id: vouch title: What an operator vouches, what an agent vouches, and what the server vouches status: open crates: [didbot-pds, didbot-lexicon] dependsOn: [ownership] exitCriterion: > A verifier reading a disagreement between the operator's, the agent's and the server's statements about one another has a written rule for which one it believes for which purpose, rather than picking one by convention. #
vouch #
ownership builds the operator relation in both directions —
an operator's vouch and an agent's operator claim, checked against each other
— and its own exit criterion is a verifier confirming "an agent and its
operator claim each other."
That is two of three parties. index discovers every server by
"following a server's subscribeRepos" and, per its Done list, walking
the vouch chain: voucher, repository, vouch, server. A third statement is
already load-bearing there and its own weight is never written down: the
server answering, on ownership's words, "its controlling DID on an
unauthenticated status endpoint."
Three statements exist or are proposed. This epic is naming what each one is worth, because the index treats disagreement between them as something to resolve, not something the lexicons currently say how to resolve.
The three claims #
Read the first claim with its correction. bot.did.vouch was an earlier,
unbuilt design; no schema for it was ever checked in, and
crates/didbot-lexicon/src/nsid.rs deleted even its retired NSID constant.
The record that exists instead is bot.did.operator, and it is not this
claim renamed: lexicons/bot/did/operator.json is explicit that it says who
runs a server, not who governs what it may do, and proves nothing about
delegation. So the operator-vouches-for-an-agent claim below has no record behind
it, and the three-way analysis in this file needs rewriting against
bot.did.operator before it is actionable. The server-and-operator half of it
is real and polled — see handshake and
crates/didbot-serve/src/operator_poll.rs.
- The operator vouches for an agent (
bot.did.vouch— never built, and the name is retired; see the note under "The three claims" below): this DID is mine, I am accountable for it. Signed with the operator's own key, in the operator's own repository. A stranger who trusts the operator's identity can trust this without trusting the server at all — it says nothing about the server the agent happens to live on. - The agent vouches for its operator (
bot.did.registration, atselfin the account's repository; see ownership): this human is who provisioned me. Written by the server at provisioning, "never by the agent about itself" —ownership.mdis explicit that this is not the agent asserting anything; it is the server asserting it on the agent's behalf, inside the agent's own repository. Its trust is bounded by the server: an operator who controls provisioning controls what every agent it mints appears to claim. - The server vouches for itself, and implicitly for its own agents
(
ownership.md's unauthenticated status endpoint, plus index's practice of trusting a server's own account listing as the enumeration of its agents): this DID controls me, and these are the agents I minted.ownership.md's own "Enumeration is derived, and is a lower bound" item already says this is not fully trusted — a compromised server can hide an agent, though containment stops it minting one outside its zone. What is not written down is what a disagreement means, only what an omission means.