VERIMAND AUTHORITY GRAPH PROTOCOL · 0.1

Make authority provable.

VAGP represents organisational authority as bounded Mandates and exact graph paths, then carries that evidence toward one resource-side verification boundary.

Authority baseline · Independently reviewed

PROTOCOL SCOPE

Authority semantics only. VAGP does not make probabilistic, policy, approval or business-risk decisions.

FOUR CORE IDEAS

01Mandate

An immutable statement of bounded organisational authority.

02Attenuation

A child may preserve or restrict its parent’s authority, never expand it.

03Authority Graph

Canonical parent relationships form independently evaluated witness paths.

04Exact continuity

The subject, action, resource, context and path stay bound through execution.

AUTHORITY GRAPH

One complete path must witness the claim.

RESOLVE discovers bounded candidate paths, validates their current state and evaluates them independently. Authority from different paths is never merged into a synthetic answer.

Graph + multi-path RESOLVE · independently reviewed
LIVE AUTHORITY PATH STRUCTURALLY VALID
Organisational authority pathAuthority narrows from a board mandate through operations and an agent to one protected development resource.01Board mandate02Operations03Agent 1704dev/vm-204
BOUNDAgent 17Exact witness · no path merging

PROTOCOL OUTCOMES

Precise states at precise boundaries.

The protocol avoids general permission language. Each layer reports only what it has established.

RESOLVEAUTHORITY_CONFIRMED · NO_AUTHORITY · ADDITIONAL_STATE_REQUIRED
VERIFYVERIFIED · REJECTED
APPLICATIONEXECUTED · BLOCKED

FAIL-CLOSED INVARIANTS

Unknown authority semantics do not pass.

A Mandate with autonomy mode PROHIBITED grants no execution authority. Security-relevant resource and financial applicability context must come from authoritative sources. Exact resource binding is byte-for-byte; lookalikes do not match.

Probabilistic reasoning must never make the final authorisation decision.

Authority is distinct from policy, approvals and other business controls. An AUTHORITY_CONFIRMED result says only that the authoritative dimensions presented as applicable were satisfied.

LIFECYCLE STATUS

01Attenuation → RESOLVE

Independently reviewed

02Reservations + budget lineage

Independently reviewed

03Revocation → Bound Decision → DERIVE → VERIFY

Built · review pending

04Portable signatures + Authority Receipts

Planned