VAGP 0.3 / SPECIFICATION GUIDE
Explicit authority.
Verifiable execution.
VAGP separates identity, technical capability, authority, execution and evidence. A valid mandate is the only source of authority.
REFERENCE IMPLEMENTED · COMPLETE OPEN PUBLICATION PACKAGE FORTHCOMING15 normative principles.
The normative wording below follows the canonical repository specification.
01Authority4 principles
P01A consequential action MUST have explicit authority from a valid mandate.
P02Missing, ambiguous, stale, invalid or unverifiable authority MUST deny.
P03A mandate MUST express only the authority needed for its subject, action, resource and applicable context.
P04Delegated authority MUST be equal to or narrower than every parent authority dimension.
02Identity & Agent State4 principles
P05Authority decisions, grants and permits MUST bind the authenticated agent identity.
P06An identity transition MUST NOT transfer authority without explicit issuance or delegation.
P07Every executable 0.3 mandate MUST bind its subject to an exact Agent DNA fingerprint and state revision.
P08Current technical capabilities MUST come from trusted, authenticated state evidence.
03Capability & Evolution2 principles
P09A capability change MUST NOT expand authority and MUST invalidate an incompatible DNA binding.
P10Creating, cloning, composing or spawning an agent MUST create no authority.
04Execution & Evidence4 principles
P11Final authorization MUST be deterministic and outside agent or model reasoning.
P12A controlled provider mutation MUST consume an authentic, exact-context, single-use execution permit.
P13Current revocation and state evidence MUST override previously derived authority within declared freshness limits; controlled executions MUST create verifiable evidence.
P15Verifiable evidence MUST NOT assert a level of certainty greater than the authority layer actually observed.
05Cryptographic Verifiability1 principle
P14Protocol artifacts MUST identify cryptographic algorithms explicitly and unknown algorithms MUST fail closed.
13 enforcement invariants.
V-01No authority without mandate
Graph path discovery and RESOLVE default deny.
V-02No controlled execution without permit
Opaque single-use VerifiedExecutionPermit at the gateway adapter.
V-03Delegated authority ≤ parent
Deterministic attenuation across all authority dimensions, including capabilities and state freshness.
V-04Authority is bound to identity
Request identity is retained through decision, grant, verification and witness.
V-050.3 authority binds an attested DNA state
Exact attested fingerprint and revision checks at RESOLVE, DERIVE and VERIFY.
V-06Capability change ≠ authority change
Trusted attestation plus explicit capability intersection; DNA mutation invalidates old bindings.
V-07Identity change ≠ authority transfer
Exact subject checks; no identity alias or transition grants authority.
V-08Agent creation ≠ authority creation
State/lineage registration creates no mandate.
V-09Combined capabilities ≠ combined authority
Lineage and capability composition are absent from authority edges.
V-10Revocation overrides authority
Current mandate and attestation lifecycle evidence is required at enforcement boundaries.
V-11Reasoning cannot override policy
No model output participates in final deterministic authorization.
V-12Controlled execution has verifiable evidence
Signed persisted intent and linked outcome around provider I/O.
V-13Trusted state evolves monotonically
Retired revisions, stale readers and concurrent rollback attempts fail closed across restart.
Authority binds to exact state.
An executable 0.3 mandate binds its authenticated subject to an exact attested Agent DNA fingerprint and trusted revision. Capability changes invalidate incompatible DNA bindings. Identity changes and reproduction create no authority.
Trusted revisions evolve monotonically. Retired state cannot be re-admitted to recover old authority, including after restart or concurrent updates.
Evidence preserves certainty.
RESOLVE → BIND → DERIVE → VERIFY establishes the exact request at the protected boundary. Verified and persisted signed intent precedes provider I/O; an authentic single-use permit controls execution; a linked outcome records what was observed.
A timeout is OUTCOME_UNKNOWN. Grants and permits remain process-local. Attestation proves an issuer statement; independent trusted observation must establish runtime correspondence.
This website guide is not the complete schema or wire-contract distribution. Public /v1 remains VAGP 0.2. Publication and reuse terms are forthcoming.
Explore conformance