v0.3.0-draft
Pre-release
Pre-release
Authority Lifecycle v0.3.0-draft. The cases are now grouped by the authority question each one asks, the model names what a verifier is allowed to say, and cases.json is the single source of truth the two case files are generated from. Read it here:
- README.md, what this repository is and the order to read it in
- AUTHORITY-LIFECYCLE.md, the model, its concepts and the invariants L1 to L12
- Verification model, the artifact verdicts, the boundary outcomes and the one meaning "not established" keeps
- Issuance standing and continuing authority, formerly "What changes when a person leaves", same anchor
- Applying the model, five canonical cases for the shapes this document is most often asked about
- CASES.md, 134 cases in 18 semantic families: 126 verified, 7 reviewed hypotheticals, 1 candidate
- INVARIANT-CANDIDATES.md, 20 proposed invariants (14 CAND, 2 BROAD, 4 ANX) with the cases behind them and their strongest counterexamples
- OPEN-QUESTIONS.md, what is not answered yet, each question now linked to the cases, candidates and fixtures that bear on it
- BOUNDARY-CASES.md, 36 security and evidence cases next to authority lifecycle, grouped by the six reasons each is out of scope
- SUPERSEDED.md, designs we replaced and why
- AGENTS.md, attribution and status rules for AI agents reading this material
- cases.json, the single source of truth for all 170 cases, validated in CI
- schema/cases.schema.json, the schema
cases.jsonis validated against - scripts/build_cases_md.py, generates CASES.md and BOUNDARY-CASES.md, and fails CI on drift
- scripts/validate_cases.py, validates the catalog against the schema and the family and domain vocabularies
- scripts/check_links.py, checks that every internal Markdown link, heading anchor and case id resolves
- CITATION.cff, how to cite this work
- LICENSE and NOTICE, Apache-2.0
- Runnable vectors: 30 fixture families in the Agent Authority Conformance suite, labelled candidate against proposed text
What changed since v0.2:
- Cases are grouped by the authority question they ask, not by the research leg they came from. Each case carries one of 18 semantic families, the source domain survives as a separate field, and the old grouping survives as
fixture_familyso the lab fixture directory names stay resolvable. Every id is unchanged. - Boundary cases are grouped by why each one is out of scope, in six named reasons, rather than by research leg.
cases.jsonis the single source of truth.CASES.mdandBOUNDARY-CASES.mdare generated from it, and CI fails on any drift between them. Content that lived only in the Markdown, including the full sourced paragraph behind each case, moved into the JSON first.- The model adds a verification model: what a verifier may say about an artifact (valid, invalid, not established, not yet effective, suspended, restricted), what an enforcement point decides about one action at one authorization boundary, and the rule that keeps "not established" meaning exactly one thing. The invariant candidates are written against that vocabulary.
- "What changes when a person leaves" becomes "Issuance standing and continuing authority", which is the distinction the section was always making. The old anchor still resolves.
- The "Operational cases" list becomes "Applying the model", which names five canonical cases in
CASES.mdinstead of restating them. That anchor still resolves too. - Every open question now names the cases, invariant candidates and fixture families that bear on it, and says what each one does not close.
INVARIANT-CANDIDATES.mdis restructured to put each claim first and its sources last.- The whole repository carries one version. Every document says "Part of Authority Lifecycle v0.3.0-draft", and git history tracks each file.
What this release does not establish:
- A case with a fixture is not a tested rule. The vectors test proposed text in this repository, not a published specification.
- The verification model is this repository's own drafting vocabulary. It is not published specification text, and no public conformance case decides a verdict by these names.
- Precedents from law, institutions and incidents are sources of cases, not a claim that those rules apply to AI agents.
- Grouping cases by semantic family is an editorial judgment about which question each case asks. It is not a finding about the cases and it does not change any expected outcome.
- Only the Agent Passport System reference SDKs have been run against the vectors so far. Other implementations are invited to run them and report results.