is recorded, per policy",
   "result": "PASS",
   "tests": [
    "test_divergence_record_mode_keeps_the_contract",
    "test_material_divergence_revokes_the_contract"
   ]
  },
  {
   "cases": 3,
   "claim": "INV-E3-10 prediction error becomes evidence: hash-chained, tamper-evident corpus",
   "result": "PASS",
   "tests": [
    "test_benign_exec_runs_and_reality_is_observed",
    "test_corpus_is_hash_chained_and_tamper_evident",
    "test_writes_are_observed_as_effects"
   ]
  },
  {
   "cases": 3,
   "claim": "INV-E3-11 uncertainty never silently disappears: unmeasured is UNQUANTIFIED/NOT_MODELED, unobservable is labelled",
   "result": "PASS",
   "tests": [
    "test_cold_start_vs_measured_epistemic_uncertainty",
    "test_forecast_is_structurally_complete_and_never_claims_authority",
    "test_unobservable_cwd_is_labelled_not_guessed"
   ]
  },
  {
   "cases": 2,
   "claim": "INV-E3-12 evidence cannot rewrite historical prediction (replay + clean-room reject edited forecasts)",
   "result": "PASS",
   "tests": [
    "test_cleanroom_verifier_checks_forecast_receipts",
    "test_replay_rebuilds_the_forecast_gate_and_rejects_tampering"
   ]
  },
  {
   "cases": 2,
   "claim": "INV-E3-13 counterfactuals and previews are SIMULATED, change nothing, authorize nothing",
   "result": "PASS",
   "tests": [
    "test_api_forecast_preview_is_simulated",
    "test_counterfactuals_are_simulated_and_change_nothing"
   ]
  },
  {
   "cases": 1,
   "claim": "INV-E3-14 drift is detected and can deny under policy",
   "result": "PASS",
   "tests": [
    "test_calibration_and_drift_detection"
   ]
  },
  {
   "cases": 2,
   "claim": "INV-E3-15 blast radius uses real RIG reachability (memory readers, delegated children)",
   "result": "PASS",
   "tests": [
    "test_delegated_children_are_in_the_blast_radius",
    "test_memory_poisoning_forecast_uses_rig_reachability_and_memvault"
   ]
  },
  {
   "cases": 2,
   "claim": "INV-E3-16 prediction state is tenant-isolated",
   "result": "PASS",
   "tests": [
    "test_api_forecast_preview_is_simulated",
    "test_tenants_have_separate_corpora"
   ]
  },
  {
   "cases": 2,
   "claim": "INV-E3-17 prediction time machine separates known-then from now",
   "result": "PASS",
   "tests": [
    "test_api_invoke_carries_forecast_and_prediction_time_machine",
    "test_prediction_time_machine"
   ]
  },
  {
   "cases": 6,
   "claim": "INV-E2 carried: every E2 invariant still holds with forecasting enabled in the regression set",
   "result": "PASS",
   "tests": [
    "test_blue_green_processes_share_use_bound_and_e8_registry",
    "test_change_between_decision_and_e8_commit_refuses_execution[contract_revoke-revocation_state]",
    "test_change_between_decision_and_e8_commit_refuses_execution[env_change-environment_digest]",
    "test_change_between_decision_and_e8_commit_refuses_execution[epoch_bump-governance_epoch]",
    "test_change_between_decision_and_e8_commit_refuses_execution[policy_change-policy_digest]",
    "test_change_between_decision_and_e8_commit_refuses_execution[rig_revoke-capability_binding_digest]"
   ]
  }
 ],
 "date": "2026-10-04",
 "not_claimed": [
  "that forecasts are accurate (benchmark: Brier worse than base rate for failures)",
  "real-world attack prevention",
  "physical/financial consequence modelling",
  "150 invariants or 1000+ adversarial tests (see LIMITATIONS.md item 9)",
  "independent third-party verification",
  "cross-host replication"
 ],
 "overwrites": "nothing",
 "prediction_benchmark": {
  "adverse_brier": {
   "brier": 0.3661,
   "brier_of_base_rate_predictor": 0.16,
   "note": "a Brier above the base-rate predictor means the static table is NOT calibrated for failures; it predicts consequence, not command failure",
   "observed_adverse_rate": 0.2
  },
  "fs_effect": {
   "fn": 1,
   "fp": 5,
   "misses": [
    [
     "find",
     ".",
     "-maxdepth",
     "0",
     "-fprint",
     "f1.out"
    ]
   ],
   "precision": 0.706,
   "recall": 0.923,
   "tn": 17,
   "tp": 12
  }
 },
 "previous": [
  "evolution-1-frontier-contract-fabric-2026-10-04",
  "evolution-2-frontier-contract-enforcement-2026-10-04"
 ],
 "schema": "cain.claims.evolution3.v1",
 "scope": "predictive consequence governance on the contract fabric (RIG, OpenShell, MemVault, SCITT)",
 "status": "TESTED + DEPLOYED (blue+green, 3 domains)",
 "tests": "1478/1478 passed"
}
