Agents are getting identities, mandates, and receipts. Here's the map.
Delegation only works at scale when it's provable — when an agent can show what it's allowed to do before it acts, and who did what, under whose authority after. These are the standards making that real, what each one covers, and how they fit together.
One page, one argument — read it top to bottom
First
What we run
The Proof Pair — the open spec we operate: mandate in, receipt out.
Then
How we read the field
The Agentic Pulse — narrative measured against reality, every figure sourced.
Which surfaces
A lane we're opening
Claim Provenance — an unoccupied question we think matters, put in the open as an invitation.
Set in
The whole map
The scene and the market — every rail, and where the lane still sits empty.
● Our open working spec · v0 · live
The Proof Pair
Mandate in, receipt out — delegation made provable at both ends. A mandate is authority you can verify before the act: a verifiable credential from a human to an agent — scoped, expiring, revocable. A receipt is attribution you can verify after it: a signed, hash-chained record binding the action to the agent and the mandate that authorized it. One spec, because every receipt references its mandate. This is what we run, specified so you can run it too.
Then — how we read the fieldThat's what we run. To place it honestly, we start by reading the agent economy as it actually is — the story it tells, measured against what it can show.
Agentic Pulse · narrative vs measured reality
What the agent economy claims, and what it can show.
The pulse reads the gap between the agentic narrative — the raise, the whitepaper, the projection — and the measured reality: real volume, production status, whether the thing can prove who acted. The phenomenon it surfaces is what the field calls agent-washing. It is a diagnostic, not a scoreboard. Every figure traces to a named source. Where a value can't be sourced it reads [TBD-verify] — never an invented number.
~38% →~20%
of execs trust agents for routine analysis — but it falls to ~20% the moment the agent touches a transaction.
Forthcoming — Sell Trust (2026).
$4.6T
the canonical agentic-economy sizing — a Foundation Capital top-down projection of addressable knowledge-work wages, explicitly NOT measured revenue. “A map to gold, sold at the trailhead.”
Foundation Capital — top-down projection.
An agent-payments protocol (unnamed in source)
Production
Agent payments
NarrativeValuation narrative in the billions (~$7B frame).
Measured reality~$28,000/day in real, measured volume.
Can it prove who acted?[TBD-verify]
high confidence
Source: Forthcoming — Sell Trust (2026). Protocol deliberately unnamed in the source.
Remote MCP servers (population scan)
Production
Tool auth
NarrativePositioned as production agent-tool infrastructure.
Measured reality~8,000 servers scanned; ~40% had no authentication at all.
Can it prove who acted?Among servers that DID have auth, effectively none can prove who is on the other end — “a key, yes; an identity, no.”
high confidence
Source: arXiv:2605.22333 — “A First Measurement Study on Authentication Security in Real-World Remote MCP Servers” (2026).
AAuth (Dick Hardt)
Draft spec
Agent identity / authorization
NarrativeIETF draft-track; positioned as the agent-auth standard.
Measured reality0 production deployments (as of 2026-07-06); IETF draft rev-09.
Can it prove who acted?Root anchored in provider DNS — not person-owned keys.
high confidence
Source: Public IETF draft — AAuth (Dick Hardt); draft rev-09 as of 2026-07-06, restamp if it advances before publish.
Lyrie / ATP
Whitepaper
Agent identity
NarrativeRaising on the agent-identity thesis; Anthropic-affiliated.
Measured realityWhitepaper-stage; no shown production — “raised on a whitepaper.”
Can it prove who acted?[TBD-verify]
medium confidence
Source: AIOS Observatory assessment — whitepaper-stage; no shown production as of mid-2026.
● Real cash, for contrast — the honest floor (not washing)
The index cuts toward the honest builders too. These are what real, measured agent revenue looks like — the floor the narrative should be graded against, not just the ceiling it's sold at.
Sierra
Production
Agent labor (real cash)
Measured reality~$100M revenue, priced per “resolution.”
Can it prove who acted?[TBD-verify]
medium confidence
Source: Company public pricing / press.
Cognition / Devin
Production
Agent labor (real cash)
Measured reality$2.25 per 15 minutes (public pricing).
Can it prove who acted?[TBD-verify]
medium confidence
Source: Public pricing (Cognition / Devin).
Which surfaces — an open laneReading the field this way surfaces where the gaps are. One gap has no one standing in it yet — and it isn't a lane to seize, it's a question to open.
● An open lane · a question we think matters, offered not claimed
Claim Provenance
Proof answers is this real? It has no answer for should I be suspicious — and who, exactly, is behind the doubt? In an era where AI makes coordinated, plausible, tireless suspicion cheaper than it has ever been, we have a fact layer for what things are. We have nothing for who manufactures doubt about them.
The missing primitive: a verifiable answer to who is actually behind this assertion, since when, in coordination with whom — coordinated-inauthenticity detection as public infrastructure, not a platform's private trust-and-safety black box. Provenance pointed at the accuser, not the accused. Provenance for the suspicion itself.
