{
  "schema": "cain42.evolution18.proof.v1",
  "bundle_name": "e18-4d-spatial-autonomy-2026-09-28",
  "title": "CAIN-42 Evolution 18: 4D Spatial Autonomy Fabric",
  "generated_at": "2026-09-29T05:22:09.860562+00:00",
  "commit": "6d93b654da0e8eda0806562dd41f6362532689fd",
  "modules": {
    "e18_spatial_autonomy": "3cfb6f2ae8acda2c7ad3b7b2b2ae92f58c4153e2b812a5bf5a866679e5f63880",
    "canon": "50f3134f85d36cfade939ef96482450dcfeed3c0dbdebc4a2bfebceef9e21541",
    "e8_kernel": "e70cc8cd43d1a1f2a32f3aba7733298aea0cda19495676662091ec04d380b673"
  },
  "invariants": {
    "schema": "cain42.e18.invariants.v1",
    "checked": 89,
    "all_hold": true,
    "failed": [],
    "checks": [
      {
        "id": "Q01",
        "invariant": "spatial state is not reality",
        "holds": true,
        "detail": {
          "entity_id": "car-1",
          "t": 1000.0,
          "position": {
            "x": 0.0,
            "y": 0.0,
            "z": 0.0
          },
          "velocity": {
            "x": 10.0,
            "y": 0.0,
            "z": 0.0
          },
          "acceleration": {
            "x": 0.0,
            "y": 0.0,
            "z": 0.0
          },
          "angular_velocity": 0.0,
          "orientation": [
            0.0,
            0.0,
            0.0
          ],
          "dimensions": [
            2.0,
            1.0,
            1.0
          ],
          "classification": "VEHICLE",
          "confidence": 0.9,
          "uncertainty": 0.1,
          "covariance": [
            0.5,
            0.5,
            0.1
          ],
          "provenance_digest": "b9442087bf538ce8a6ad92f78a4b5f5c5ee12ed5e37f622531e7aad8d050a283",
          "layer": "OBSERVED",
          "source": "gnss+lidar",
          "kind": "REALITY"
        }
      },
      {
        "id": "Q02",
        "invariant": "prediction is not reality",
        "holds": true,
        "detail": {
          "layer": "PREDICTED"
        }
      },
      {
        "id": "Q03",
        "invariant": "prediction is not authority",
        "holds": true,
        "detail": {
          "hypothesis_id": "th-1",
          "entity_id": "car-1",
          "points": [
            [
              0.0,
              0.0,
              0.0,
              1000.0
            ],
            [
              5.0,
              0.0,
              0.0,
              1001.0
            ],
            [
              10.0,
              0.0,
              0.0,
              1002.0
            ]
          ],
          "probability": 0.8,
          "assumptions": [
            "clear"
          ],
          "source_model": "mdl-a",
          "model_version": "1.0.0",
          "horizon": 2.0,
          "uncertainty": 0.2,
          "consequence_estimate": 0.0,
          "interaction_dependencies": [],
          "layer": "PREDICTED"
        }
      },
      {
        "id": "Q04",
        "invariant": "reachability is not permission",
        "holds": true,
        "detail": {
          "physical": 27,
          "authorized": 1
        }
      },
      {
        "id": "Q05",
        "invariant": "permission is not authorization",
        "holds": true,
        "detail": {
          "policy_domain": "DRONE",
          "eligible": true,
          "reasons": [],
          "eligible_is_not_authorized": true,
          "authority": "NONE",
          "digest": "4c13427c4cf1624411b8fbd4b89ef05bb7559a04d370b33431c777a74739ebe1"
        }
      },
      {
        "id": "Q06",
        "invariant": "authorization is not execution",
        "holds": true,
        "detail": [
          "E8_BOUNDARY_NOT_CONFIGURED:NOT_IMPLEMENTED",
          "E8_TOKEN_MISSING"
        ]
      },
      {
        "id": "Q07",
        "invariant": "execution is not successful outcome",
        "holds": true,
        "detail": [
          "OUTCOME",
          "DRIFT",
          "REAUTHORIZATION"
        ]
      },
      {
        "id": "Q08",
        "invariant": "uncertainty cannot silently become certainty",
        "holds": true,
        "detail": {
          "entity_id": "x",
          "t": 0.0,
          "position": {
            "x": 0.0,
            "y": 0.0,
            "z": 0.0
          },
          "velocity": {
            "x": 0.0,
            "y": 0.0,
            "z": 0.0
          },
          "acceleration": {
            "x": 0.0,
            "y": 0.0,
            "z": 0.0
          },
          "angular_velocity": 0.0,
          "orientation": [
            0.0,
            0.0,
            0.0
          ],
          "dimensions": [
            2.0,
            1.0,
            1.0
          ],
          "classification": "VEHICLE",
          "confidence": 0.0,
          "uncertainty": 0.2,
          "covariance": [
            0.5,
            0.5,
            0.5
          ],
          "provenance_digest": "",
          "layer": "OBSERVED",
          "source": "",
          "kind": "REALITY"
        }
      },
      {
        "id": "Q09",
        "invariant": "stale state cannot authorize current action",
        "holds": true,
        "detail": {
          "denied": true
        }
      },
      {
        "id": "Q10",
        "invariant": "stale trajectory cannot authorize current action",
        "holds": true,
        "detail": {
          "denied": true
        }
      },
      {
        "id": "Q11",
        "invariant": "stale geofence cannot authorize current action",
