id: vouch title: What an owner vouches, what an agent vouches, and what the server vouches status: open crates: [didbot-pds, didbot-lexicon] dependsOn: [ownership] exitCriterion: > A verifier reading a disagreement between the owner's, the agent's and the server's statements about one another has a written rule for which one it believes for which purpose, rather than picking one by convention. #
vouch #
ownership builds bidirectional ownership — an owner's vouch
and an agent's owner claim, checked against each other — and its own exit
criterion is a verifier confirming "an agent and its owner claim each other."
That is two of three parties. index discovers every server by
"following a server's /events" and, per its Done list, walking
the vouch chain: voucher, repository, vouch, server. A third statement is
already load-bearing there and its own weight is never written down: the
server answering, on ownership's words, "its controlling DID on an
unauthenticated status endpoint."
Three statements exist or are proposed. This epic is naming what each one is worth, because the index treats disagreement between them as something to resolve, not something the lexicons currently say how to resolve.
The three claims #
Read the first claim with its correction. bot.did.vouch was an earlier,
unbuilt design; no schema for it was ever checked in, and
crates/didbot-lexicon/src/nsid.rs deleted even its retired NSID constant.
The record that exists instead is bot.did.operator, and it is not this
claim renamed: lexicons/bot/did/operator.json is explicit that it says who
runs a server, not who governs what it may do, and proves nothing about
delegation. So the owner-vouches-for-an-agent claim below has no record behind
it, and the three-way analysis in this file needs rewriting against
bot.did.operator before it is actionable. The server-and-operator half of it
is real and polled — see handshake and
crates/didbot-serve/src/ownership_poll.rs.
- The owner vouches for an agent (
bot.did.vouch— never built, and the name is retired; see the note under "The three claims" below): this DID is mine, I am accountable for it. Signed with the owner's own key, in the owner's own repository. A stranger who trusts the owner's identity can trust this without trusting the server at all — it says nothing about the server the agent happens to live on. - The agent vouches for its owner (the still-unbuilt half of
ownership): this human is who provisioned me. Written by
the server at provisioning, "never by the agent about itself" —
ownership.mdis explicit that this is not the agent asserting anything; it is the server asserting it on the agent's behalf, inside the agent's own repository. Its trust is bounded by the server: an operator who controls provisioning controls what every agent it mints appears to claim. - The server vouches for itself, and implicitly for its own agents
(
ownership.md's unauthenticated status endpoint, plus index's practice of trusting a server's own account listing as the enumeration of its agents): this DID controls me, and these are the agents I minted.ownership.md's own "Enumeration is derived, and is a lower bound" item already says this is not fully trusted — a compromised server can hide an agent, though containment stops it minting one outside its zone. What is not written down is what a disagreement means, only what an omission means.
What each is worth to a stranger, and where they can disagree #
What a verifier does when they disagree #
Done #
Nothing closed yet.