Agentic PrimitivesAGENTIC PRIMITIVES

Demos

One substrate.
Six apps you can run right now.

Every app here is a relying app of the same Home: it signs people in through faithnet.me, never holds a key, and every act it performs is a grant the person signed. Pick one, sign in as a demo person, follow the script. The whole tour is about half an hour.

00Before you start

Sign in as a demo person. Each one is a real Home.

alice.mealice
Alice Okoro

The player. Stewards the organization Missio Nexus; has a treasury the Home chartered for her.

bob.mebob
Bob Tanaka

Custodies the Hold’em coach service. Not at the table; his service is consulted through the player’s own agent.

carol.mecarol
Carol Mbeki

A second person and counterparty. Can be paid, invited, granted to.

Passkeys for the demo people are on the demo people page. Everything below runs for play money on a test chain; nothing here is a real-money service.

01The person’s own place

Home

One name, your own agent, your own records, the organizations you can act for.

faithnet.me is the Home every other app on this page signs in through. A passkey yields a Smart Agent — alice.me — not a session. Organizations are created here, apps are linked here, and every grant an app asks for is signed here, by the person, with the caveats on screen.

What it proves
  • Identity that can sign (a passkey → an ERC-4337 account)
  • Your app cannot create an organization; the person does, at their Home
  • A grant is a ceremony the person performs, never an operation the app performs
The scriptsign in as alice · 3 min
  1. 1
    Sign in with a passkey.
    You are alice.me — an account with an address, not a row in a users table.
  2. 2
    Open Organizations.
    The organizations Alice stewards or belongs to, each its own Smart Agent with its own treasury.
  3. 3
    Open Linked apps.
    Every relying app on this page, with the exact grant each holds and a Revoke that takes effect at the next gate.
  4. 4
    Open your vault.
    The receipts of everything an agent did as you — the record is yours, the apps hold caches.

02Home MCP connector

Your agent, inside Claude

Claude asks your agent as you. Anything that would change something waits for your signature.

A remote MCP server that is an OAuth 2.1 authorization server toward Claude and a relying app toward the Home. The bearer Claude holds never leaves the Worker; what reaches your agent is your own ask-as-me delegation, verified against your account on chain per request. Acts park as authority_required and hand you a link to your Home to sign.

  • Connector addressClaude → Settings → Connectors → Add custom connector
https://home-mcp.faithnet.io/mcp
What it proves
  • The service that acts as an agent is never that agent — Claude holds a revocable delegate, not you
  • Resolution is not authority: finding an agent is not permission to use it
  • Trust is a graph: discovery returns candidates with evidence, never a score
The scriptsign in as alice · 5 min
  1. 1
    Ask: “What have I asked my agent for recently?”
    Your recent runs, answered by your agent by name (alice.me). This proves the bearer reaches your agent as you — not as the connector.
  2. 2
    Ask: “Find an agent that can help with a study on justification.”
    Your agent searches the estate’s discovery tier and returns candidate agents — the Ligonier catalog service among them — with what each one can do and the evidence for it. Nothing has been asked of them yet.
  3. 3
    Ask the Ligonier catalog the same question through your agent.
    The catalog answers with titles, teachers and topics (240 items under 236 topics). Your agent reports what it read and from which tier; the run leaves a receipt in your vault.
  4. 4
    Ask for something that would change a record — “invite Bob to Missio Nexus.”
    authority_required, and a grant_link to your Home. Claude cannot sign for you.

03A card room — the reference app

Game Night

People and AI agents at the same table; the house holds nobody’s keys.

Texas hold’em and canasta for play money (Sheqel, a test coin). Buy-ins and cash-outs settle from each player’s own Smart Agent treasury under a mandate the player signed — payee, ceiling, coin. A coach service Bob custodies is consulted through the player’s own agent under a study grant, and may advise but never act.

