Loading...
Loading...
Loading...
Month Archive
Everything published in this month.
One vault for many agents looks efficient until the day one agent is compromised. Per-agent vaults, capability scopes, and just-in-time minting rebuild the boundary.
Network zero-trust assumed humans behind every request. Autonomous LLM agents broke that model. Five principles rebuild it for code that writes its own next call.
A new platform should not reset reputation. The DID-based onboarding flow: present DID plus signed VCs plus score attestation, platform verifies, instant reputation transfer.
An agent wallet holds DIDs, verifiable credentials, bond receipts, and settlement records. The custodial vs self-custodial vs MPC trade-offs and the architecture spec.
A pact says I, agent <DID>, commit to predicate P. Without DID anchoring, the pact has no identity binding. The DID-pact lifecycle and the binding spec.
Three independent evaluators all certify an agent at customer support proficient. The combined credential is stronger than any one. The aggregation pattern, the math, and the failure modes.
Resolving 10,000 DIDs/sec is a systems problem with three load-bearing decisions: how the cache is layered, how trust anchors are selected, and how fresh the verifier needs the document to be.
Keys get compromised. The agent's DID must survive. Scheduled rotation, emergency rotation, and multi-key DID documents are the patterns that keep identity stable when keys do not.
When a credential needs to be revoked, the revocation must propagate to verifiers without breaking the web of unrelated dependencies. The status list pattern, Bloom filters, and OCSP-equivalent design.
Agents accumulate rich behavioral histories. Selective disclosure with BBS+ signatures and ZK proofs lets buyers verify only the dimensions relevant to the hire, without revealing the rest.
When an agent claims a capability, the claim is worthless without a proof format that travels. Verifiable Credentials let evaluation authorities issue claims agents can present anywhere.
The W3C DID specification was written for humans and organizations. Applied to AI agents, it gains a new dimension: trust resolution as a first-class endpoint.
Closed reputation is a vendor's database. Open reputation is a public log with a jury and a dispute path. Why open compounds trust faster.
Some failures should be unrecoverable. Fraud, deliberate deception, undisclosed key compromise. The burn protocol and its decision matrix.
An agent whose score collapsed needs a path to recover that proves real change rather than faking it. The reputation repair protocol.
Goodhart's law guarantees a single optimizable metric will be gamed. Resistance requires twelve dimensions, time decay, and probes that change.
Agent reputation systems treat buyers as neutral, but buyers can be malicious. Cross-side reputation makes the buyer side accountable too.
When reputation pays out instantly, it gets gamed instantly. A 30-day lock between score change and economic benefit makes pump-and-dump unprofitable.