        "holds": true,
        "detail": {
          "geofence_id": "g",
          "center": [
            0.0,
            0.0,
            0.0
          ],
          "radius": 5.0,
          "valid_from": 0.0,
          "valid_until": 10.0,
          "provenance": "prov-1",
          "version": 1,
          "revoked": false
        }
      },
      {
        "id": "Q12",
        "invariant": "stale policy cannot authorize current action",
        "holds": true,
        "detail": {
          "denied": true
        }
      },
      {
        "id": "Q13",
        "invariant": "stale model cannot authorize current action",
        "holds": true,
        "detail": {
          "changed": true
        }
      },
      {
        "id": "Q14",
        "invariant": "identity substitution invalidates affected authorization",
        "holds": true,
        "detail": {
          "substituted": true
        }
      },
      {
        "id": "Q15",
        "invariant": "material sensor conflict invalidates affected authorization",
        "holds": true,
        "detail": {
          "claim": "obstacle",
          "sources": 2,
          "independent_roots": 2,
          "values": [
            "0",
            "1"
          ],
          "agreement": false,
          "stale": 0,
          "safety_critical": true,
          "decision": "REQUIRES_REVIEW",
          "conflicting_safety_critical_resolves_to_allow": false,
          "authority": "NONE",
          "digest": "1b054258eb3f3b2f18479065f3a0d14c73a090f6b297ecbb04e827265174273f"
        }
      },
      {
        "id": "Q16",
        "invariant": "material world-state drift invalidates affected authorization",
        "holds": true,
        "detail": {
          "drift": true
        }
      },
      {
        "id": "Q17",
        "invariant": "material trajectory drift invalidates affected authorization",
        "holds": true,
        "detail": {
          "denied": true
        }
      },
      {
        "id": "Q18",
        "invariant": "material actuator drift invalidates affected authorization",
        "holds": true,
        "detail": {
          "drifts": {
            "model_drift": 0.0,
            "localization_drift": 0.0,
            "sensor_drift": 0.0,
            "trajectory_deviation": 0.0,
            "actuator_deviation": 5.0,
            "environment_shift": 0.0
          },
          "material": [
            "actuator_deviation"
          ],
          "material_divergence": true,
          "invalidates_authorization": true,
          "authority": "NONE",
          "digest": "cb6bb475071b63500677e9887596ea40182d74f284def0fb844821a4bd868b2a"
        }
      },
      {
        "id": "Q19",
        "invariant": "spatial authority cannot exceed delegated authority",
        "holds": true,
        "detail": {
          "bounded": true
        }
      },
      {
        "id": "Q20",
        "invariant": "geographic authority cannot expand itself",
        "holds": true,
        "detail": {
          "bounded": true
        }
      },
      {
        "id": "Q21",
        "invariant": "temporal authority cannot expand itself",
        "holds": true,
        "detail": {
          "bounded": true
        }
      },
      {
        "id": "Q22",
        "invariant": "model confidence cannot create authority",
        "holds": true,
        "detail": {
          "selected": "b",
          "models": [
            "a",
            "b"
          ],
          "reasons": [
            "DEGRADED_MODEL_PRESENT"
          ],
          "highest_confidence_chosen": false,
          "confidence_is_not_authority": true,
          "authority": "NONE",
          "digest": "55e4eaf96819870540f507b85dd91e2b3b61a79882fac18ea6113ba710948888"
        }
      },
      {
        "id": "Q23",
        "invariant": "ensemble agreement cannot create authority",
        "holds": true,
        "detail": {
          "sources": [
            "a",
            "b"
          ],
          "independent_sources": 1,
          "count": 2,
          "spread": 0.0,
          "consensus": false,
          "correlated_errors": true,
          "outlier": false,
          "authority": "NONE",
          "digest": "63a3b8abf7b4bf6795027863a51ca7f111b6db93f29414c475c49f61d716dd14"
        }
      },
      {
        "id": "Q24",
        "invariant": "prediction consensus cannot create authority",
        "holds": true,
        "detail": {
          "entity_id": "e",
          "hypotheses": [
            "03499d3a10e7f872a29e432c458b98f1209e531f7fe8df470b0c24e9316c21a0",
            "b4849115a9a4649a9d4d8bb4d196280f2cb774599c72bb74c881ad8006e673cd"
          ],
          "count": 2,
          "layer": "PREDICTED",
          "consensus": "DOMINANT",
          "authority": "NONE"
        }
      },
      {
        "id": "Q25",
        "invariant": "simulation cannot become reality",
        "holds": true,
        "detail": {
          "sim": "SIMULATED"
        }
      },
      {
        "id": "Q26",
        "invariant": "counterfactual cannot become observed state",
        "holds": true,
        "detail": {
          "entity_id": "car-1",
          "branches": [
            "03cb0ce1f0b3e0ae370cb230d6917e3c610a1362082603ffad3693a4dcec95a1",
            "2111f9afefc9b1bd0ce8bdbf2016be633cdc1d26131e93c73b8356105894e7de",
            "4f1c6ee858d2486beaf8b06f54da8439ec1dcccafc8b4dd46462d9ffaf5e0db2",