What it proves
  • A mandate binds a grant to one intent — a buy-in is N mandates, not one
  • The person’s agent never moves money; the treasury service does, under the mandate
  • A capability’s declared risk cannot be lowered by the planner (poker.advise, never poker.act)
The scriptsign in as alice · 6 min
  1. 1
    Sign in as alice; “Deal me in.”
    The Home asks Alice to sign the buy-in mandate: payee = the table, ceiling = the buy-in, coin = Sheqel. The chips arrive from alice.treasury.
  2. 2
    Play a hand; ask the coach.
    Advice comes back through Alice’s own agent under a study grant Bob’s service accepted. It cannot bet.
  3. 3
    Cash out; open Alice’s vault at the Home.
    A receipt per buy-in and cash-out — mandate, verifier decision, transaction hash — held by Alice, not the card room.
  4. 4
    Revoke the card room at the Home; try to buy in again.
    Refused at the next gate. Nothing was cached.

04Gatherings — find, host, operate

Gather27

Listings are communities and regions, never individuals; a host is a person who signed for the listing.

A seeker finds a group near them with no session. A host connects at the Home, creates or adopts an organization, affirms the four-clause covenant, and publishes a listing; the host organization’s vault is the record of truth and the site holds a rebuildable projection. Three surfaces of one app: Find (public), the host app, and Ops — admission receipts, the lifecycle of every listing, who signed what.

  • Findpublic — no sign-in
  • Hostsign in at the Home
  • Opsoperator console
What it proves
  • Two tiers that never meet: Find reads the public tier; a host’s records live in their vault
  • Acting for an organization needs a stewardship grant, not membership
  • A listing is a signed, timestamped event — so is delisting
The scriptsign in as dave · 5 min
  1. 1
    Open Find; search a region.
    Public listings from the discovery tier — no account, no cookie, nothing private disclosed.
  2. 2
    Open Host; sign in as dave; adopt an organization, affirm the covenant, publish a gathering.
    The listing is a signed event by the host organization’s agent. A member who is not a steward is told so, and which grant it would take.
  3. 3
    Open Ops.
    The admission receipt for the listing, its lifecycle, and the signer — evidence, not a log line.

05Field Circles — a local-first workspace for field work

Field

Local people are accountable actors. Vaults preserve custody. Projections cross boundaries — not raw field reality.

A workspace for organizations doing mission work: who belongs, who may speak for the organization, the circles and relationships on a field, and progress along modelled dimensions. The tab title is deliberately neutral — under a discreet posture the app name is a disclosure to anyone who picks up the device. The Ask panel asks the workspace you are standing in; membership comes from the ontology (a team has members), never from a name match, and any act that speaks for the organization checks a stewardship grant.

What it proves
  • Membership is not a grant — a member sees; a steward acts
  • Domain relationships live in the ontology: “who is a member” is a modelled relation, never guessed
  • Two tiers: the workspace can be asked; the authority tier still decides what may change
The scriptsign in as alice · 4 min
  1. 1
    Sign in as alice; open a workspace (Northern Colorado Field).
    The side nav is scoped to that one workspace — the app says so when it is not.
  2. 2
    Open Ask and ask: “Who are the members of my organization?”
    You can watch it think, then answer: the members, resolved from the organization’s own records through the ontology, with the tier the answer came from.
  3. 3
    Try an act that speaks for the organization.
    “You are a member of …, not a steward. This act speaks for the organization, so it needs a stewardship grant.” — refused, naming the grant it would take.

06Playbooks and ontology, by digest

Skills registry

Every capability a demo above used, pinned by digest — and the ontology modules it binds to, as graphs.

SKILL.md management for the estate: agent archetypes, the capabilities each may mean, and the ontology modules behind them. A receipt from any app above cites the digest of the playbook that admitted the run; this is where that digest resolves.

What it proves
  • Behaviour is generated; authority never is — a playbook is consulted by no verifier
  • One ontology from the utterance to the audit
The script2 min
  1. 1
    Open the Hold’em Coach archetype.
    poker.advise and poker.review — never poker.act — and the fourteen ontology areas it binds.
  2. 2
    Take a playbook digest from a Game Night receipt and find it here.
    The exact compiled definition that admitted that run.

07If something refuses

Most refusals are ceremonies, not bugs.

authority_required means the act needs a signature the person has not given — follow the grant link to the Home and sign. member, not a steward means the person belongs to the organization but may not speak for it. A refusal after a revoke is the point: nothing was cached. The gates page lists every gate and who holds it.

Now build one.

Every app on this page is a third-party relying app: it imports the published packages, signs people in through a Home, and never holds a key. The Build guide is five short pages.