Delegating to AI agents
A third journey: Delegate.
Beyond Add and Prove, the direction is to let you hand an AI agent a narrow, time-boxed, revocable slice of your authority — provable to any EU relying party, enforced at runtime, and post-quantum from day one, even though the EU Business Wallet is not yet. You grant, scope and revoke agents will live in the wallet; the agent just runs, its key hardware-protected. The formal core ships today; the in-wallet management screens are in development.
Mandate
A scoped, revocable power to represent
The delegator (a person or business) issues a short-lived power-of-representation credential bound to the agent's own key. It names the exact operations authorised — nothing more — and and is revocable via its status list. The EU Digital Identity mandate is the interoperable, verifiable face of a Mandamus authority.
Enforce
An agent can never exceed what it was granted
The issuer cannot mint a mandate that widens a delegator's own powers, and a verifier cannot accept a request outside the granted scope, bound to the wrong key, or after revocation. The same monotonic-narrowing property is proved on both sides.
Govern
Human approval where it counts, receipts for everything
Consequential actions require a fresh iProov step-up bound into the authorisation; a higher assurance tier can raise the bar but never widen scope. Every action writes a hash-chained, tamper-evident receipt linked to the mandate.
Formally verified on both stacks: the issuer’s mandate gate and the verifier’s acceptance gate each carry a Lean-proved theorem that a delegate can only ever exercise a subset of the granted powers, only while the mandate is valid and non-revoked, only with the bound agent key. Not yet an EU-recognised model for machine agents — a designed, honest extension that converges when the EU power-of-representation Rulebook lands.