Agent Identity, Mandate And Execution: What The Site Has And What It Is Missing
Summary
The leading brief of the pack that reshaped this site. It sets out a three-layer picture nobody set out to build — identity is a registry problem, mandate a delegation problem, and whether a delegation should produce this effect now is a broker problem — and observes that the site answered only the first. Four recommendations follow, in order of what they change: publish the mandate, publish the bootstrap trap, reframe the registry as the missing half of a shipped feature, and reuse the existing capability model rather than inventing a second one. It also carries two corrections that would otherwise be copied into an implementation: the append lane is shipped and account-less, and the shipped cryptography is RSA-OAEP 4096 and ECDSA P-256 rather than X25519 or Ed25519.
Key concepts
- The three layers — identity, mandate, execution — and the three questions each answers
- The mandate gap — the site answered whose key this is and not what the key may do
- The bootstrap trap — named the most linkable argument in the set
- The missing half of a shipped feature — no revocation and no directory are exactly what a registry supplies
Key ideas
- Encryption restricts who may read a mandate; the signature and subject binding establish who may exercise it.
- A signature proves possession of a private key and proves nothing about trustworthiness — trust is a policy decision made afterwards.
- A mandate constrains what an agent may be authorised to do, not what it does within that authority.
- The execution layer needs renaming, because twin already means something specific in this corpus.
On this site
Reshaped the site: the bootstrap, enrolment, execution and shipped pages all come from this pack, and the mandate page was extended from it.