VAGP v0.2 / ORGANISATIONAL AUTHORITY

THE AUTHORITY LAYERFOR AUTONOMOUS AI

Identity tells you who.
Authority proves why.

Verimand establishes one complete organisational authority path behind an exact action — now frozen as VAGP v0.2 and live proven across Google Cloud and Microsoft Azure.

REAL IDENTITYREAL AUTHORITYREAL EXECUTION

Autonomous agents can authenticate and hold permissions.
Verimand establishes why they may.

LIVING AUTHORITY GRAPHSIMULATION / 01
VERIFY
resource-side
INSPECT / MandateM-100 · bounded authority
01 / 9IDLE

One principal. One agent. One exact action.

Current authority can be revalidated at execution time. Revoked authority causes execution to be rejected. This visual simulation never contacts cloud infrastructure.

01 / EXPLORE THE EVIDENCE

FROM IDENTITY TO EVIDENCE

Why may
this agent act?

The identity stays the same. Change the resource or the mandate’s current status — and see why VAGP v0.2 changes the outcome.

EXACT REQUESTEDUCATIONAL SIMULATION
Agent
cloudops-agent
Action
cloud.vm.stop
Resource
vm:development:17
Context
Authoritative resource inventory
  1. 01RESOLVE
  2. 02BIND
  3. 03DERIVE
  4. 04VERIFYVERIFIED
  5. 05EXECUTED
APPLICATION OUTCOMEEXECUTED

One complete current path covers the exact request. The simulated VM stops.

Static examples. No live cloud calls. RESOLVE establishes authority, not policy, approval or a final business decision.

AUTHORITY WITNESSW / 001

One complete qualifying path.

Current at simulated execution

Principal
Head of Cloud Operations
Mandate
M-100
Delegation
D-204
Agent
cloudops-agent
Action
cloud.vm.stop
Resource
vm:development:17
QUALIFYING PATH AT RESOLVEM-100 D-204
RESOLVEAUTHORITY_CONFIRMEDCURRENT VERIFYVERIFIED
Inspect mandate lineage

M-100 → D-204: parent authority narrows to DEV only. Both action and resource must be covered by this same path. No unrelated path can complete it.

Status: M-100 and D-204 ACTIVE in this fixture.

Illustrative Authority Witness. Not a signed grant, credential or cryptographic receipt.

ONE COMPLETE PATH · NEVER A PATCHWORK

Authority is a path.
Not a collection
of permissions.

Every applicable dimension must be satisfied by one complete qualifying path. Two incomplete paths cannot be combined into authority that neither one carries.

PATH A

Right action.
Wrong resource.

stop VM
DEV only

PATH B

Right resource.
Wrong action.

read
PROD

REQUEST stop PROD VM

Two partial paths ≠ one complete path.

Authority cannot be assembled from unrelated paths.

Explore Authority Graph invariants

AUTHORITY CONSERVATION

Authority
is conserved.

Non-amplifying Delegation preserves the boundary of the original mandate — across privilege, finite capacity and time.

NOT BROADER.

Parent: DEV + PROD

Delegation can restrict authority. It cannot add an ADMIN dimension absent from its parent.

Child: DEV

child ⊆ parent

Within the original authority.

CONSERVED

Illustrative conservation constraints, not a budget calculator or a protocol evaluator.

NOT BROADER. NOT DUPLICATED. NOT STALE.

A DISTINCT LAYER · NOT A REPLACEMENT STACK

Bring your identity.
Keep your policy.

Add organisational authority. Authentication establishes the caller. Authority establishes the mandate. Policy and business controls remain separate responsibilities.

01

Identity

WHO?

Microsoft Entra · Google Agent Identity · workload identity

02

Technical permission

CAN EXECUTE?

IAM / RBAC · narrowly scoped gateway capability

03

Organisational authority

WHY?

VERIMAND · mandate lineage and one complete current path

04

Enforcement

EXECUTE?

Protected resource · local verification and execution controls

AUTHORITY_CONFIRMED is not a final business decision. ADDITIONAL_STATE_REQUIRED means authority evaluation needs further state. Only resource-side VERIFIED can precede protected execution; REJECTED means BLOCKED.