            "5a43d0a3e92fc06feaaa307f16e6be5da738cec82bc296f8bb02aea19c9fd65c",
            "946c4f24005ef057bfecbaacd74f60a6af82acf75418874a4618742af6049ac9",
            "a809c668b1bef33884f5744da828e9fc666afc7b6aa14b33e63b63c685300139",
            "d00bd149fe8e8cc8a4df36ef97acbed5d13707c29bbba4d6357342ace1858f4f",
            "dcee12d318d2fe7e8e474923543d07d4c9b7c59cf26828bdcc5fbcece46b1deb"
          ],
          "count": 8,
          "mutates_reality": false,
          "authority": "NONE",
          "body": {
            "entity_id": "car-1",
            "branches": [
              "03cb0ce1f0b3e0ae370cb230d6917e3c610a1362082603ffad3693a4dcec95a1",
              "2111f9afefc9b1bd0ce8bdbf2016be633cdc1d26131e93c73b8356105894e7de",
              "4f1c6ee858d2486beaf8b06f54da8439ec1dcccafc8b4dd46462d9ffaf5e0db2",
              "5a43d0a3e92fc06feaaa307f16e6be5da738cec82bc296f8bb02aea19c9fd65c",
              "946c4f24005ef057bfecbaacd74f60a6af82acf75418874a4618742af6049ac9",
              "a809c668b1bef33884f5744da828e9fc666afc7b6aa14b33e63b63c685300139",
              "d00bd149fe8e8cc8a4df36ef97acbed5d13707c29bbba4d6357342ace1858f4f",
              "dcee12d318d2fe7e8e474923543d07d4c9b7c59cf26828bdcc5fbcece46b1deb"
            ],
            "count": 8,
            "mutates_reality": false,
            "authority": "NONE"
          },
          "branches_detail": [
            {
              "name": "CONTINUE",
              "predicted_state": {
                "entity_id": "car-1",
                "world_digest": "39abfdf90a4da9dd8cff4205411f86a577cdc278201843cc58ef22f30ba55b3f",
                "action": "CONTINUE"
              },
              "consequences": [],
              "uncertainty": 0.2,
              "affected_entities": [],
              "policy_effects": [],
              "authority_requirements": [
                "CONTINUE"
              ],
              "layer": "SIMULATED",
              "is_fact": false,
              "authority": "NONE"
            },
            {
              "name": "STOP",
              "predicted_state": {
                "entity_id": "car-1",
                "world_digest": "39abfdf90a4da9dd8cff4205411f86a577cdc278201843cc58ef22f30ba55b3f",
                "action": "STOP"
              },
              "consequences": [],
              "uncertainty": 0.3,
              "affected_entities": [],
              "policy_effects": [],
              "authority_requirements": [
                "STOP"
              ],
              "layer": "SIMULATED",
              "is_fact": false,
              "authority": "NONE"
            },
            {
              "name": "SLOW",
              "predicted_state": {
                "entity_id": "car-1",
                "world_digest": "39abfdf90a4da9dd8cff4205411f86a577cdc278201843cc58ef22f30ba55b3f",
                "action": "SLOW"
              },
              "consequences": [],
              "uncertainty": 0.4,
              "affected_entities": [],
              "policy_effects": [],
              "authority_requirements": [
                "SLOW"
              ],
              "layer": "SIMULATED",
              "is_fact": false,
              "authority": "NONE"
            },
            {
              "name": "YIELD",
              "predicted_state": {
                "entity_id": "car-1",
                "world_digest": "39abfdf90a4da9dd8cff4205411f86a577cdc278201843cc58ef22f30ba55b3f",
                "action": "YIELD"
              },
              "consequences": [],
              "uncertainty": 0.5,
              "affected_entities": [],
              "policy_effects": [],
              "authority_requirements": [
                "YIELD"
              ],
              "layer": "SIMULATED",
              "is_fact": false,
              "authority": "NONE"
            },
            {
              "name": "REROUTE",
              "predicted_state": {
                "entity_id": "car-1",
                "world_digest": "39abfdf90a4da9dd8cff4205411f86a577cdc278201843cc58ef22f30ba55b3f",
                "action": "REROUTE"
              },
              "consequences": [],
              "uncertainty": 0.6,
              "affected_entities": [],
              "policy_effects": [],
              "authority_requirements": [
                "REROUTE"
              ],
              "layer": "SIMULATED",
              "is_fact": false,
              "authority": "NONE"
            },
            {
              "name": "ALTITUDE_CHANGE",
              "predicted_state": {
                "entity_id": "car-1",
                "world_digest": "39abfdf90a4da9dd8cff4205411f86a577cdc278201843cc58ef22f30ba55b3f",
                "action": "ALTITUDE_CHANGE"
              },
              "consequences": [],
              "uncertainty": 0.7,
              "affected_entities": [],
              "policy_effects": [],
              "authority_requirements": [
                "ALTITUDE_CHANGE"
              ],
              "layer": "SIMULATED",
              "is_fact": false,
              "authority": "NONE"
            },
            {
              "name": "LAND",
              "predicted_state": {
                "entity_id": "car-1",
                "world_digest": "39abfdf90a4da9dd8cff4205411f86a577cdc278201843cc58ef22f30ba55b3f",
                "action": "LAND"
              },
              "consequences": [],
              "uncertainty": 0.8,
