pki.sgit.ai / documents / enrolment

Agent Enrolment Without Borrowed Authority: The Append Lane Is The Narrow Door

TypeArchitecture brief Versionv0.33.60 Date19 August 2026 AuthorDinis Cruz (project lead) and collaborators LicenceCC BY 4.0 Sourceraw markdown · view on GitHub

Summary

An enrolment architecture that lets an agent obtain a project-recognised identity starting from nothing but a keypair — no repository credential, no project token, no certificate authority key, no vault key, no administrator identity — because every one of those grants authority broader than the identity being created. The agent signs a canonical request over its own public key, delivers it through an append lane whose granted capability is to add an object to an inbox and nothing else, and a trusted processor holding the issuing key reads the inbox, applies policy and publishes the result. Identity and mandate stay separate signed statements throughout.

Key concepts

Key ideas

On this site

Became the enrolment page. Its milestones were revised down by the append-lane correction published two days later.

Read the document

📄 Original document · v0.33.60 · 19 August 2026 · rendered from the raw markdown (the source of truth)