Agentic PrimitivesAGENTIC PRIMITIVES

05 · The composition

Every layer has a peer. Several are ahead on their one layer. Nobody has the composition.

We checked two fields, honestly and in writing: the agent frameworks (Microsoft Agent Framework, ADK, LangGraph, Dapr, Agno, Strands, Mastra, Pydantic, CrewAI, the OpenAI SDK, Buzz) and the Web3 trust substrate (MetaMask DTK, Smart Sessions, Lit Vincent, Safe, the ERC-8004 → 8273 stack, AP2, x402, Virtuals, Inrupt, PROV-AGENT, Kite, and the Web2 IAM vendors). Eight concerns make an agentic application accountable. Every one has a peer. No project found composes them — one Smart Agent identity for a person, an organization and a service; delegation with caveats a contract enforces; a loop that re-verifies each step against a signed mandate; provenance the principal owns; an ontology every layer binds to; a registry kit rather than a registry. That composition is 77 packages under one npm scope and 33 Solidity contracts, deployable to any EVM.

Eight trust-substrate concerns against six peer families: every concern has a peer, no family covers the column, and Agentic Primitives ships every row as packages and contracts on one identityTHE EIGHT CONCERNSWHO HAS AN ANSWER TODAYHERE — PACKAGE · CONTRACTAgentframeworksWeb2 IAMfor agentsSmart accounts+ delegationThe ERCagent stackRegistries+ discoveryData +provenanceIdentity is a smart accountpeers: ERC-8004 · Kite · Coinbaseagent-account · key-custodyAgentAccount · CustodyPolicyPerson · org · service classespeers: Entra blueprints · Hatstypes · ontology · organizationAgentNameRegistry · 10 typed subregistriesCaveated delegation, on-chain revocablepeers: DTK · Smart Sessions · Vincentdelegation · tool-policy · chain-stateDelegationManager · 9 enforcersPer-step verify against a mandatepeers: ERC-8273 · Strands · Dapr hooksharness · orchestration · a2aDigestBindingEnforcerMandates · commerce · coordinationpeers: AP2 · x402 · ERC-8001/8183intent-engagement · coordination · paymentsPaymentEscrow · AgreementRegistryRecords under per-record delegationpeers: Inrupt Solid · Auth0 Token Vaultvault · mcp-runtime · entitlementsAllowedMethodsEnforcer · AttributeStorageProvenance the principal ownspeers: PROV-AGENT · OTel GenAI · ERC-8196provenance · verification-receipts · witnessPaymentReceiptRegistry · ApprovedHashRegistryNaming · discovery · a registry KITpeers: ERC-8004 · AGNTCY · NANDA · ANSregistry-kit · agent-naming · agent-profileAgentRegistryBase · AgentProfileResolverhas itpart of itnot in scopeRead down any column: nobody fills it. Read across any row: somebody is there, several ahead on that one row.The composition — one Smart Agent identity across every row, authority a contract enforces, provenance the owner keeps — is the thing no project found has. 77 packages · 33 contracts · any EVM.sources: agentic-framework-competitive-analysis · web3-agent-substrate-landscape (2026-09)agenticprimitives.dev
Eight concerns down; six peer families across. A filled cell is a real answer for that concern; a half cell is part of one; a dashed cell is out of scope. The teal column names what ships here for the row — a package and a contract. Read down: no family fills its column. Read across: every row has a peer, and on several rows that peer has more production hours than we do.

The eight concerns — who is there, who is ahead, and what ships here

Canonical identity is a smart account
frameworks · IAM · wallets · ERCs · registries · data

Peers: ERC-8004 identity registry (live on 30+ mainnets), Kite Passport, Catena ACK-ID, Coinbase / Crossmint / Turnkey agent wallets, Entra Agent ID (a service-principal subtype).

Ahead: ERC-8004 on footprint and tooling. Nobody on the class model: one address for a person, an organization and a service, surviving credential rotation.

@agenticprimitives/agent-account @agenticprimitives/account-custody @agenticprimitives/key-custody @agenticprimitives/ap-kms @agenticprimitives/delegated-signer @agenticprimitives/browser-identity
AgentAccount.sol AgentAccountFactory.sol CustodyPolicy.sol UniversalSignatureValidator.sol P256Verifier.sol WebAuthnLib.sol SmartAgentPaymaster.sol
Person · organization · service, as classes
frameworks · IAM · wallets · ERCs · registries · data

Peers: Entra Agent ID blueprints (≈ archetype + identity, tenant-bound), Hats Protocol roles, Aragon OSx permissions, ACK-ID owner→agent credentials.