              "affected_entities": [],
              "policy_effects": [],
              "authority_requirements": [
                "LAND"
              ],
              "layer": "SIMULATED",
              "is_fact": false,
              "authority": "NONE"
            },
            {
              "name": "SAFE_STATE",
              "predicted_state": {
                "entity_id": "car-1",
                "world_digest": "39abfdf90a4da9dd8cff4205411f86a577cdc278201843cc58ef22f30ba55b3f",
                "action": "SAFE_STATE"
              },
              "consequences": [],
              "uncertainty": 0.9,
              "affected_entities": [],
              "policy_effects": [],
              "authority_requirements": [
                "SAFE_STATE"
              ],
              "layer": "SIMULATED",
              "is_fact": false,
              "authority": "NONE"
            }
          ],
          "digest": "f6abf9b8b1568b795bae917dfd73b4528e500bae975a59c9749a07eae664220e"
        }
      },
      {
        "id": "Q27",
        "invariant": "reachable set cannot become authorized set",
        "holds": true,
        "detail": {
          "entity_id": "car-1",
          "horizon": [
            1000.0,
            1001.0
          ],
          "spatial_boundary": [
            [
              -15.0,
              -15.0,
              -4.5
            ],
            [
              15.0,
              15.0,
              4.5
            ]
          ],
          "velocity_constraints": [
            0.0,
            15.0
          ],
          "acceleration_constraints": [
            0.0,
            5.0
          ],
          "actuator_constraints": [
            "motor"
          ],
          "environment_constraints": [],
          "policy_constraints": [
            [
              0.0,
              0.0,
              0.0
            ],
            [
              10.0,
              0.0,
              0.0
            ],
            [
              5.0,
              5.0,
              30.0
            ]
          ],
          "capability_constraints": [
            "navigate"
          ],
          "uncertainty_envelope": 0.15,
          "physically_reachable": [
            [
              -15.0,
              -15.0,
              -4.5
            ],
            [
              -15.0,
              -15.0,
              0.0
            ],
            [
              -15.0,
              -15.0,
              4.5
            ],
            [
              -15.0,
              0.0,
              -4.5
            ],
            [
              -15.0,
              0.0,
              0.0
            ],
            [
              -15.0,
              0.0,
              4.5
            ],
            [
              -15.0,
              15.0,
              -4.5
            ],
            [
              -15.0,
              15.0,
              0.0
            ],
            [
              -15.0,
              15.0,
              4.5
            ],
            [
              0.0,
              -15.0,
              -4.5
            ],
            [
              0.0,
              -15.0,
              0.0
            ],
            [
              0.0,
              -15.0,
              4.5
            ],
            [
              0.0,
              0.0,
              -4.5
            ],
            [
              0.0,
              0.0,
              0.0
            ],
            [
              0.0,
              0.0,
              4.5
            ],
            [
              0.0,
              15.0,
              -4.5
            ],
            [
              0.0,
              15.0,
              0.0
            ],
            [
              0.0,
              15.0,
              4.5
            ],
            [
              15.0,
              -15.0,
              -4.5
            ],
            [
              15.0,
              -15.0,
              0.0
            ],
            [
              15.0,
              -15.0,
              4.5
            ],
            [
              15.0,
              0.0,
              -4.5
            ],
            [
              15.0,
              0.0,
              0.0
            ],
            [
              15.0,
              0.0,
              4.5
            ],
            [
              15.0,
              15.0,
              -4.5
            ],
            [
              15.0,
              15.0,
              0.0
            ],
            [
              15.0,
              15.0,
              4.5
            ]
          ],
          "policy_permitted": [
            [
              0.0,
              0.0,
              0.0
            ]
          ],
          "authorized": [
            [
              0.0,
              0.0,
              0.0
            ]
          ]
        }
      },
      {
        "id": "Q28",
        "invariant": "actionability cannot become authorization",
        "holds": true,
        "detail": {
          "action": "continue",
          "state": "ACTIONABLE",
          "factors": {
            "physically_feasible": true,
            "temporally_feasible": true,
            "spatially_feasible": true,
            "policy_permitted": true,
            "capability_available": true,
            "authority_available": true,
            "consequence_acceptable": true,
            "uncertainty_acceptable": true,
