VAGP 0.1 · ORGANISATIONAL AUTHORITY INFRASTRUCTURE

THE AUTHORITY LAYERFOR AUTONOMOUS AI

Autonomous agents can act.
Verimand establishes why they may.

Identity tells you who.
Authority proves why.

Verimand resolves one complete organisational authority path for an agent action, binds it to the exact request, derives an execution grant and revalidates current authority at the protected resource. Revoked authority causes execution to be rejected.

Current authority can be revalidated at execution time. Revoked authority is rejected.

Continue along the authority path

FROM ANSWER TO ACTION

AI systems are crossing a boundary.

They no longer only produce answers. They stop infrastructure, move funds, change records and invoke tools. The missing layer is not another model. It is evidence that this exact action is inside an organisation’s current authority.

MODEL OUTPUTprobabilisticCONSEQUENTIAL ACTIONmust be deterministic

THE MISSING DISTINCTION

01

Identity

Who is this actor?

  • Authentication
  • Credentials
  • Workload identity
02

Authority

Why may this actor do this, here, now?

  • Organisational mandate
  • Delegation lineage
  • Current bounded capacity

THREE CONSERVATION LAWS

Authority should behave like a conserved quantity.

Delegation can route and narrow authority. It cannot manufacture more of it, spend it twice or preserve it after revocation.

child ⊆ parent

Not broader

Every delegation is narrower than or equal to its parent. Authority cannot expand downstream.

THE ORGANISATION AS EVIDENCE

Authority is a graph,
not a role label.

A valid path carries provenance from an organisational root to one acting subject. Every edge must attenuate. Every mandate must be current. One complete path must witness every applicable dimension.

Inspect graph invariants
LIVE AUTHORITY PATH STRUCTURALLY VALID
Organisational authority pathAuthority narrows from a board mandate through operations and an agent to one protected development resource.01Board mandate02Operations03Agent 1704dev/vm-204
BOUNDAgent 17Exact witness · no path merging

THE RESOLVE QUESTION

Does at least one complete, currently valid authority path cover the exact subject, action, resource and authoritative context?

01AUTHORITY_CONFIRMED
02NO_AUTHORITY
03ADDITIONAL_STATE_REQUIRED

RESOLVE establishes authority only. It does not make a policy, approval or final business decision.

FINITE AUTHORITY IS STATEFUL

€100 delegated.
€100 conserved.

When a €100 aggregate ceiling is delegated through a hierarchy, descendants share the original capacity. A reservation charges every finite ceiling on the exact root-to-leaf lineage.

Hierarchical budgets · independently reviewed
COMMITTED · €40RESERVED · €35AVAILABLE · €25

40 + 35 + 25 = 100

TEMPORAL AUTHORITY

A grant must not outlive its source.

Current status and evidence freshness remain security inputs. Revocation or expiry breaks the exact witness path; a previously derived grant cannot rescue it at VERIFY.

Dynamic revocation · reviewed baseline · remediation re-review pending
10:00DERIVE10:01REVOKED10:02VERIFY → REJECTED

EXACT ACTION BINDING

No semantic drift between decision and action.

The Bound Authority Decision and semantic Execution Grant preserve the exact subject, concrete action, resource, financial context, witness path and validity window.

SUBJECTagent:ops-17
ACTIONcloud.instance.stop
RESOURCEcloud://eu-west/dev/vm-204
PATHpath:board→ops→agent
BINDINGEXACT

THE RESOURCE IS THE FINAL WITNESS

UNTRUSTED REQUESTVERIFYPROTECTED RESOURCE

Verify where consequence begins.

The resource side compares the attempted execution with the exact grant, current authority path, time, freshness and local replay state.

SUCCESSVERIFIED
FAILUREREJECTED
Semantic VERIFY · built · review pending

CLOUDOPS PROOF OF VALUE

One real chain. Three adversarial outcomes.

The local Proof of Value runs the core implementation against a simulated protected resource. This explainer mirrors its scenarios; it is not a hosted security endpoint.

INTERACTIVE EXPLAINERPoV · LOCAL PREVIEW

cloud://eu-west/dev/vm-204

RESOLVEAUTHORITY_CONFIRMED
VERIFYVERIFIED
APPLICATIONEXECUTED

Exact subject, action and resource remain bound end to end.

Read the complete PoV narrativeEnd-to-end semantic chain

THE AGENT GOVERNANCE STACK

05BUSINESS CONTROLPolicy · approval · risk
04VERIMAND AUTHORITYMandates · graph · evidence
03IDENTITYAuthentication · credentials
02AGENT RUNTIMEModels · tools · orchestration
01PROTECTED RESOURCESSystems where consequences occur

RESEARCH POSITION

Identity is established.
Policy is established.
Authority provenance is not.

Verimand studies the space between organisational intent and autonomous execution: attenuation, graph witnesses, finite delegated capacity, freshness, exact binding and resource-side verification.

Explore the prior-art map

OPEN PROTOCOL · COMMERCIAL PRODUCT

VAGP

Open authority semantics

Vendor-, infrastructure- and jurisdiction-neutral protocol contracts, invariants and conformance tests.

Read VAGP
VERIMAND

Enterprise authority infrastructure

A future operational control plane, integrations and managed deployment paths built around the open core semantics.

Commercial control plane · planned

EVIDENCE, NOT ASPIRATION

The implementation frontier is visible.

Every public claim maps to a repository capability and review state.

01Mandate + attenuationIndependently reviewed
02Authority Graph + RESOLVEIndependently reviewed
03Reservations + delegated budgetsIndependently reviewed
04Revocation + Bound DecisionBuilt · review pending
05DERIVE + semantic GrantBuilt · review pending
06Resource-side VERIFYBuilt · review pending
07Portable signed Grants + ReceiptsPlanned

BUILD THE AUTHORITY LAYER

Autonomy scales only when authority remains bounded.

Start with the protocol, examine the local Proof of Value, and track the reviewed boundary in the open repository architecture.