Ahead: Nobody. PROV-O’s trichotomy mirrored on chain as atl:agentType, with Treasury / Team / Workspace / Registry as DERIVED types named by a suffix.

@agenticprimitives/types @agenticprimitives/ontology @agenticprimitives/organization @agenticprimitives/situations @agenticprimitives/agent-naming @agenticprimitives/registry-resolution
AgentNameRegistry.sol PermissionlessSubregistry (×10 typed).sol AgentNameUniversalResolver.sol AgentNameAttributeResolver.sol OntologyTermRegistry.sol AttributeStorage.sol
Delegation with caveats, revocable on chain
frameworks · IAM · wallets · ERCs · registries · data

Peers: MetaMask DTK (7710 + 7715), Rhinestone / Biconomy Smart Sessions, Lit Vincent policies, Zodiac Roles v2, Safe Policy Engine, ERC-8196, ERC-8226, Kite delegation tokens.

Ahead: DTK on wallet-distributed grant UX; Smart Sessions on a productized session module. We are 7710 wire-compatible and add the intent digest they do not have.

@agenticprimitives/delegation @agenticprimitives/tool-policy @agenticprimitives/chain-state @agenticprimitives/chain-state-viem @agenticprimitives/agentic-authorization @agenticprimitives/entitlements @agenticprimitives/key-authorization
DelegationManager.sol AllowedTargetsEnforcer.sol AllowedMethodsEnforcer.sol ValueEnforcer.sol TimestampEnforcer.sol CallDataHashEnforcer.sol PaymentEnforcer.sol QuorumEnforcer.sol DigestBindingEnforcer.sol ApprovedHashRegistry.sol
An agent loop that re-verifies every step against a mandate
frameworks · IAM · wallets · ERCs · registries · data

Peers: ERC-8273 attestation-gated actions (actionDigest, one tx), Vincent ability execution, Strands interventions + Cedar, Dapr / Permit / Cerbos per-call hooks, Turnkey policy in an enclave.

Ahead: Nobody has a planner-level mandate. ERC-8273 is the nearest on-chain shape to DigestBindingEnforcer — as a draft. The Web2 gateways gate per call on tokens, never on a signed intent.

@agenticprimitives/harness @agenticprimitives/orchestration @agenticprimitives/orchestration-anthropic @agenticprimitives/orchestration-openai-compat @agenticprimitives/service-agent @agenticprimitives/context @agenticprimitives/a2a
DigestBindingEnforcer.sol DelegationManager.sol QuorumEnforcer.sol
Mandates, commerce, coordination between agents
frameworks · IAM · wallets · ERCs · registries · data

Peers: Google AP2 (mandates as VCs, FIDO-governed), OpenAI / Stripe ACP, x402 (Linux Foundation), Virtuals ACP on ERC-8183 (12M memos), ERC-8001 (Final), Olas Mech Marketplace, Catena ACK-Pay.

Ahead: AP2 on governance and partners; x402 on volume; Virtuals on live agent-to-agent commerce. An AP2 mandate is a signed document a merchant checks; ours is a delegation verified on chain per step.

@agenticprimitives/intent-engagement @agenticprimitives/intent-marketplace @agenticprimitives/intent-resolver @agenticprimitives/coordination @agenticprimitives/collaboration @agenticprimitives/payments @agenticprimitives/fulfillment @agenticprimitives/agreements @agenticprimitives/acp
PaymentEscrow.sol PaymentReceiptRegistry.sol AgreementRegistry.sol PaymentEnforcer.sol
Private records under per-record delegation
frameworks · IAM · wallets · ERCs · registries · data

Peers: Inrupt ESS 3.0 (Solid pods; access grants as VCs with purpose; an MCP resource service where approval is deliberately not a tool), Auth0 Token Vault + FGA.

Ahead: Inrupt — shipped, enterprise-deployed, RDF-native. Nobody else pairs per-record scope with an on-chain principal and on-chain revocation.

@agenticprimitives/vault @agenticprimitives/vault-authority @agenticprimitives/mcp-runtime @agenticprimitives/mcp-protocol @agenticprimitives/mcp-oauth @agenticprimitives/related-agents @agenticprimitives/privacy-credentials @agenticprimitives/content-storage @agenticprimitives/content-primitives
DelegationManager.sol AllowedMethodsEnforcer.sol AttributeStorage.sol ShapeRegistry.sol
Provenance the principal owns
frameworks · IAM · wallets · ERCs · registries · data

Peers: PROV-AGENT / ORNL Flowcept (W3C PROV for agents, open source), OpenTelemetry GenAI conventions (still Development), ERC-8263 inference attestations, EAS notaries, ERC-8196 hash-chained audit.