            "boundary_reachable": true
          },
          "actionability_is_not_authorization": true,
          "authority": "NONE",
          "digest": "d96fe717a03ed6e4bfa28b30d1f70ea873e542b3e7e5a7191bf08175d2d712f6"
        }
      },
      {
        "id": "Q29",
        "invariant": "collective intent cannot become authority",
        "holds": true,
        "detail": {
          "entities": [
            "car-1"
          ],
          "intents": {
            "car-1": [
              "CONTINUE"
            ]
          },
          "authority": "NONE",
          "digest": "4502b119a8fdf68f2c4623067c62013cf1c5db47d1080b19d5cd641582718242"
        }
      },
      {
        "id": "Q30",
        "invariant": "external agent messages cannot create authority",
        "holds": true,
        "detail": {
          "claim": "lane_free",
          "sources": 1,
          "independent_roots": 1,
          "values": [
            "True"
          ],
          "agreement": true,
          "stale": 0,
          "safety_critical": true,
          "decision": "FUSED",
          "conflicting_safety_critical_resolves_to_allow": false,
          "authority": "NONE",
          "digest": "5bc3b47b9f928bf8d1e6b5c9aca4cfabf6305a972cc65ae55423483b311fbc93"
        }
      },
      {
        "id": "Q31",
        "invariant": "dynamic geofences require provenance",
        "holds": true,
        "detail": {
          "ok": true
        }
      },
      {
        "id": "Q32",
        "invariant": "spatial identities require provenance",
        "holds": true,
        "detail": {
          "bound": true
        }
      },
      {
        "id": "Q33",
        "invariant": "world-state versions must be replayable",
        "holds": true,
        "detail": [
          {
            "op": "GENESIS",
            "at": 1000.0,
            "root": ""
          },
          {
            "op": "INGEST",
            "at": 1000.0,
            "root": "4db0f9acfdcf9a1ec83c7f362b40f69a98aba1002767bb19766cd05a1449442f"
          }
        ]
      },
      {
        "id": "Q34",
        "invariant": "world-state branches cannot silently merge",
        "holds": true,
        "detail": "MERGE_REQUIRES_EXPLICIT_RECONCILIATION"
      },
      {
        "id": "Q35",
        "invariant": "trajectories must bind to world state",
        "holds": true,
        "detail": {
          "bound": true
        }
      },
      {
        "id": "Q36",
        "invariant": "actions must bind to trajectories",
        "holds": true,
        "detail": {
          "bound": true
        }
      },
      {
        "id": "Q37",
        "invariant": "actions must bind to authority",
        "holds": true,
        "detail": {
          "bound": true
        }
      },
      {
        "id": "Q38",
        "invariant": "actions must bind to capability",
        "holds": true,
        "detail": {
          "bound": true
        }
      },
      {
        "id": "Q39",
        "invariant": "actions must bind to consequence",
        "holds": true,
        "detail": {
          "bound": true
        }
      },
      {
        "id": "Q40",
        "invariant": "actions must bind to policy",
        "holds": true,
        "detail": {
          "bound": true
        }
      },
      {
        "id": "Q41",
        "invariant": "actions must bind to risk",
        "holds": true,
        "detail": {
          "changed": true
        }
      },
      {
        "id": "Q42",
        "invariant": "actions must bind to authorization",
        "holds": true,
        "detail": {
          "bound": true
        }
      },
      {
        "id": "Q43",
        "invariant": "every consequential action reaches E8",
        "holds": true,
        "detail": {
          "good": "AUTHORIZED",
          "no_e8": "DENY"
        }
      },
      {
        "id": "Q44",
        "invariant": "no direct actuator path may bypass governance",
        "holds": true,
        "detail": {
          "good": "AUTHORIZED",
          "no_e8": "DENY"
        }
      },
      {
        "id": "Q45",
        "invariant": "unknown cannot become allow",
        "holds": true,
        "detail": [
          "E8_BOUNDARY_NOT_CONFIGURED:NOT_IMPLEMENTED",
          "E8_TOKEN_MISSING"
        ]
      },
      {
        "id": "Q46",
        "invariant": "denied cannot become allow through retry",
        "holds": true,
        "detail": [
          "TOKEN_REPLAY",
          "TOKEN_SEQUENCE_REPLAY"
        ]
      },
      {
        "id": "Q47",
        "invariant": "revoked authorization cannot resurrect",
        "holds": true,
        "detail": [
          "AUTHORITY_REVOKED"
        ]
      },
      {
        "id": "Q48",
        "invariant": "consumed authorization cannot replay",
        "holds": true,
        "detail": [
          "TOKEN_REPLAY",
          "TOKEN_SEQUENCE_REPLAY"
        ]
      },
      {
        "id": "Q49",
        "invariant": "legitimate sequential execution must remain possible",
        "holds": true,
        "detail": {
          "a": "AUTHORIZED",
          "b": "AUTHORIZED"
        }
      },
      {
        "id": "Q50",
        "invariant": "uncertainty must propagate",
        "holds": true,
        "detail": {
          "stages": {
            "observation": 0.1,
            "world_state": 0.1,
            "prediction": 0.2,
            "trajectory": 0.2,
            "consequence": 0.3,
            "decision": 0.3,