Learn what AI agent authority means

PROOF, NOT PLATFORM LOCK-IN

One authority model.
Multiple ecosystems.

The same frozen VAGP v0.2 authority model has passed live RESOLVE → BIND → DERIVE → VERIFY evidence runs on Google Cloud and Microsoft Azure.

VAGP v0.2ONE FROZEN AUTHORITY PROTOCOL

One frozen authority protocol. Two real cloud identity ecosystems. Same organisational authority model.

LIVE PROOF

GOOGLE CLOUD

  1. Google Agent Identity
  2. Verimand Authority Gateway
  3. VAGP v0.2
  4. real protected Google Cloud execution
LIVE PROOF

MICROSOFT AZURE

  1. Entra Agent Identity
  2. Verimand Authority Gateway
  3. VAGP v0.2
  4. real protected Azure execution
DEMONSTRATED

Google Cloud

Google Agent Identity

Secret-version state

VAGP v0.2 live PoV complete

Development executed. Production blocked by NO_AUTHORITY. Post-DERIVE revocation rejected. Experimental, not a production service.

Evidence boundary

docs/pov/verimand-multicloud-authority-pov-v0.2.md · 2026-09-08

DEMONSTRATED

Microsoft Azure

Entra Agent Identity

Azure VM operation

VAGP v0.2 live PoV complete

Development VM deallocated. Production blocked by NO_AUTHORITY. Post-DERIVE revocation rejected. Experimental, not a production service.

Evidence boundary

docs/pov/verimand-multicloud-authority-pov-v0.2.md · 2026-09-08

IdentityWho is the agent?
AuthorityWhy may it act?
ExecutionCan the protected resource execute?
WitnessWhat evidence explains the outcome?

Evidence snapshot · 8 September 2026. Identity layer differs per cloud. Verimand complements IAM/RBAC; it does not replace them. No production readiness claim.

A

Authorised DEV

AUTHORITY_CONFIRMED → BIND → DERIVE → VERIFY. Real cloud resource changed state.

B

PROD NO_AUTHORITY

Authentication succeeded. Gateway technically capable. Authority did not. No execution.

C

Post-DERIVE revocation

Grant derived. Exact Mandate revoked before VERIFY. VERIFY rejected. No execution.

Inspect the Proofs of ValueOpen the versioned VAGP v0.2 reference

THE IMPLEMENTATION FRONTIER

Inspect what exists.
Question what’s next.

Built, demonstrated and reviewed are different claims. Portable cryptographic grants are not yet built; current Execution Grants remain unsigned, process-local and scoped to the single-instance evidence boundary.

VAGP v0.2 frozen baselineREVIEWED

Frozen protocol baseline · independent final review passed

Request Identity + path selectionREVIEWED

One request identity selects one canonical qualifying path; no path shopping

Finite authority conservationREVIEWED

Reservations + hierarchical budget lineage

BIND · DERIVE · VERIFYREVIEWED

Execution-time trusted context continuity through protected-boundary VERIFY

Issuer-bounded freshness + revocationREVIEWED

Finite status staleness and current-path verification

Authority WitnessREVIEWED

Explanatory evidence for authority success or failure; not a credential

Issuer-declared financial applicabilityREVIEWED

Authority-defined financial evaluation requirements; no action-name guessing

Portable cryptographic grantsPLANNED

Not yet · current grants are unsigned and process-local

Cryptographic receiptsRESEARCH

Future authentic evidence; no cryptographic receipt implementation

  1. RESOLVE

    Find one valid authority path.

  2. BIND

    Bind identity, action, resource and trusted context.

  3. DERIVE

    Create one process-local execution grant.

  4. VERIFY

    Validate current authority before execution.

Read the implementation map

PUBLIC SEMANTICS · ENTERPRISE DIRECTION

Make authority
a first-class
infrastructure concept.

VAGP is vendor-, infrastructure- and jurisdiction-neutral. Verimand’s future commercial control plane builds around those public semantics. It does not redefine them. Publication/reuse terms are not yet specified.

Commercial control plane · planned