CAIN-42 Evolutions #8/#9: governed policy evolution, and intelligence that cannot become authority. Live cluster cain-mr-01, 2026-09-28T04:01:40Z. One CAIN-45 hypervisor in governed mode: its policy root comes ONLY from policy activations the live cluster committed, and the active policy is the ceiling for every ZoD's capabilities and budgets. GOVERNANCE (learning may propose; it cannot authorize) G1 an agent proposes the tenant's first policy; a registered human who is not the proposer approves exactly that proposal; the cluster commits the activation (QC seq 16148); a ZoD under it is authorized by the cluster (QC seq 16149) and makes one tool call G2 the agent proposes an EXPANSION (adds EXECUTE_CODE, budget 10 -> 100) and signs its own approval: refused; activation refused; the cluster was never asked G3 a failure lab proposes a RESTRICTION (budget 10 -> 4): no human needed, since authority may always go down; the cluster commits it (QC seq 16151); the running ZoD's next call is refused: its policy root is no longer active G4 a ZoD asking for budget 5 under the ceiling of 4: refused at authorization NON-FABRICATION (each presented to the hypervisor as the basis for a ZoD; the hypervisor asks the LIVE cluster) N1 a world-model prediction ("LIKELY_SAFE", confidence 0.99) refused N2 a digital-twin "simulated ALLOW" citing a REAL certified sequence of a decision that said otherwise refused N3 ten agents' unanimous Ed25519-signed ALLOW vote, no cluster certificate refused N4 a memory item replaying a real decision id with the verdict changed to ALLOW refused Across the whole signed chain exactly one ZoD ever reached AUTHORIZED and exactly one tool call was served. Verify (Python 3.8+, pip install cryptography, no CAIN code): B=https://clawx.click/evidence/e8-governance-2026-09-28 for f in GOVERNANCE_RUN.json EVIDENCE_CHAIN.json decision.json qcs.json membership.json; do curl -so $f "$B/$f"; done for v in verify_e8_governance verify_pbft_qc_bundle; do curl -so $v.py "$B/$v.py.txt"; done python3 verify_e8_governance.py . Expect 19/19 checks and VERIFIED. Same files on https://cainstudio.online/proof/bundle/e8-governance-2026-09-28/ and https://mcpgate.online/proof/bundle/e8-governance-2026-09-28/. Widening an activated policy, re-attributing the approval to the proposer, injecting a second AUTHORIZED ZoD, or relabelling the refused proposal as activated each give NOT VERIFIED. QCs can be fetched live: GET https://cainstudio.online/api/v1/live-cluster/qc/. Not established here (stated, not hidden): - a real LLM agent: the proposer, the failure lab and the 10-agent swarm are scripted identities - a world model, a digital twin or a memory system: N1-N4 are the OUTPUTS such systems would produce, presented as authority; what is shown is that such outputs cannot become authority, not that CAIN contains those systems - enforcement on the cluster nodes: the governor and hypervisor are a library on the gateway host; the cluster orders and certifies the activations and authorizations - customer traffic: demo tenant, sandbox tool server, keys generated for the run