We're putting this open question on the record — as an invitation, not a claim. An unoccupied lane we think matters, named in public so the people who should build it can find it — the same host posture as the Proof Pair. The spec isn't written yet. Neither is anyone else's, and we'd rather help open the lane than fence it off. Consider this an open door.
Set in — the whole mapThat's the lane we're opening. Here is the whole field it sits in — every rail pulling the same direction, and where the lane still reads empty.
● The scene — 9 rails, one direction
AP2 — Agent Payments Protocol
Forming
Google + 60+ partners
Signed user-intent artifacts for agent commerce: Intent Mandates (what the user authorized the agent to seek) and Cart Mandates (the specific transaction approved).
How it fits: A Proof Pair mandate compiles down to an AP2 Intent/Cart Mandate for payments. The delta: AP2's trust chain terminates at a processor account; the Proof Pair's terminates at a verifiable human or institutional root — which is what regulated and cross-institutional delegation needs.
ERC-8004 — Trustless Agents
Forming
Ethereum
On-chain registries for agent identity, reputation, and validation — public anchor rails any agent framework can reference.
How it fits: Agent DIDs are registrable in its identity registry, and receipt-chain checkpoints can publish to its validation registry (the Proof Pair's planned v0.1 anchoring path).
W3C DIDs + Verifiable Credentials
Shipping
W3C
The identity substrate: decentralized identifiers plus cryptographically verifiable claims — the data model underneath every serious credential system.
How it fits: Every actor in the Proof Pair is a DID; a mandate is a Verifiable Credential. This is the layer the whole scene stands on.
SD-JWT VC
Converging
IETF (OAuth WG)
Verifiable credentials as JWTs with claim-level selective disclosure and cryptographic holder binding (KB-JWT).
How it fits: The mandate's single normative format in Proof Pair v0 — an agent proves “I may spend ≤ $X for org Y” without revealing its full grant set.
OID4VC (OID4VCI + OID4VP)
Converging
OpenID Foundation
The issuance and presentation transports for verifiable credentials — how credentials move between issuers, holders, and verifiers over HTTP.
How it fits: The Proof Pair's profiled bindings for issuing mandates and presenting them to HTTP verifiers. Headless agent wallets are conformant holders.
DIDComm v2
Converging
DIF
Encrypted, transport-agnostic messaging between DID-identified parties, with mediators that queue messages for offline agents.
How it fits: The agent-to-agent and mailbox transport: how a headless agent receives and presents mandates while its machine sleeps.
Bitstring Status List
Converging
W3C
Credential revocation at scale — a compact, privacy-preserving way for verifiers to check whether a credential is still valid.
How it fits: The Proof Pair's single normative revocation mechanism: a compromised agent must be stoppable in seconds, not CRL-hours.
C2PA
Shipping
Coalition for Content Provenance
Signed, append-only provenance manifests for media content — who made this, with what, changed how.
How it fits: The pattern source for the receipt chain: the same signed, tamper-evident manifest discipline, applied to agent actions instead of media files.
Zero Trust for AI Agents
Guidance
Anthropic
The security framing the field converged on in 2026: without verifiable identity you cannot enforce access controls, maintain audit trails, or attribute actions to specific agents.
How it fits: Names the gap the Proof Pair fills. Identity answers who. A mandate answers what this agent may do, for whom, until when. A receipt answers who did what, under whose authority.
● The agent-identity landscape, mapped
Benchmarked against a running system, not a whitepaper.
Most agent-identity comparisons line up whitepapers against whitepapers. This one is calibrated against a proven end-to-end implementation — a working system in which an agent is issued a scoped, owner-bound credential, presents it to a counterparty in a different organization with no prior relationship, and has that credential verified cryptographically on the wire, with selective disclosure and explicit revocation, today. The bar here is implemented, not proposed.
rivalintegration pointadjacent / watch
AAuthrival · DNS-root · 0 prod
Entra Agent IDintra-org issuer
PICattenuation pattern
agentgatewayenforcement layer
open laneperson-rootoffline-verifycross-orggov-anchored
kagentruntime
agent-substrateruntime
MCP-authOAuth 2.1 render target
passkeysadjacent pattern
The one lane still open.
● The lane, stated first
Here is the specific combination the field has not delivered — an agent identity that is simultaneously all of these at once:
Person-rooted — the root of trust is a key held by a human being — not a cloud provider, a certificate authority, or a DNS record.
Offline-verifiable — a counterparty can verify the credential without a live callback to the issuer. (No one else in this map does this.)
Cross-organizational without a prior relationship — two parties who have never onboarded to each other can still verify.
Government / institution-anchored — the human root can tie to a real-world, legally meaningful identity when the context demands it.
Portability, selective disclosure & explicit revocation — the table stakes the better solutions already share.
No solution in the field delivers all of the above. The map below shows where each one stops.
● Six solutions — what they do, where they stop
A crucial distinction runs through the field: most of these are not rivals — they are integration points. Four of the six operate at layers below or beside agent authority (where agents run, how traffic is enforced, who issues inside one company). Only one occupies the same layer.
AAuth
Direct rival
Dick Hardt · IETF draft
What it doesDelegated authorization for agents. The most direct attempt at the same problem: letting a principal grant scoped authority to an agent. Includes a genuinely good asynchronous-consent pattern (pending / deferred approval).
