START HERE — Native M5 Agents in a Member-Controlled M5POD #23
satonakaoshimoto
started this conversation in
M5-AI Agents
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Native M5 Agents in a Member-Controlled M5POD
The M5 model begins with a named, accountable human or lawful entity—not a wallet, model, API key, device, or autonomous agent.
M5Canon is not an AI agent. It is the deterministic policy and authority-control layer that checks whether a consequential action may activate. M5AGT is the canonical type for an autonomous/software agent acting under bounded delegated authority.
See the architecture
These are Illustrative Public Review Drafts. Maintained repository text and governance records control where visual shorthand differs.
Three dimensions that must remain separate
1. Who the agent serves — account context
000-IAM— Identity & Access Management001-M5BOM— Bank of Me002-M5BOU— Bank of Us003-M5BOB— Bank of Business004-M5BOI— Bank of Institutions005-M5BOG— Bank of Government / Governance2. What right or economic state is involved
3. What the agent may do now
Principal identity, current role and credential, jurisdiction, deterministic policy, required accountable approval, and evidence/audit anchoring must all be evaluated. An internal M5 label never creates a legal conclusion, government authority, regulated status, or transfer right.
What we want participants to help organize
Public/private boundary
Please contribute schemas, test cases, threat analysis, diagrams, policy questions, public-safe workflows, and interoperability requirements. Do not post private M5POD contents, prompts, agent memory, identity documents, credentials, keys, wallet or account information, personal communications, protected records, confidential business processes, or unreported vulnerabilities.
Public discussion, a role label, successful authentication, or an agent configuration does not create authority. Security vulnerabilities must be reported privately through the repository's security process.
Read first
Start below: Which agent capability, account context, threat, workflow, legal boundary, or conformance test can you help define or review?
M5-agent review series
For company, dataset, product, workforce, and training proposals that extend beyond agent architecture, use Discussion 22 — Build the Public Economic Data Commons.
All reactions