pki.sgit.ai / roadmap

Build order

The ordering is the design decision, not an implementation detail. A registry holding one organisation's agents can be tested, broken, and thrown away. A global public one cannot — it is a commitment the day somebody depends on it.

A registry with one organisation's agents in it is testable; a global one is a commitment.

The order

1

The collection, organised by question

The material exists in depth — 729 files in the corpus mention the subject, with dedicated documents going back to February 2026: an architecture debrief, a messaging implementation, model-integration research, a document identity brief, operating modes, a provenance treatment, a brand strategy. So this is a publication and curation problem, organised by the question a reader arrives with rather than by date.

Status: queued — needs the corpus documents identified
2

The failure page

Short, useful, and independent of anything being built. The most linkable thing the site will have, and the evidence that what follows was designed with the history in hand.

Status: done — read it
3

The four rules, published before the registry exists

The registry's stated design, as claims that can be checked against whatever ships. Four sentences that answer the question a reader will have.

Status: done — read them
3b

The other two obstacles, published alongside

Added after review: the failure page explains why the last generation of key repositories was destroyed, and the bootstrap trap explains why the next generation has not been built. Those are different obstacles and a registry has to clear both. Enrolment is the path through the second, and the execution layer is named because identity and mandate cannot answer a question about what actually happened.

Status: done — the argument pages, ahead of any implementation
4

A private registry, for our own agents

The smaller problem, and the one with a real user. Inside one organisation the trust root is not an open question, abuse is not an open question, and moderation is not an open question — which leaves the actual registry logic as the thing being tested. And the user is now concrete rather than hypothetical: somebody already running the shipped PKI commands who has hit the two absences.

Status: planned — first-pass pack published. A five-brief MVP pack (leading brief, architecture, schemas, workflows, build order) proposes the shape: public in data, private in authority — this step with the covers off, not step 6 early. Now a full dev pack with diagrams, change control and a tabletop exercise; three v0.33.61 briefs landed the same day and their corrections are recorded in change control. Awaiting project-lead adoption (N6)
5

Mandate statements, separate from identity

Independently revocable signed statements about what an agent may do. The concept and its fields are published; the implementation follows the private registry, because a mandate with nowhere to live is a document. It cannot be finished without answering the attestation question, since a mandate issued by somebody other than the agent is a third-party attestation.

Status: not started — blocked on a decision rather than on work
6

A public registry — last

It inherits every hard problem of the private one, plus trust roots, abuse and moderation. It is also the memorable idea, which is exactly why it is the one to be disciplined about.

Status: not started — and deliberately behind step 4

Step 4 before step 6 is the ordering that matters. Everything else can move.

What this does not try to be

NotInstead
A new key serverA registry designed from a documented failure, with different rules
Append-only in the way that failedAppend-only with the writer owning what it writes
Deletion-freeRevocation is a signed append, which supersedes without destroying
Automatically a web of trustThird-party attestation is a deliberate choice with a known cost
Public firstPrivate first — testable before committed

Honest tensions

Published because a design page that lists only what works is marketing:

TensionNote
Append-only as house patternIt is right for channels and it is what destroyed the key servers. The ownership rule is the whole of what separates them, so it carries a great deal of weight for one sentence
Third-party attestationWhat made the old system valuable and what made it attackable — and mandates may need it
Size bounds on recordsThey prevent the flooding attack, and they will one day reject a legitimate record
Fractal trustNesting is powerful and it requires every store to declare its roots, or the graph is unevaluable
Public registryThe memorable idea, carrying abuse, moderation and trust-root problems a private one does not
Reusing existing material729 documents is depth, and most of it will not appear on the site

Open questions — what is argued, and what is genuinely open

Publishing questions unresolved is the discipline. Publishing them as if nothing had been said about them is not: a cross-reference review of the corpus found that four of the six below already have substantial arguments behind them, some running to thousands of words. An open question with an argument behind it reads very differently from one with nothing, so the table now says which is which.

QuestionStateWhere it stands
Does the registry accept third-party attestations?argued, decision pendingA working design exists — third-party scanners sign their results, receiver-readable and hash-bound to the file — alongside a multi-dimensional web-of-trust model. The attack surface has also been analysed. What is missing is the call, not the argument
Who may be a trust root?argued, decision pendingThe deepest trust-model work in the corpus addresses it directly, including equivocation witnessing and atomic trust-graph writes. Raised three times in two days and still unresolved — a chain cannot terminate without it
Is a mandate a separate object from an identity?argued — yesAnswered twice: mandate is delegation, and the right to ask is separable from the means to act. They revoke independently, so they are separate objects
What does an agent's identity attest to?argued, decision pendingAccountability happens when privileges are assigned, not when the model acts — and the newest thinking moves attestation from the actor to the write itself
What is the size bound per record?genuinely openOperational limits exist upstream, and the growth question has since been reframed — the bound belongs on the entry file, not the history. The number is still unchosen
How is the binding between an agent and its key verified?genuinely openA design was proposed in March (well-known documents, DNS records, a verification endpoint) and never built. The replacement keyserver used email; agents have no equivalent

Newly opened, 20 August

Four briefs on one day opened more than they closed. These are the questions this site now carries that it did not this morning:

QuestionWhy it matters
What forbids a reset on the register's published branch?A stated policy, a published head and a server-side rule are not equivalent. The proposed fifth rule picks the second
How often is the head published, and where?Too rare and a rewrite hides inside the gap; too frequent and it becomes its own growing record
Does a revocation supersede the entry or add a field to it?The clean-file rule says supersede — and a consumer wants to see revoked without doing a traversal
Which verification mode ships first — signed assertion, or live lookup?Two products with opposite properties, and building both at once means neither is finished
Is the notary's query graph retained at all?Billing needs a count, not a subject. The separation should be structural rather than a retention policy
What is rendered when an edge has never been checked?Distinct from unreachable and from denied, and the default decides how the whole register reads
Who reviews a mandate when the provider adds a capability?A grant grows on somebody else's release schedule — and a deny-list mandate widens with it, silently
Has any vendor shipped a signed surface claim?The dated tripwire. It needs an owner and a re-run cadence, and anybody who shows one refutes the claim
These are refutation targets. Anybody who answers one well improves the design — including by showing that a rule is wrong. Comms is the channel.