Build order
The ordering is the design decision, not an implementation detail. A registry holding one organisation's agents can be tested, broken, and thrown away. A global public one cannot — it is a commitment the day somebody depends on it.
A registry with one organisation's agents in it is testable; a global one is a commitment.
The order
The collection, organised by question
The material exists in depth — 729 files in the corpus mention the subject, with dedicated documents going back to February 2026: an architecture debrief, a messaging implementation, model-integration research, a document identity brief, operating modes, a provenance treatment, a brand strategy. So this is a publication and curation problem, organised by the question a reader arrives with rather than by date.
Status: queued — needs the corpus documents identifiedThe failure page
Short, useful, and independent of anything being built. The most linkable thing the site will have, and the evidence that what follows was designed with the history in hand.
Status: done — read itThe four rules, published before the registry exists
The registry's stated design, as claims that can be checked against whatever ships. Four sentences that answer the question a reader will have.
Status: done — read themThe other two obstacles, published alongside
Added after review: the failure page explains why the last generation of key repositories was destroyed, and the bootstrap trap explains why the next generation has not been built. Those are different obstacles and a registry has to clear both. Enrolment is the path through the second, and the execution layer is named because identity and mandate cannot answer a question about what actually happened.
Status: done — the argument pages, ahead of any implementationA private registry, for our own agents
The smaller problem, and the one with a real user. Inside one organisation the trust root is not an open question, abuse is not an open question, and moderation is not an open question — which leaves the actual registry logic as the thing being tested. And the user is now concrete rather than hypothetical: somebody already running the shipped PKI commands who has hit the two absences.
Status: planned — first-pass pack published. A five-brief MVP pack (leading brief, architecture, schemas, workflows, build order) proposes the shape: public in data, private in authority — this step with the covers off, not step 6 early. Now a full dev pack with diagrams, change control and a tabletop exercise; three v0.33.61 briefs landed the same day and their corrections are recorded in change control. Awaiting project-lead adoption (N6)Mandate statements, separate from identity
Independently revocable signed statements about what an agent may do. The concept and its fields are published; the implementation follows the private registry, because a mandate with nowhere to live is a document. It cannot be finished without answering the attestation question, since a mandate issued by somebody other than the agent is a third-party attestation.
Status: not started — blocked on a decision rather than on workA public registry — last
It inherits every hard problem of the private one, plus trust roots, abuse and moderation. It is also the memorable idea, which is exactly why it is the one to be disciplined about.
Status: not started — and deliberately behind step 4Step 4 before step 6 is the ordering that matters. Everything else can move.
What this does not try to be
| Not | Instead |
|---|---|
| A new key server | A registry designed from a documented failure, with different rules |
| Append-only in the way that failed | Append-only with the writer owning what it writes |
| Deletion-free | Revocation is a signed append, which supersedes without destroying |
| Automatically a web of trust | Third-party attestation is a deliberate choice with a known cost |
| Public first | Private first — testable before committed |
Honest tensions
Published because a design page that lists only what works is marketing:
| Tension | Note |
|---|---|
| Append-only as house pattern | It is right for channels and it is what destroyed the key servers. The ownership rule is the whole of what separates them, so it carries a great deal of weight for one sentence |
| Third-party attestation | What made the old system valuable and what made it attackable — and mandates may need it |
| Size bounds on records | They prevent the flooding attack, and they will one day reject a legitimate record |
| Fractal trust | Nesting is powerful and it requires every store to declare its roots, or the graph is unevaluable |
| Public registry | The memorable idea, carrying abuse, moderation and trust-root problems a private one does not |
| Reusing existing material | 729 documents is depth, and most of it will not appear on the site |
Open questions — what is argued, and what is genuinely open
Publishing questions unresolved is the discipline. Publishing them as if nothing had been said about them is not: a cross-reference review of the corpus found that four of the six below already have substantial arguments behind them, some running to thousands of words. An open question with an argument behind it reads very differently from one with nothing, so the table now says which is which.
| Question | State | Where it stands |
|---|---|---|
| Does the registry accept third-party attestations? | argued, decision pending | A working design exists — third-party scanners sign their results, receiver-readable and hash-bound to the file — alongside a multi-dimensional web-of-trust model. The attack surface has also been analysed. What is missing is the call, not the argument |
| Who may be a trust root? | argued, decision pending | The deepest trust-model work in the corpus addresses it directly, including equivocation witnessing and atomic trust-graph writes. Raised three times in two days and still unresolved — a chain cannot terminate without it |
| Is a mandate a separate object from an identity? | argued — yes | Answered twice: mandate is delegation, and the right to ask is separable from the means to act. They revoke independently, so they are separate objects |
| What does an agent's identity attest to? | argued, decision pending | Accountability happens when privileges are assigned, not when the model acts — and the newest thinking moves attestation from the actor to the write itself |
| What is the size bound per record? | genuinely open | Operational limits exist upstream, and the growth question has since been reframed — the bound belongs on the entry file, not the history. The number is still unchosen |
| How is the binding between an agent and its key verified? | genuinely open | A design was proposed in March (well-known documents, DNS records, a verification endpoint) and never built. The replacement keyserver used email; agents have no equivalent |
Newly opened, 20 August
Four briefs on one day opened more than they closed. These are the questions this site now carries that it did not this morning:
| Question | Why it matters |
|---|---|
| What forbids a reset on the register's published branch? | A stated policy, a published head and a server-side rule are not equivalent. The proposed fifth rule picks the second |
| How often is the head published, and where? | Too rare and a rewrite hides inside the gap; too frequent and it becomes its own growing record |
| Does a revocation supersede the entry or add a field to it? | The clean-file rule says supersede — and a consumer wants to see revoked without doing a traversal |
| Which verification mode ships first — signed assertion, or live lookup? | Two products with opposite properties, and building both at once means neither is finished |
| Is the notary's query graph retained at all? | Billing needs a count, not a subject. The separation should be structural rather than a retention policy |
| What is rendered when an edge has never been checked? | Distinct from unreachable and from denied, and the default decides how the whole register reads |
| Who reviews a mandate when the provider adds a capability? | A grant grows on somebody else's release schedule — and a deny-list mandate widens with it, silently |
| Has any vendor shipped a signed surface claim? | The dated tripwire. It needs an owner and a re-run cadence, and anybody who shows one refutes the claim |