W4-027 · Condition 02 — Portable identity

Portable authority

Portable authority is agent identity expressed as a chain of attenuated grants rather than a login: every action traces to a person who authorised it, each grant narrower than its parent, and a counterparty verifies the chain without trusting the issuer.

Published 2026-09-28UnrevisedAlso: agent identity as a chain

An agent does not log in. It presents a chain, and the chain ends at a person.

A login proves an account. It cannot answer the question an agent raises: who authorised this software to act, and what were they entitled to hand down? Portable authority answers it structurally — a grant may only ever carry a subset of the granter’s scopes, so a chain that reconstructs to an accountable person is the credential, and a chain that does not is refused before anything mints.

This is the delegation-chain concept (W4-012) seen from the identity side rather than the audit side. It is what makes standing travel: a counterparty who does not trust the issuer can still verify the signatures, and solving it for agents solves it for people as a side effect rather than the reverse. The falsifier is that identity vendors extend OAuth scopes downward with a profile good enough that portability becomes a preference.

The canonical definition is planned at https://flashyos.com/defined/portable-authority and does not resolve yet; until it does, this builder’s entry is the reference and says so.

Related entries