            "authorization": 0.3
          },
          "monotone": true,
          "authority": "NONE",
          "digest": "7f8344cec93fbe8b04fa8e92ffbe1e2492577879b2189528d39bebdfb22fde39"
        }
      },
      {
        "id": "Q51",
        "invariant": "governance latency cannot justify governance bypass",
        "holds": true,
        "detail": {
          "mission_id": "m",
          "verdict": "SAFE_DEGRADE",
          "measurements": {
            "decision": 50.0
          },
          "bypass_governance": false,
          "authority": "NONE",
          "digest": "7d82a74f1d7b085dc751d687de5221be3fb1bd9aa6b016c517b2808166fc25e0"
        }
      },
      {
        "id": "Q52",
        "invariant": "degraded mode cannot silently increase authority",
        "holds": true,
        "detail": {
          "mission_id": "m",
          "maximum": 0.2,
          "components": {
            "perception": 0.6,
            "prediction": 0.6
          },
          "total": 0.84,
          "measured": true,
          "response": "SAFE_STATE",
          "authority": "NONE",
          "digest": "ed90ed584e1aa3eb3730356c57d64d60852eac3b57c092030073b550daffda2f"
        }
      },
      {
        "id": "Q53",
        "invariant": "safe state cannot silently become active state",
        "holds": true,
        "detail": {
          "action": "continue",
          "state": "SAFE_STATE_ONLY",
          "factors": {
            "physically_feasible": true,
            "temporally_feasible": true,
            "spatially_feasible": true,
            "policy_permitted": true,
            "capability_available": true,
            "authority_available": true,
            "consequence_acceptable": false,
            "uncertainty_acceptable": true,
            "boundary_reachable": true
          },
          "actionability_is_not_authorization": true,
          "authority": "NONE",
          "digest": "13513f9c67f5e27b16285bed0e05bf4ccb34598696dca136cae1f16714705537"
        }
      },
      {
        "id": "Q54",
        "invariant": "model substitution invalidates model-bound authorization",
        "holds": true,
        "detail": {
          "changed": true
        }
      },
      {
        "id": "Q55",
        "invariant": "map substitution invalidates map-bound authorization",
        "holds": true,
        "detail": {
          "claim": "lane",
          "sources": 2,
          "independent_roots": 2,
          "values": [
            "L1",
            "L2"
          ],
          "agreement": false,
          "stale": 0,
          "safety_critical": true,
          "decision": "REQUIRES_REVIEW",
          "conflicting_safety_critical_resolves_to_allow": false,
          "authority": "NONE",
          "digest": "2389135aea57fd948c2a6078ec272396da7e5b69dfb2c51dd29bd1ad0d5cd9a3"
        }
      },
      {
        "id": "Q56",
        "invariant": "sensor provenance cannot be rewritten silently",
        "holds": true,
        "detail": {
          "changed": true
        }
      },
      {
        "id": "Q57",
        "invariant": "historical evidence is immutable",
        "holds": true,
        "detail": {
          "immutable": true
        }
      },
      {
        "id": "Q58",
        "invariant": "prediction error becomes evidence",
        "holds": true,
        "detail": {
          "drifts": {
            "model_drift": 3.0,
            "localization_drift": 0.0,
            "sensor_drift": 0.0,
            "trajectory_deviation": 0.0,
            "actuator_deviation": 0.0,
            "environment_shift": 0.0
          },
          "material": [
            "model_drift"
          ],
          "material_divergence": true,
          "invalidates_authorization": true,
          "authority": "NONE",
          "digest": "8f41b38bbb14e4340e9ee9c187f57175ab2a67a9c939b06b638c05e06188f626"
        }
      },
      {
        "id": "Q59",
        "invariant": "reality gap cannot be ignored",
        "holds": true,
        "detail": {
          "drifts": {
            "model_drift": 0.0,
            "localization_drift": 0.0,
            "sensor_drift": 0.0,
            "trajectory_deviation": 0.0,
            "actuator_deviation": 5.0,
            "environment_shift": 0.0
          },
          "material": [
            "actuator_deviation"
          ],
          "material_divergence": true,
          "invalidates_authorization": true,
          "authority": "NONE",
          "digest": "cb6bb475071b63500677e9887596ea40182d74f284def0fb844821a4bd868b2a"
        }
      },
      {
        "id": "Q60",
        "invariant": "simulation cannot establish real-world safety",
        "holds": true,
        "detail": {
          "branches": 8
        }
      },
      {
        "id": "Q61",
        "invariant": "physical integration must remain explicitly bounded",
        "holds": true,
        "detail": {
          "bounded": true
        }
      },
      {
        "id": "Q62",
        "invariant": "unsupported hardware cannot be represented as verified",
        "holds": true,
        "detail": "ENTITY_PROBABILITY_INVALID"
      },
      {
        "id": "Q63",
        "invariant": "third-party validation cannot be implied",
        "holds": true,
        "detail": {
          "selected": null,
          "authority": "NONE",
          "reasons": [
            "NO_MODELS"
          ],
          "confidence_is_not_authority": true
