Skip to content
VerifAIer

IDENTITYEvidence product

Agent Passport

Puts a declared identity on the thing that acted. Which agent, which version, under whose authority, carrying which attributes. All of it is written into the record at the moment of the operation, not attached to it afterwards.

An operation nobody can attribute is an operation nobody can answer for. What travels is portable, verifiable trust evidence for AI agents, composed from the evidence layers beneath it: it is not a self-declared credential, and there is no claim of external standards interoperability behind the word portable.

Why it existsWhat is it for?

Evidence needs a subject.

A record of what happened, sealed and checkable, still leaves one question open: acting as what. Software changes between one week and the next, runs under different authority in different places, and carries attributes that decide what it was allowed to attempt. If none of that is in the record, the record describes an act without an actor.

A label on an entry: Written beside the act
A declared identity in the record: Sealed inside it
A label on an entry: A name that could mean anything
A declared identity in the record: A version, an authority, attributes
A label on an entry: Reconstructed later, if at all
A declared identity in the record: Fixed at the moment it acted

Identity attached afterwards is a guess wearing a badge.

Working out who or what performed an operation weeks later means inferring it from context that has since changed. Written at the moment of the act, it is a fact about that act. Written afterwards, it is an assertion about a memory, and nobody can check the difference from the outside.

What it isWhat does it actually produce?

A declaration the operation carries with it.

Passport · as declaredev_bf6442d03d1d4…

Ready Every field above was present in the record when it was sealed. None was added later.

agent
claude-code
version
1.0.60
surface
mcp · editor client
authority
workspace · adopted pack
capabilities
read, write · as adopted
declared at
09:20:04.030411

Declared, then sealed

The passport is stated by the acting system and written into the envelope with everything else. Sealing covers the identity and the operation together, so the two cannot be separated afterwards without the seal failing. That is also why attribution outlives the system that produced it: renaming an agent, upgrading it or retiring it changes nothing about the passports already sealed into past records.

A declaration, not a verdict

What the record establishes is that this identity was declared, at that moment, for that operation. Whether the declaring system was entitled to say so is a question for the systems that grant entitlements, and this is not one of them.

AttributionHow far does it reach?

As far as the declaration, and no further.

This is the product’s single axis, and the one a reader will most want to stretch. Attribution has four honest limits, and each one is worth more than a claim that sounds stronger.

What it establishesThis identity, this operation, this moment

Fixed in the sealed record and checkable against it.

Strong, because it is a fact about the record rather than an inference about the world.

What it does notThat the declaration was true

A declared identity is what the acting system stated about itself.

Nothing here authenticates it. Where that matters, an identity provider does that work and this records what it produced.

The human behind itNot resolved here

The record names the acting system and the authority it ran under.

Following that to a person is an organisational question, answered with organisational records. Guessing at it would be the worst thing this product could do.

Outside the pathNo passport at all

Work that bypassed the runtime declared nothing and left nothing.

Reported as absent rather than attributed to whatever seems most likely.

Cannot tell

Asked to attribute something with no passport, the answer is that nothing could look. Not that nobody acted, and never that the act was approved. An unattributable operation is reported as unattributable, with the reason stated.

AdoptionHow do you get it?

It begins the moment the runtime does.

Like the other evidence products, this has no install path of its own. A passport is written with the first governed operation, and there is no directory to populate or registry to maintain before it works.

The two real routes
Run an assessment
A run produces records that name what acted in them. Nothing is installed.
Install the runtime into an editor
Every governed operation then carries a passport. Two editors install today.

Nothing to enrol, and nothing to backfill

There is no onboarding step in which agents are registered before they can act. A passport is not an account: an account is a thing that exists between operations and is maintained, renamed, merged or deleted, while a passport exists only inside the operation it belongs to. An agent that has never been seen before still leaves a complete one.

Operations from before the runtime was in the path carry no passport, and one cannot be issued for them afterwards.

Note

There is no packaged installer for anything in the platform, no directory service to run and nothing on this page to download. The two routes above are the whole of it.

BoundariesWhat are we not telling you?

This is not how anything gets in.

The word passport suggests a document that grants entry, and this grants nothing. It sits on the evidence side of the architecture: it records identity as part of what happened. Nothing here decides whether an agent may act, and no system should be configured as though it did.

Not claimed
Not authentication

Nothing here proves an identity is genuine. It records what was declared, which is a different and narrower thing.

Not access control

No permission is granted or refused by this. What an operation was allowed to attempt is decided by the policy that was adopted.

Not identity management

There is no directory, no credential to issue, rotate or revoke, and no lifecycle to administer. It does not replace the systems that do that.

Not a sign-in

Nothing here participates in a sign-in flow, holds a session or federates with anything. A passport is written after the decision to act, not before it.

Not a credential

It is a trust document rather than a credential: no credential standard is implemented, nothing is issued to a holder or presented to a verifier, there is no revocation list, and no external identity scheme is involved at any point. What travels is the record and the evidence beneath it.

No reputation

An agent does not accumulate standing here. There is no score, no rating and no history that makes one agent more trusted than another, and nothing is written to a time series, so no claim about an agent behaving better or worse over a period can be made.

It answers acting as what, and leaves the harder questions to the systems that own them.

Whether an identity is genuine, whether it should have been permitted, and which person stands behind it are three different questions with three different owners. Declining all three is what makes the one it does answer worth relying on. It is also the question an investigation cannot proceed without: a sequence of operations nobody can attribute describes an incident without ever reaching an actor, and no amount of surrounding evidence recovers that later.