GUARDAID: an open standard for agent identity and mandate verification

Today a person signs a permission, not a list of acts. A service receiving an agent has no way to know who answers if something goes wrong, so it blocks — legitimate agents included. GUARDAID defines the format and the procedure by which a person signs, with a key that never leaves their hardware, the closed list of what an agent is going to do — and by which any third party verifies it without consulting anyone. The ordering principle: reading the passport is identical everywhere; what each party does with that reading is its own. The format and the procedure are proposed; the authority never is. Two parts, each adoptable without the other. The passport is issued by whoever sends agents: identity, registration, the signed mandate, and one ticket per action. The gate is implemented by whoever receives them: a fixed-order reading, with no memory between readings, returning the facts admission needs. A service can implement it today without waiting for anyone: if an agent arrives with a passport, it reads it; if not, its usual rules apply. Neutral between blocs by construction. Algorithms are declared, not fixed: the registry includes those of the West and those of China, under the rule that nobody may withdraw the other's algorithm on its own. There is no central authority, no global tree, and each country and each service decides what it admits at its own door without ceding anything. It includes the byte-level object model, the formal reading steps with their result codes, and the case bank that defines conformance — because a standard that says they must read alike and gives nothing to check it with is a wish. Open, free of charge, with nothing to sign. The name is free for any implementation that passes the test bank. Files. The core specification, in English, which is the normative language. Version 1 of the algorithm registry is the table in §4.1; the signed registry file of §4.2 will be added as a new version of this record. Feedback. Corrections, implementation reports and findings of an error are welcome at [email protected]. A difference between two of these documents is a defect in one of them, and reporting it is the fastest way it gets fixed.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-08
DOI
https://doi.org/10.5281/zenodo.23224698
Citations
2
Primary Topic
Access Control and Trust
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

GUARDAID: an open standard for agent identity and mandate verification

Fabiana Andrea Gómez Martínez
2 citations
Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
preprint

GUARDAID: an open standard for agent identity and mandate verification

Fabiana Andrea Gómez Martínez
preprint en
2 citations

Abstract

Today a person signs a permission, not a list of acts. A service receiving an agent has no way to know who answers if something goes wrong, so it blocks — legitimate agents included. GUARDAID defines the format and the procedure by which a person signs, with a key that never leaves their hardware, the closed list of what an agent is going to do — and by which any third party verifies it without consulting anyone. The ordering principle: reading the passport is identical everywhere; what each party does with that reading is its own. The format and the procedure are proposed; the authority never is. Two parts, each adoptable without the other. The passport is issued by whoever sends agents: identity, registration, the signed mandate, and one ticket per action. The gate is implemented by whoever receives them: a fixed-order reading, with no memory between readings, returning the facts admission needs. A service can implement it today without waiting for anyone: if an agent arrives with a passport, it reads it; if not, its usual rules apply. Neutral between blocs by construction. Algorithms are declared, not fixed: the registry includes those of the West and those of China, under the rule that nobody may withdraw the other's algorithm on its own. There is no central authority, no global tree, and each country and each service decides what it admits at its own door without ceding anything. It includes the byte-level object model, the formal reading steps with their result codes, and the case bank that defines conformance — because a standard that says they must read alike and gives nothing to check it with is a wish. Open, free of charge, with nothing to sign. The name is free for any implementation that passes the test bank. Files. The core specification, in English, which is the normative language. Version 1 of the algorithm registry is the table in §4.1; the signed registry file of §4.2 will be added as a new version of this record. Feedback. Corrections, implementation reports and findings of an error are welcome at [email protected]. A difference between two of these documents is a defect in one of them, and reporting it is the fastest way it gets fixed.

Zenodo (CERN European Organization for Nuclear Research)
Estonian Association for Applied Linguistics (EE)
Access Control and Trust
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.