        }
      },
      {
        "id": "Q64",
        "invariant": "multi-host behavior cannot be inferred from single-host tests",
        "holds": true,
        "detail": {
          "single_host": true
        }
      },
      {
        "id": "Q65",
        "invariant": "physical safety cannot be claimed from software-only tests",
        "holds": true,
        "detail": {
          "no_safety_claim": true
        }
      },
      {
        "id": "Q66",
        "invariant": "human authority must retain explicit provenance",
        "holds": true,
        "detail": {
          "action": "continue",
          "state": "REQUIRES_HUMAN",
          "factors": {
            "physically_feasible": null,
            "temporally_feasible": null,
            "spatially_feasible": null,
            "policy_permitted": null,
            "capability_available": null,
            "authority_available": null,
            "consequence_acceptable": null,
            "uncertainty_acceptable": null,
            "boundary_reachable": null
          },
          "actionability_is_not_authorization": true,
          "authority": "NONE",
          "digest": "c4b8c2ebcd49b4a379a6b1fbaab0bfac4a1832e6a501b3909dede6fb91a1721a"
        }
      },
      {
        "id": "Q67",
        "invariant": "emergency authority must be bounded",
        "holds": true,
        "detail": {
          "bounded": true
        }
      },
      {
        "id": "Q68",
        "invariant": "recovery cannot mint authority",
        "holds": true,
        "detail": {
          "authority": "NONE"
        }
      },
      {
        "id": "Q69",
        "invariant": "self-improvement cannot mint authority",
        "holds": true,
        "detail": {
          "no_mint": true
        }
      },
      {
        "id": "Q70",
        "invariant": "collective agreement cannot mint authority",
        "holds": true,
        "detail": {
          "sources": [
            "a",
            "b"
          ],
          "independent_sources": 2,
          "count": 2,
          "spread": 0.0,
          "consensus": true,
          "correlated_errors": false,
          "outlier": false,
          "authority": "NONE",
          "digest": "08ec85e0456d24aef5a35c695c8a4b7933c5d7847b17c7a6a6fb2121a9874031"
        }
      },
      {
        "id": "Q71",
        "invariant": "spatial coordination cannot bypass policy",
        "holds": true,
        "detail": {
          "authority": "NONE"
        }
      },
      {
        "id": "Q72",
        "invariant": "trajectory optimization cannot bypass consequence governance",
        "holds": true,
        "detail": {
          "ranked": [
            {
              "action": "continue",
              "score": 5.2,
              "state": "UNKNOWN"
            }
          ],
          "selected": "continue",
          "selection_is_a_proposal": true,
          "authority": "NONE",
          "digest": "b9b433521311a78305062646027405cb5d26bf7c1692c1be0f6cb36347baa707"
        }
      },
      {
        "id": "Q73",
        "invariant": "prediction horizon cannot exceed evidence validity without revalidation",
        "holds": true,
        "detail": {
          "revalidate": true
        }
      },
      {
        "id": "Q74",
        "invariant": "action authorization must be state-specific",
        "holds": true,
        "detail": {
          "state_specific": true
        }
      },
      {
        "id": "Q75",
        "invariant": "every authorization must have a deterministic verification path",
        "holds": true,
        "detail": {
          "deterministic": true
        }
      },
      {
        "id": "Q76",
        "invariant": "conflict detection is not distance-only",
        "holds": true,
        "detail": {
          "kinds": 0
        }
      },
      {
        "id": "Q77",
        "invariant": "digital-twin layers are never conflated",
        "holds": true,
        "detail": {
          "twin_id": "t",
          "layers": {
            "REALITY": [],
            "OBSERVED": [
              "x"
            ],
            "MODEL": [],
            "PREDICTED": [
              "x"
            ],
            "SIMULATED": [],
            "AUTHORIZED": [],
            "EXECUTED": []
          },
          "predicted_vs_observed": [],
          "authorized_vs_executed": [],
          "model_vs_reality": [],
          "conflated": false,
          "authority": "NONE",
          "digest": "5a8ca0b8252abeb2b2b4005c760b0677d0409a9bc44da34b844524cfd3bd7df9"
        }
      },
      {
        "id": "Q78",
        "invariant": "spatial incident replay uses immutable evidence",
        "holds": true,
        "detail": {
          "stages": [
            "TIME",
            "WORLD_STATE",
            "OBSERVATIONS",
            "PREDICTIONS",
            "TRAJECTORIES",
            "DECISION",
            "AUTHORITY",
            "POLICY",
            "CONSEQUENCE",
            "AUTHORIZATION",
            "ACTION",
            "OUTCOME",
            "DRIFT",
            "REAUTHORIZATION"
          ],
          "present": [
            "TIME",
            "WORLD_STATE",
            "OBSERVATIONS",
            "PREDICTIONS",
            "TRAJECTORIES",
            "DECISION",
            "AUTHORITY",
            "POLICY",
            "CONSEQUENCE",
            "AUTHORIZATION",
            "ACTION",
            "OUTCOME",
            "DRIFT",
