Skip to content

Journeys

What the identity runtime does across regulated wallet profiles, national identity systems, and delegated agents.

Delegating to AI agents

A third journey: Delegate.

Beyond Add and Prove, the direction is to let you hand an AI agent a narrow, time-boxed, revocable slice of your authority — provable to any EU relying party, enforced at runtime, and post-quantum from day one, even though the EU Business Wallet is not yet. You grant, scope and revoke agents will live in the wallet; the agent just runs, its key hardware-protected. The formal core ships today; the in-wallet management screens are in development.

Mandate

A scoped, revocable power to represent

The delegator (a person or business) issues a short-lived power-of-representation credential bound to the agent's own key. It names the exact operations authorised — nothing more — and and is revocable via its status list. The EU Digital Identity mandate is the interoperable, verifiable face of a Mandamus authority.

Enforce

An agent can never exceed what it was granted

The issuer cannot mint a mandate that widens a delegator's own powers, and a verifier cannot accept a request outside the granted scope, bound to the wrong key, or after revocation. The same monotonic-narrowing property is proved on both sides.

Govern

Human approval where it counts, receipts for everything

Consequential actions require a fresh iProov step-up bound into the authorisation; a higher assurance tier can raise the bar but never widen scope. Every action writes a hash-chained, tamper-evident receipt linked to the mandate.

Formally verified on both stacks: the issuer’s mandate gate and the verifier’s acceptance gate each carry a Lean-proved theorem that a delegate can only ever exercise a subset of the granted powers, only while the mandate is valid and non-revoked, only with the bound agent key. Not yet an EU-recognised model for machine agents — a designed, honest extension that converges when the EU power-of-representation Rulebook lands.