Agentic PrimitivesAP

The trust substrate for agentic applications

Agentic PrimitivesRails,
not throttles.

The industry’s answer to agent risk is to make the agent smaller — sandboxes, restricted modes, a second model grading the first. Agentic Primitives bounds what it may do: a signed, caveated, revocable grant, enforced by code outside the model, receipted for the owner. Open source.

Built at four scalesSubstrate→Estate→Town→Federation
ERC-4337ERC-7710A2A 1.0MCPW3C PROV-OpasskeysW3C VC

Status · 2026-09-18Pre-production, honestly labelled. GO for testnet pilots on our own chain · NO-GO for real private data, real value, public mainnet — each with dated closing conditions. 77 packages · 939/939 contract tests · 54 open findings, all public.

Read the assessment

Open, end to endagentic-primitives · substrateap-home · estateap-town · town·OntologySkills libraryA live Home

The code is the substrate and the estate; the ontology says how each domain is shaped; the skills library turns it into playbooks.

How it is organized

Four words you will see everywhere: substrate, estate, town, federation.

Agentic Primitives is not one website or one app. It is built the way a place is built: materials and a building code, then a property with its own front door and keys, then a street of properties that share an address book and a notice board, then roads between towns. Every screen, every agent and every receipt lives at one of these four scales, and knowing which one tells you who is in charge there.

  1. The substrate: packages and contracts, the ground everything stands onPACKAGES · CONTRACTS

    01 Substrate

    Live

    The materials and the building code. Nobody lives here; everything else is built from it, so every Home, town and federation behaves the same way.

    Like the building code and the lumber yard: you never see them, and they are why the house stands.

    If you are a person
    You never touch it. It is why your agent can sign, why a permission you give can be taken back, and why there is always a receipt.
    If you run an organization
    The guarantees are the same whichever Home or town you use, because they come from here, not from a vendor.
    If you build
    Published packages and contracts. Take one capability or all nine; your app imports them, they never import you.
  2. An estate: one property with a Home, agents, a vault and a gate

    02 Estate

    Public

    Your own property. The front door where you sign in, the staff who work for you (your agents), the filing cabinet that holds your records (the vault), and the gate that checks who may come in (the edge). You hold the keys.

    Like your house: your door, your help, your papers, your gate, your name on the deed.

    If you are a person
    This is where you sign in, decide, and keep what is yours. Nothing is done in your name without a permission you signed here, and you can take it back here.
    If you run an organization
    Your members, teams and treasuries live in your estate. A member acts under a role you gave; a treasury pays only within a limit you set.
    If you build
    ap-home is the estate product, public on GitHub. Run one for your community, or build a relying app that plugs into someone else’s.
  3. A town: several estates on one street, sharing an address book and a notice board

    03 Town

    Public

    The street your estate is on. The address book that says who lives where, the public notice board, the directories of who offers what, and the utilities every neighbour shares. Shared by all, owned by none.

    Like a town: street names, a notice board, a trades directory. Being listed is not the same as being in charge.

    If you are a person
    How others find you and how you find them. A listing in a directory never gives anyone power over your estate.
    If you run an organization
    Your name is unique in the town, your public facts are readable by anyone, and your private ones stay in your vault.
    If you build
    Naming, discovery and registries for every estate on one chain. Build a vertical registry from the same kit; it lists, it never grants.
  4. A federation: towns on different ground, joined by public roads

    04 Federation

    Next

    Towns in different places, connected by public roads. You can visit another town and act there, but your keys never leave home; you prove what you are entitled to, sign at your own door, and keep the receipt.

    Like travelling with a passport: another country can check it, but it cannot sign your name.

    If you are a person
    Act somewhere else, sign at home, keep the receipt. A permission you gave in one place is never quietly honoured in another.
    If you run an organization
    Work with organizations whose estates stand on other chains, including public ones, without moving your records or your money to them.
    If you build
    Public ground, proofs of standing, and the binding between one principal’s accounts. Designed, not yet built; the open questions are listed, not hidden.

The rule that runs through all four: being somewhere never gives anyone power over you. Your keys stay at your estate. A town can list you; it cannot act for you. A federation can prove what you are entitled to elsewhere; it cannot spend on your behalf.

A day in the town

One person. One agent. Many contexts — and the keys never leave home.

