Who are you?
Authentication establishes the caller.
VAGP 0.3 / INTERACTIVE EXPLANATIONS
Explore how explicit mandates constrain capable agents. These educational simulations make the reference profile’s authority and evidence boundaries inspectable.
THE SHIFT / FROM SOFTWARE TO ACTORS
They choose tools, coordinate work, acquire capabilities and create other agents. Access alone cannot explain which organisational mandate authorizes their next consequential action.
Authentication establishes the caller.
Tools and attested state establish technical capability.
A valid mandate establishes the bounded right to act.
Verimand complements IAM, RBAC and policy engines. Your identity infrastructure stays; organisational authority becomes explicit.
Understand the authority gapAGENT DNA / AUTHORITY BINDS TO STATE
Agent DNA fingerprints the security-relevant configuration: runtime, instructions, policy, capabilities, tools and environment. An executable 0.3 mandate binds both the DNA fingerprint and trusted state revision.
DNA-AA trusted issuer attests the current DNA. The mandate binds its exact fingerprint and revision.
Illustrative state transitions, not computed fingerprints or signed attestations. A trusted observer must establish correspondence between the manifest and the applied runtime.
CONSERVATION / DELEGATION ONLY NARROWS
A child cannot gain a privilege, capacity or time window its parent did not hold. Every applicable dimension must fit within one complete qualifying path.
Delegation can restrict authority. It cannot add an ADMIN dimension absent from its parent.
Child: DEV
Within the original authority.
CONSERVEDIllustrative conservation constraints, not a budget calculator or a protocol evaluator.
stop VM
DEV only
read
PROD
REQUEST stop PROD VM
Authority cannot be assembled from unrelated paths.
MULTI-AGENT SYSTEMS / CREATION IS NOT ISSUANCE
Cloning, spawning and composition produce new agents. Lineage records their origin. Explicit issuance or delegation is still required before they may act.
Capability: analyse data
Capability: execute payments
New identity · new DNA
No authority inherited
Parentage explains where an agent came from. It does not establish why it may act.
ARCHITECTURE / AT THE EXECUTION BOUNDARY
A deterministic path outside model reasoning. Inspect each boundary to see what it establishes and what would fail without it.
Find one complete, current authority path for the exact request.
RESOLVE → BIND → DERIVE → VERIFY is the protocol sequence. Verified, persisted INTENT precedes provider I/O; permit consumption guards EXECUTE; WITNESS records the linked outcome. No model makes the final authorization decision.
AUTHORITY_CONFIRMED is an authority result, not a final business decision. ADDITIONAL_STATE_REQUIRED requires further state. Resource-side VERIFIED may precede execution; REJECTED means BLOCKED.
Inspect the implementation mapONE ECOSYSTEM / FOUR DISTINCT LAYERS
VAGP defines the authority model. Verimand builds implementation, enforcement and enterprise infrastructure around it. The intended open protocol does not require buying the commercial platform; publication and reuse terms are forthcoming.
The specification, authority semantics and conformance model. VAGP is being prepared for open publication.
Explore the protocolAPI for systems. SDK for developers. MCP for agent-native access. These interfaces carry requests; they do not confer authority.
Inspect the integration directionThe protected boundary between agents and tools, services or APIs. Verify current authority before a consequential action.
Understand enforcementThe future managed service and enterprise control plane around VAGP: mandates, Agent DNA, revocations and evidence.
Explore the platform directionEVIDENCE / P15
A signature proves authenticity, not certainty. Verifiable evidence must never assert more than the protected execution boundary actually observed.
Verified and persisted before the controlled provider call.
INTENT → PROVIDER I/OThe request was dispatched. No definitive result was observed. The action may have occurred; a timeout does not prove failure.
SIGNED EVIDENCE ≠ GREATER CERTAINTYIllustrative witness states. No signatures are generated here. Host trust policy defines which provider results establish definitive failure; ambiguity defaults to OUTCOME_UNKNOWN.
TRUSTED STATE / V-13
Replaying a previously valid state must never revive authority. Monotonic trusted state is a protocol property, independent of the storage technology.
Trusted state moves forward. Retired revisions stay retired across restart, concurrent writers and stale readers.
THE PROTOCOL / 15 PRINCIPLES · 13 INVARIANTS
VAGP 0.3 makes authority, agent evolution and execution evidence separate concerns. Explore the principles behind the reference profile.
P01A consequential action MUST have explicit authority from a valid mandate.
P02Missing, ambiguous, stale, invalid or unverifiable authority MUST deny.
P03A mandate MUST express only the authority needed for its subject, action, resource and applicable context.
P04Delegated authority MUST be equal to or narrower than every parent authority dimension.
P05Authority decisions, grants and permits MUST bind the authenticated agent identity.
P06An identity transition MUST NOT transfer authority without explicit issuance or delegation.
P07Every executable 0.3 mandate MUST bind its subject to an exact Agent DNA fingerprint and state revision.
P08Current technical capabilities MUST come from trusted, authenticated state evidence.
P09A capability change MUST NOT expand authority and MUST invalidate an incompatible DNA binding.
P10Creating, cloning, composing or spawning an agent MUST create no authority.
P11Final authorization MUST be deterministic and outside agent or model reasoning.
P12A controlled provider mutation MUST consume an authentic, exact-context, single-use execution permit.
P13Current revocation and state evidence MUST override previously derived authority within declared freshness limits; controlled executions MUST create verifiable evidence.
P15Verifiable evidence MUST NOT assert a level of certainty greater than the authority layer actually observed.
P14Protocol artifacts MUST identify cryptographic algorithms explicitly and unknown algorithms MUST fail closed.
VALIDATION / FINDINGS DRIVE THE WORK
Implementation, independent review, hardening and retest are distinct evidence. The version and scope matter.
Agent DNA, attested capabilities, exact-state mandates and linked signed evidence. Initial implementation: b3b697b.
Adversarial review found enforcement defects and gaps in regression and conformance coverage.
Revision concurrency, intent verification and uncertain provider outcomes addressed in bb18346.
The retest assessed bb18346 and identified remaining regression, persistence and vector work.
Follow-on tests, persistence failure classification and fixed Ed25519 evidence vectors. P15 and V-13 made explicit.
FOUNDATION / VERSIONED VAGP 0.2 EVIDENCE
The earlier frozen VAGP v0.2 authority model was demonstrated on Google Cloud and Microsoft Azure. These Proofs of Value establish the 0.2 foundation; they are not live proof of the 0.3 profile.
One frozen authority protocol. Two real cloud identity ecosystems. Same organisational authority model.
Google Agent Identity
Secret-version state
VAGP v0.2 live PoV completeDevelopment executed. Production blocked by NO_AUTHORITY. Post-DERIVE revocation rejected. Experimental, not a production service.
docs/pov/verimand-multicloud-authority-pov-v0.2.md · 2026-09-08
Entra Agent Identity
Azure VM operation
VAGP v0.2 live PoV completeDevelopment VM deallocated. Production blocked by NO_AUTHORITY. Post-DERIVE revocation rejected. Experimental, not a production service.
docs/pov/verimand-multicloud-authority-pov-v0.2.md · 2026-09-08
Evidence snapshot · 8 September 2026. Identity layer differs per cloud. Verimand complements IAM/RBAC; it does not replace them. No production readiness claim.
THE NEXT STEP / A BOUNDED AUTHORITY PILOT
Start with one consequential workflow, a protected execution boundary and evidence you can inspect. VAGP remains vendor-, infrastructure- and jurisdiction-neutral.
0.3 REFERENCE PROFILE · /v1 REMAINS 0.2 · NO PUBLIC 0.3 ADMISSION API