Ahead: Flowcept on capture tooling; OTel on adoption. Nobody anchors PROV in the principal’s vault or ties a prov:Activity to a signed mandate.

@agenticprimitives/provenance @agenticprimitives/verification-receipts @agenticprimitives/witness @agenticprimitives/attestations @agenticprimitives/audit @agenticprimitives/evaluation @agenticprimitives/verifiable-credentials @agenticprimitives/capability-claims
PaymentReceiptRegistry.sol ApprovedHashRegistry.sol AgreementRegistry.sol
Discovery, naming, a registry KIT
frameworks · IAM · wallets · ERCs · registries · data

Peers: ERC-8004 + Agent0, AGNTCY ADS (OASF, Sigstore, DHT), NANDA Index, Linux Foundation ANS, HCS-10, Fetch.ai Almanac, Visa TAP / Web Bot Auth, ERC-8107.

Ahead: AGNTCY on a complete open discovery stack; ERC-8004 on footprint. We ship what registries are built FROM and route every bridge to an adapter outside Ring 0.

@agenticprimitives/registry-kit @agenticprimitives/registry-resolution @agenticprimitives/agent-naming @agenticprimitives/agent-profile @agenticprimitives/agent-resolution @agenticprimitives/agent-relationships @agenticprimitives/identity-directory @agenticprimitives/identity-directory-adapters @agenticprimitives/surface-catalog @agenticprimitives/home
AgentRegistryBase.sol AgentProfileResolver.sol AgentRelationship.sol RelationshipTypeRegistry.sol GeoFeatureRegistry.sol SkillDefinitionRegistry.sol AgentNameRegistry.sol

Seven properties — policy code there, a contract here

The differentiator is not “we use a blockchain.” It is that properties every framework implements as revocable promises in application code — and that the Web3 peers implement one at a time — are here properties of the authority representation itself, enforced by contracts no harness bug and no vendor can bypass.

PropertyAgent frameworksWeb3 peersHereContract
Identity that survives the runtimeDeployment or service identity — a Dapr workload id, a platform account.A key (Lit PKP, Buzz keypair) or a registry row (ERC-8004 ERC-721).The ERC-4337 Smart Agent address IS the agent. Custody rotates; delegations survive rotation; person / org / service on chain.AgentAccount · CustodyPolicy
AttenuationattenuateMandate(parent, scope) — a function every caller must be trusted to call.Smart Sessions policies AND-composed; Vincent policy params on chain.An ERC-7710 chain: a child delegation’s authority is the parent’s hash; the manager enforces the whole caveat chain at redemption. A child cannot widen the parent.DelegationManager
RevocationA framework flag, checked if the code checks.On chain in DTK / Vincent — checked at redemption, not mid-loop.isRevoked read per STEP; a revoke between step 2 and step 3 stops step 3. Live-tested.DelegationManager · chain-state
Intent bindingNothing mainstream — scopes and policies are standing.ERC-8273 actionDigest (draft); Kite intent-hashed tokens (own L1).The delegation carries the JCS digest of the intent. The same capability for a different sentence fails redemption: intent-mismatch, proven live.DigestBindingEnforcer
ReplayIdempotency keys in a store.Nonces per account; 8196 hash-chained audit.A single-use on-chain nonce derived from the intent. Replay reverted — NonceReused — with real USDC.DigestBindingEnforcer
Approval as a boundaryClient-submitted approvals — the pattern Pydantic warns against.A wallet click (DTK 7715); Buzz’s approve button.An ERC-1271-verified approval record, re-verified per step; QuorumEnforcer requires the quorum at redemption. The person’s confirmation IS the signature.QuorumEnforcer · ApprovedHashRegistry
Receipts a third party can checkTraces in a vendor platform.ACK-Pay VC receipts; EAS attestations.Signed receipts binding intent · mandate · step · outcome; PROV-O provenance in the owner’s vault; payment receipts on chain.PaymentReceiptRegistry

The cost, said once: this buys verifiability and custody, and it costs latency (a chain read per step verify), signature UX, and an adapter surface none of the peers pay. Where we manage that cost rather than pretend it away is in the specs — anchor per run vs per step; obligations enforced on chain for high-risk acts only.

Nobody found: the composition. Being the substrate registries are built from only holds if our adapters to their standards exist and are current.

the verdict, from the maintained analysis