Skip to content

Agent Passports, Time Travel, Constraint Observance and retention

Phase 3 of the Authority Control Plane is about principals and evidence. Every agent gets a Passport, a signed and versioned document any party can check that says who the agent is, who owns it, what model and prompt it runs, what it may touch and how it has behaved. Every decision gains Authority Time Travel: the authority exactly as it stood at execution time, and what has changed since. Proof packs gain a Proof of Constraint Observance. And evidence gets a retention schedule that erases payload on time while every hash and proof stays.

Agent Passports (XAP)

A passport is issued when an agent registers, re-issued as a new version whenever what it states changes (a declaration, an attestation that did not match, a revocation), and revoked with the agent. Format xybern-passport-v1, token prefix xpp1., signed with the Provenance Vault's published ECDSA key, the same key that signs warrants and stamps.

Field Meaning
principal agent id, name, DID, credential fingerprint, kind, framework
owner the accountable owner as a pseudonymous id the issuer resolves on lawful request
organisation workspace, department, external organisation for federated agents
model, system_prompt_hash declared by the SDK at registration or later; the prompt hash is attested at every session start
approved_tools, permitted_models, data_clearance declared, else derived from the access profile or the registered tool schemas
financial_authority the largest single amount the agent's derived authority and active missions allow
delegation_authority may delegate, requires a grant, maximum depth, grants received and given
risk_class, environment declared (low to critical, production to sandbox), else derived from trust and refusals
posture trust state and level, active warrants, missions, sessions, decision counts, prompt drift count
last_attestation when the SDK last attested the prompt hash, and whether it matched
trust_history the trust states the agent has moved through

Declare with the SDK: client.register_agent("Payer", model={"family": "claude-sonnet", "version": "5"}, prompt_hash=sha256_of_prompt, environment="production", risk_class="medium", approved_tools=[...], data_clearance="CONFIDENTIAL"), later client.declare_agent(agent_id, risk_class="high"). Attest with client.start_session(agent_id, prompt_hash=...): a hash that differs from the declared one is recorded as prompt drift, sealed to the Vault and shown on the passport (a mandate may refuse on it; the attestation itself never allows or refuses).

Resolve at GET /proof/passport/<passport_id> on the issuer's host (JSON, or HTML in a browser): validity, current version, the full body, how many times it was checked. A superseded or revoked version says so and names the current one. The issuer record at /.well-known/xybern-issuer/<id> names the passport resolver. Verify offline with tools/xybern-verify --passport <token> --keys keys.json.

The passport travels with the evidence: the receipt names it (action.agent.passport), the stamp carries its id (agent.passport), the Authority Graph node shows it. The Passports view (Agents group) lists every agent's passport, model and prompt attestation, authority and posture, with re-issue and declaration by hand.

Authority Time Travel

GET /v1/enforce/decisions/<id>/authority renders the authority as it stood when the decision was made, from what was sealed at the time: the Charter version and its mandate list, the compiled rule set, the warrant body, the mission and its judgement, the agent and its passport version, the Authority Slice and its invariant findings, and the lineage sentence. It then names every change since (a new Charter version, a changed rule set, a revoked warrant, an ended mission, a revoked agent, a newer passport). In the decision record, Authority at decision time opens the same view side by side, then and now. Nothing is reconstructed by guessing; where a version row is missing the response says so and keeps the sealed hash.

Proof of Constraint Observance

A signed proof pack over a window and a constraint (a rule, a mandate, a mission, an invariant or an action family): the channels the layer controlled (SDK intercept, MCP gateway, AI gateway, relay) with the actions each carried, the actions the constraint spoke to, the violations observed and how each was decided, and a coverage statement. It is a record of what the layer saw and decided, never a claim about paths that did not pass through it, and the pack says so in its statement and its coverage.not_covered.

Generate from the Proof view (Proof of Constraint Observance) or POST /v1/enforce/proof/constraint-observance with {constraint: {kind, id}, from_date?, to_date?}. The public page at /proof/<pack_id>?t=<token> renders the constraint, coverage, channels and violations, and the pack verifies like any other.

Evidence retention

Evidence is kept by class:

Class Default What happens on schedule
payload 365 days the action content is replaced by its SHA-256 and every argument value by its SHA-256; the decision remembers when
request 90 days verification records (the judge's inputs and reasoning) are deleted
decision_metadata kept the decision row: type, decision, rules, lineage, Authority Slice
proof_hash kept vault entries, hashes and signatures
financial_authorisation 3650 days decisions that carry an amount keep their payload for this long instead of the payload period

Install defaults come from XYBERN_RETENTION_<CLASS>_DAYS; a workspace may shorten a period (never lengthen past the install default) through PUT /enforcement/retention. Receipts generated after erasure still carry the original content_sha256 and metadata_sha256, so they verify against what the Vault sealed; action.erased says when and under which class. The Deployment Manifest states the schedule under retention.evidence_classes. Erasure is hash-preserving by overwrite; per-period payload keys are a later step and the manifest would say so.

The Authority model view

Under Oversee, Authority model shows the ontology every decision is made with, live for this workspace: the eight primitives with counts (agents, roles, passports; action types observed; resource classes; missions and sessions; warrants, grants, profiles, windows, mandates; rules, decay and lease; decisions and authority events; stamps, attestations, co-authorisations), the eight invariants with their Charter lint status and violations in the last 30 days, the outcomes of the last 30 days, the open formats and their status, the retention schedule, and a resolver that shows the Authority Slice for any agent and action without deciding.