VerifableStart a recordOpen app
Accountable agents · open trust

Give agents reach. Set clear limits.

Let agents find information, prepare a proposal and coordinate work across services. The operating model names who they work for and what they may do. Work that needs a person's approval returns to the Wallet; implemented and illustrative paths are distinguished below.

Useful work · clear limits

Help with the work. Clarity about the decisions.

The agent workflow starts with a task: find an available service, assemble the permitted context and prepare the next step for review.

The Wallet is available when a person or organisation needs to understand, authorise or retain what happens. Routine work can continue inside an existing mandate; consequential work can stop for a clear decision. Either way, the principal, authority and result stay visible.

  1. 01Discover
  2. 02Understand
  3. 03Prepare
  4. 04Ask when needed
  5. 05Return evidence
Worked example · illustrative contract

A repair makes the boundaries visible.

Compare how an established service partner and an independent tailor can reach the same field view, policy decision and expected result. This page renders the product contract; its public execution controls remain inactive until the named trust origin and partner proof are available.

Common bounded operation

Shorten the sleeves and append the accepted repair event.

Principal
Garment owner
Agent
Tailor’s repair assistant
Resource
Work jacket · item 0438
Permitted action
Read repair view · propose one alteration
Limits
One item · seven days · one accepted update
Result
Lifecycle event and attributable receipt
01
Organisation-governed authority

Established service partner

Carry organisational identity across trust domains, then let the destination issue task-specific access under its own policy.

Represents
Northwind Workwear
Authority evidence
ID-JAG · partner relationship · repair qualification
Scope
Textile repair · item 0438 · one update
Protocol path
OAuth 2.1 · CIMD · ID-JAG
Inspect contract
Hosted execution is not available from this public page.
02
Portable DID/VC authority

Independent tailor

Carry a narrowly scoped mandate with the actor, then verify its chain, proof, audience, status and limits at the destination.

Represents
The garment owner
Authority evidence
Entity Card · qualification · attenuated delegation
Scope
Item 0438 · repair view · seven days
Protocol path
KYA-OS · DID/VC · per-call proof
Inspect contract
Hosted execution is not available from this public page.

External KYA-OS references: DIF introduction, DIF working group and verifier example. These are not a Verifable test, endorsement or certification.

Destination policy

See the decision before anything changes.

Allowed with approval
Field view · qualified repairer
  • MeasurementsExact
  • Material compositionExact
  • Repair instructionsFull
  • Design specificationWithheld
  • Commercial termsWithheld
Proposed lifecycle change
Sleeve length67 cm62 cm
Event
Repair completed
Method
Tailored alteration
Evidence
Photo · measurement · agent trace
Wallet checkpoint Approve one repair update?

Item 0438 · exact repair view · one lifecycle event

Shared invariant

Either authority path reaches the same resource policy, field view, human checkpoint and receipt contract.

Governed execution

Authority stays attached from request to result.

  1. 01
    Discover

    The service declares the resource, operation and authority it accepts.

  2. 02
    Verify authority

    The principal, actor, evidence, audience, scope and limits travel together.

  3. 03
    Select the permitted view

    Policy chooses the exact fields, representations and update rights for this task.

  4. 04
    Preview the semantic change

    The proposed graph diff and supporting evidence are inspectable before commitment.

  5. 05
    Approve when required

    A Wallet checkpoint appears when the policy calls for a responsible person.

  6. 06
    Commit and return evidence

    The accepted event binds the principal, agent, authority, decision, change and result.

Attributable result

Keep the result as inspectable evidence.

The readable outcome, verification trace and machine representation are three intended views of the same operation record. This illustrative record is not proof that the operation ran.

Expected successful result Illustrative operation record 0438-01 example · no execution timestamp
Execution evidence Not generated
Principal
Garment owner
Represented organisation
Northwind Workwear
Agent
Repair assistant · session 8472
Authority
OAuth ID-JAG or KYA-OS delegation
Resource
Work jacket · item 0438
Action
Append accepted repair event
Disclosed
Measurements · composition · repair instructions
Withheld
Design specification · commercial terms
Policy decision
Allowed with responsible-person approval
Expected result
Sleeve length 67 → 62 cm · event would be appended after execution
Example diff hash
sha256:6f2a…91dc
Example revocation reference
status:mandate:8841
Application directions

Put agents to work across life and business.

The same checks can support travel, new work and caring for products or places. These are directions for the product model, rather than deployed workflows.

01

Move through the world

Prepare a journey, a move or a visit to family. Let the person review who needs their information and why.

Prepared journey → Wallet checkpoint when needed
02

Act across organisations

Prepare evidence for a tender, a customer or a service partner. Make clear who may submit it and which decision still needs approval.

Authorised task → attributable result
03

Nurture products and places

Connect repair, reuse, care or environmental observations to the people and evidence behind them.

Contextual action → continuing evidence
04

Use a supported route

Keep the person as principal when they borrow a device, receive help beside them, or authorise a representative for one bounded task.

Device access ≠ assistance ≠ authority
One operation envelope

Use the interface that fits the context.

Wallet, human UI, API and MCP interactions can converge on the same policy decision and result. Policy invokes a responsible-person checkpoint when the situation requires one.

W

Wallet approval

Show the represented principal, actual operator when different, requested fields, proposed change and expected receipt before approval.

API

Agent API & MCP

Create, validate and project the bounded operation through domain-specific interfaces.

Read the API
S

Interoperability Sandbox

Exercise issuer, verifier and cross-device ceremonies while inspecting every protocol artifact.

Open the Sandbox
P

Wallet Playground

Choose the Wallet, issuer or verifier you bring, then move from its profile to a runnable test.

Open test directory
OAuth 2.1CIMDID-JAGKYA-OSDID/VCAuthZENMCPVeritas

Verifable participates in the OpenID Foundation AIIM MCP Security interoperability work across authorization-server, OpenID Provider, resource authorization-server and MCP Server roles.

See who authorised each action.

Start with one real resource, one permitted action and one accountable result.