Alice's agent books her check-up as a patient, asks her church and home group for this week's times as a member, gets the yoga timetable as a neighbour, and opens one shelf of her vault to her coach — then closes it. Every provider answers from its own estate, with its own agent. Press play.

A day in the town: one person's agent as patient, member, neighbour — and a window into her vaultALICE'S ESTATE · HER HOME, HER AGENT, HER VAULTHER CHURCH · HER HOME GROUPTOWN SERVICESThe churchHome group · the Nguyens'Address bookThe chainKey serviceDirectoriesPublic graphHer vaultAlice's HomeHer agentGateDr Okafor's practicepractice agentRec centreCoach Priya's agentshelf: fitness goalsread only · the coach · this seasonbook my check-upfind my practiceas a patient: any slots?appointment · Thu 9:40 → her vaultas a member: when do we meet?and the home group?as a neighbour: yoga this week?a grant: coach may read my fitness goalscoach asks again → refused at the gatehere is its card · checked on the chainThu 9:40 or Fri 14:00 — which suits?Sunday 10:00 · main hallWednesday 19:00 · at oursTue 18:00 · Thu 7:00 · Sat 9:00I see: 3 of 5 sessions — nicerefused: her window is closedclosed, from her doorknows her as: a patientknows her as: a membera memberknows her as: a neighboursaw one shelf · now closedknows: her name and addressholds: her keys, every permission, every receiptA DAY IN THE TOWNOne person. One agent. Many contexts.Every building is an estate with its own agent. The roads are conversations. The keys never move.Each has its own front door. Nobody holds anyone else's keys.agenticprimitives.dev

1 / 7 · One person, one agent, one town · ← → to step, space to pause

01 · ONE PERSON, ONE AGENT, ONE TOWN

Alice lives at the bottom of the hill. Her agent lives at her Home, next to her vault. Across town: her doctor's practice, her church and her home group, the rec centre. In the middle, the services the whole town shares. Every one of them has its own agent, at its own address.

Each has its own front door. Nobody holds anyone else's keys.

01The state of the argument

Everyone now admits a capable agent has a blast radius. Then they reach for a throttle.

Three answers dominate. Each is real engineering. Each stops at the same place: none can say, for an act that happened, under whose authority it happened — or refuse the next one because that authority is gone.

THROTTLE 01The frontier labs

Containment

Shrink what the agent can reach: sandboxes, restricted modes, egress denied by default, a kill switch.

What it buys
A smaller blast radius for one process on one machine.
Where it stops
A sandbox is a wall around a room. It says nothing about who let the agent into the room, on whose behalf, or for what. Every act inside the wall is equally authorized — which is to say, none of them are.

Containment bounds reach. It cannot bound authority, because it has no concept of it.

THROTTLE 02The frontier labs, again

Supervision

Watch the agent: permission prompts, then — when people approve 93% of them — a second model that grades the first.

What it buys
Fewer catastrophic actions, on average, with a non-zero miss rate the vendors acknowledge.
Where it stops
A click is not consent and a classifier is not a grant. When a probabilistic monitor approves a probabilistic agent, the result is still probabilistic — and the record of it is a log line in a vendor’s store.

Supervision is a better throttle. It is not a rail.

THROTTLE 03The enterprise platforms

Platform governance

Anchor agents in one platform’s ontology: purpose-based permissions, a human-in-the-loop dial, reversible actions, lineage across the estate.

What it buys
Real control — inside the platform, for the workloads it hosts, on terms it sets.
Where it stops
The permission is the platform’s ACL. The reversal is the platform’s branch. The evidence is the platform’s lineage. Your sovereignty is exactly as large as your contract, and a counterparty outside it has to take the platform’s word.

Reversibility inside one vendor is that vendor’s sovereignty. Revocability the owner holds is yours.

THE RAIL

Authority as a grant

Let the agent be as capable as you like. Bound what it MAY do with a signed, caveated, revocable grant — enforced by code that runs outside the model, on every step, and receipted for the owner.