Where it stopsRoot of trust is anchored in the provider's DNS, not in keys the person holds — so authority terminates at a provider, not a human. A standards-track draft with, as of writing, no production deployments. Not offline-verifiable.
Direct rival — same layer. But DNS-rooted and pre-production.
PIC
Technique to adopt
delegation / capability tokens · [TBD-verify: confirm full name]
What it doesA capability-token scheme for delegating narrow permissions, with a strong attenuate-only rule: each hop in a delegation chain can only narrow authority, never widen it.
Where it stopsSolves sub-delegation elegantly but does not carry a person-root, government anchoring, or cross-org verification without shared infrastructure. Adjacent to the lane, not in it.
Source of a good idea — the attenuation invariant is worth adopting; the protocol is not the same product.
Microsoft Entra Agent ID
Integration point
What it doesEnterprise identity for agents inside one organization / tenant — issuing, listing, and governing an org's own agents at scale, with mature lifecycle tooling.
Where it stopsBounded to the org that issues. It is an intra-org issuer, not a cross-org trust fabric; two agents from different companies don't gain mutual verifiability from it.
Integration point (an issuer to interoperate with), with lifecycle blueprints worth learning from. Watch item: if combined with a verified-credential product for cross-org portability, the boundary could shift. [TBD-verify: GA status]
agentgateway
Integration point
What it doesA policy-enforcement layer for agent traffic — evaluates rich policy expressions at the gateway and allows / denies calls. Cloud-native, well-distributed.
Where it stopsEnforces policy; it does not establish who the agent is or where its authority came from. It needs an authority to enforce.
Integration point — a person-rooted credential is a standard token that enters its policy engine with minimal adaptation. Compose, don't compete.
kagent
Integration point
What it doesAn agent runtime — where agents are built and run.
Where it stopsRuns agents; says nothing about portable, verifiable identity or cross-org authority.
Integration point — the layer beneath identity, not a rival to it.
agent-substrate
Integration point
What it doesAn agent runtime / substrate — infrastructure for operating agents.
Where it stopsOperational substrate, not an identity or authority layer.
Integration point — not a rival.
The tally: four integration points (two runtimes, one enforcement layer, one intra-org issuer), one source of a technique to adopt, and one true rival in the same layer — AAuth — which is DNS-rooted and has yet to ship in production.
● Where the person-rooted approach sits
Against that map, the lane is still open. A person-rooted agent credential — owner-bound, revocable, selectively disclosable, cross-org, offline-verifiable, and anchorable to a real-world identity — is the one combination nobody else assembles. The human holds the key that authority descends from: AAuth roots in DNS, the enterprise issuers root in a tenant, the runtimes have no root at all. Offline verification is unique to this approach across the whole map. This isn't a claim that everyone else is wrong — they solve different problems, and the authority layer that sits above all of them, rooted in a person, is unoccupied.
● The honest limit — where person-root actually matters
A market map that only lists strengths is not credible. A person-owned root of trust has real demand only where the context requires that a human authorized something — government acts, legally binding mandates, citizen transactions, regulated consent. Where authority is purely machine-to-machine and no human needs to be provably behind it, a provider-root or an org-issuer is often enough, and cheaper. So this is both the market and its edge: the value is highest exactly where the law, an institution, or accountability demands a real person stand behind the agent's action — and it is deliberately not trying to be the default for every automated call between two services. This same limit was reached independently by two separate analyses; independent convergence on a system's honest boundary is a credibility signal, not a weakness.
● Compose, don't compete
The position we're aiming for is to be the authority layer everyone else can build on — adopting the best ideas without adopting whole protocols: attenuation per hop (sub-delegation can only narrow authority, never widen it), asynchronous consent (deferred / pending approval as a first-class flow), and lifecycle blueprints from the enterprise issuers. A person-rooted mandate is the source of truth that renders down into the authorization protocols the ecosystem already uses — riding existing rails rather than fighting them. The proof of “compose, don't compete” is an integration, not an argument.
Standards alignment: built on and interoperating with the open standards the category is converging on — ERC-8004, AP2, W3C Verifiable Credentials, SD-JWT, and OID4VC — so composability is designed in, not bolted on.
● Open questions for the category
Platform-custodied person-keys. The largest consumer platforms already custody person-scale keys (the “sign in with…” pattern). The open question is whether the consumer and citizen agentic economy — where a self-held person-root is genuinely required — grows large and fast enough before platform-custodied keys become the de-facto root.
Enterprise-suite consolidation. An enterprise identity vendor connecting its agent-ID product to its verifiable-credential product could push toward cross-org portability from an enormous installed base.
Standards-body anointment. If a working group adopts a provider-rooted draft as the default, it could become an enterprise focal point regardless of production maturity. To date, the tooling ecosystem has leaned the other way.
A map of a live field, drawn honestly, by the team measuring the category rather than marketing to it. Benchmarked against a running end-to-end implementation as of mid-2026; standards drafts and product statuses evolve — time-sensitive claims are re-verified before publication.