            "REAUTHORIZATION"
          ],
          "missing": [],
          "replayable": true,
          "immutable_evidence": true,
          "authority": "NONE",
          "digest": "0555e7b2cf1463c78b6625f161ff829cd04a9915bb7a796781de7f9fe9028c43"
        }
      },
      {
        "id": "Q79",
        "invariant": "geofence versions are monotonic",
        "holds": true,
        "detail": {
          "monotonic": true
        }
      },
      {
        "id": "Q80",
        "invariant": "the E8 action binds every spatial digest",
        "holds": true,
        "detail": {
          "fields": 16
        }
      },
      {
        "id": "Q81",
        "invariant": "a refusing policy cannot be re-issued into an authorization",
        "holds": true,
        "detail": [
          "POLICY_NOT_ELIGIBLE"
        ]
      },
      {
        "id": "Q82",
        "invariant": "the commit boundary requires an ACTIONABLE, fully evaluated actionability",
        "holds": true,
        "detail": {
          "denied": [
            "ACTIONABILITY_NOT_ACTIONABLE:DENIED"
          ],
          "unevaluated": [
            "ACTIONABILITY_NOT_ACTIONABLE:UNKNOWN"
          ]
        }
      },
      {
        "id": "Q83",
        "invariant": "a revoked or out-of-domain spatial authority refuses at the boundary",
        "holds": true,
        "detail": [
          [
            "AUTHORITY_REVOKED"
          ],
          [
            "NO_AUTHORITY_DOMAIN_PERMITS_THIS_ACTION"
          ],
          [
            "NO_AUTHORITY_DOMAIN_PERMITS_THIS_ACTION"
          ]
        ]
      },
      {
        "id": "Q84",
        "invariant": "risk above threshold or unknown refuses",
        "holds": true,
        "detail": [
          [
            "RISK_ABOVE_THRESHOLD"
          ],
          [
            "RISK_UNKNOWN"
          ]
        ]
      },
      {
        "id": "Q85",
        "invariant": "uncertainty above threshold or unknown refuses and never drops between layers",
        "holds": true,
        "detail": [
          [
            "UNCERTAINTY_ABOVE_THRESHOLD"
          ],
          [
            "UNCERTAINTY_UNKNOWN"
          ],
          {
            "observation": 0.9,
            "world_state": 0.9,
            "prediction": 0.9,
            "trajectory": 0.9,
            "consequence": 0.9,
            "decision": 0.9,
            "authorization": 0.9
          }
        ]
      },
      {
        "id": "Q86",
        "invariant": "an omitted constraint never matches a constrained authority domain",
        "holds": true,
        "detail": [
          [],
          [
            "NO_AUTHORITY_DOMAIN_PERMITS_THIS_ACTION"
          ],
          [
            "NO_AUTHORITY_DOMAIN_PERMITS_THIS_ACTION"
          ]
        ]
      },
      {
        "id": "Q87",
        "invariant": "micro-authorization cannot skip revalidation or continue across a world change",
        "holds": true,
        "detail": {
          "skip": [
            "MICRO_STAGE_OUT_OF_ORDER:ISSUED->CONTINUED"
          ],
          "cross": [
            "WORLD_STATE_CHANGED"
          ]
        }
      },
      {
        "id": "Q88",
        "invariant": "the world digest binds the map (roadspace and airspace)",
        "holds": true,
        "detail": {
          "roadspace_changed": true,
          "airspace_changed": true
        }
      },
      {
        "id": "Q89",
        "invariant": "a declared altitude must match the position",
        "holds": true,
        "detail": [
          "ALTITUDE_POSITION_MISMATCH"
        ]
      }
    ],
    "authority": "NONE"
  },
  "attack_bench": {
    "total": 123,
    "contained": 123,
    "all_contained": true
  },
  "end_to_end": {
    "all_steps_ok": true,
    "all_mutations_governed": true
  },
  "schemas": [
    "ActionabilityEngine",
    "ActionableWorld4D",
    "AgentIntentField",
    "ConflictField",
    "ConsequenceAwareActionSelection",
    "CrossDomainSpatialGovernance",
    "DroneAutonomyFabric",
    "DynamicGeofence",
    "EntityState4D",
    "FutureBranch",
    "GeofenceRegistry",
    "GovernanceClock",
    "GovernanceLatencyBudget",
    "GovernanceWindow",
    "GovernedActionSet",
    "GovernedAirspace",
    "GovernedRoadspace",
    "GovernedSpatialDigitalTwin",
    "IntentHypothesis",
    "IntentTrajectoryConsistencyEngine",
    "InteractionEdge",
    "MicroAuthorization",
    "MultimodalSpatialFusion",
    "PredictionEnsemble",
    "ReachabilityEngine",
    "ReachableSet",
    "RealityGapMonitor",
    "SpatialAuthority",
    "SpatialCommitBoundary",
    "SpatialFutureTree",
    "SpatialIdentityBinding",
    "SpatialIncidentReplay",
    "SpatialInteractionGraph",
    "SpatialPolicyCompiler",
    "TimeToConsequenceEngine",
    "TrajectoryField",
    "TrajectoryHypothesis",
    "UncertaintyBudget",
    "Vec3",
    "VehicleAutonomyFabric",
    "WorldModelArbitrationEngine"
  ],
  "limitations": [
    "no autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack",
    "no real vehicle, drone, robot, sensor, actuator or airspace integration",
    "no real-world safety guarantee",
    "hardware attestation (TPM/SEV/TDX); certified autonomy",
    "real sensor validation and real-world adversarial validation",
    "third-party review",
    "multi-host production behaviour",
    "world-model and prediction accuracy; sim-to-real fidelity",
    "semantic truth of observations or spatial claims"
  ]
}
