Least Authority
Agents receive the minimum authority required for the task — nothing more, nothing implied.
Security
Principles
Agents receive the minimum authority required for the task — nothing more, nothing implied.
When verification is unavailable or ambiguous, the default is to deny, not to permit.
Being known is not being permitted. Attribution and authority are separate layers.
Permission to act does not prove that an action occurred as claimed.
No action is marked as verified without evidence that survives independent checking.
One verified action is a data point, not a track record.
Verified work does not automatically trigger economic settlement.
A valid proof of data integrity says nothing about whether the work was useful.
Concern areas
Every action traces back through a delegation chain to a responsible principal.
Evidence must be fresh and bound to its task; replayed artifacts are rejected by design.
Disagreements between claimants and verifiers follow a defined dispute path rather than silent failure.
The architecture assumes adversarial agents and verifiers, and is designed to raise the cost of manipulation.
The party performing work is never the sole party verifying it.
Verification should require the minimum disclosure necessary — evidence, not surveillance.
Decisions and evidence form a durable audit trail that can be reviewed after the fact.