How the grant is built
  1. 01
    Signed by the principal, not configured by the platform.
    A person, an organization or a service issues the grant from its own account, with a passkey, at its own Home. No vendor holds the key.
  2. 02
    Bounded by caveats that are code.
    Payee, ceiling, method, target, time window, the digest of one exact intent. Each caveat is an enforcer contract that runs at redemption. A scope is a string; an enforcer executes.
  3. 03
    Verified every time, cached never.
    Before the step, after the approval, and on chain when value moves. Revocation is one transaction, final at the next gate, everywhere — no expiry to wait out, no list to update.
  4. 04
    Receipted for the owner.
    Which grant, which decision, which transaction, which playbook — into a PROV-O graph in the owner’s vault. A counterparty verifies it without the runtime’s cooperation.

02What the substrate guarantees

Three questions, answerable for every act — by a counterparty, without trusting the platform.

Not a dashboard the operator shows you. A signature you can check, a grant you can read, a receipt the owner carries.

Who is acting?
Identity that survives the runtime
Every person, organization and service in your application is a Smart Agent — an on-chain account that can verify signatures, hold value and execute logic. Names, cards, registry entries and DID documents are projections of it, never the identity itself. Passkeys and keys rotate; the agent does not.
ERC-4337 account · ERC-1271 signatures · typed names (.me .org .svc .treasury .workspace)
May they do this?
Authority that is a grant, not a token
Permission to act is a delegation the principal signs, narrowed by caveats — a payee, a ceiling, one intent, a time window — and revocable in one transaction. It is verified before every step, again after every approval, and again on chain when value moves. No cached verdict ever authorizes an act after the authority behind it is gone.
ERC-7710 delegations · caveat enforcers · intent-digest mandates · on-chain revocation
What did they do?
Evidence the owner carries
Every protected step leaves a receipt — which grant, which decision, which transaction, which playbook — into a hash-chained log and a W3C PROV-O graph held in the owner's vault, not in a vendor's trace store. A receipt travels because the owner carries it, and a counterparty can check it without the runtime's cooperation.
PROV-O provenance · OpenTelemetry spans · hash-chained receipts · vault-resident records

03The architecture

Application on harness. Harness on authority. Authority on identity. Identity on chain.

Every layer is a published package or a deployed contract. Admission runs at the edge of every request; evidence is written for every protected step; the ontology binds the vocabulary so the code cannot invent its own.

The Agentic Primitives substrate in layers: application, harness, authority, identity, chain — with edge admission and evidence alongside
The substrate in layers. The harness turns an ask into an intent, a mandate, a plan, per-step verification and a receipt. Authority is a signed delegation with caveats, revocable in one transaction. Identity is a Smart Agent per person, organization and service. The chain anchors all three; edge admission and evidence run alongside every layer.

Four scales, four repositories

Substrate. Estate. Town. Federation.

The packages are the substrate. One deployment of them — a Home, an agent runtime, a vault, an edge, on one chain — is an estate. The estates on one chain and the services they share there are a town. Towns on different chains, private and public, joined on public ground, are a federation. Each is its own repository; each depends only on the one below; each answers a question the one below cannot.

The four scales: substrate, estate, town, federation — one repository each, each depending only on the one below
One chain per estate. One chain per town. Many chains per federation. Authority never leaves the chain it was signed into: evidence and value cross, a grant never does.

01 Substrate

Live

What is an agent, what may it do, and how is that proven?

The published packages and contracts: everything an agentic application needs, as primitives with one identity, one authority mechanism and one evidence trail.

Chain: Any EVM. The contracts are deployed per chain; nothing in a package names one.

Rule: Generic. No vertical, no brand, no hostname, no deployment. Products import it; it imports nothing of theirs.

agentictrustlabs/agentic-primitives →

Ring 0. Packages on npm, exact-pinned by consumers.

02 Estate

Public

Where does a person sign, where do her agents run, and where is the record?

One deployment of the substrate for one set of people and organizations: the Home where they sign, their agents, their vault, the edge in front of it, the Home MCP that lets a client reach the person, and the chain they enforce on.

Chain: One chain. An estate enforces on exactly one; its grants, names and anchors live there.

Rule: The vault is the record; DO storage is the serving plane. Only a person signs, and only at her Home.

agentictrustlabs/ap-home →

The Home product. Deploys Faithnet on faithchain. Public since 2026-10.

03 Town

Public

How do estates on one chain find each other, name each other and read the same facts?

Several estates on one chain and the services they share: agent naming, the public graph and discovery, registries, the KMS tenants, and the operations of the chain itself.

Chain: One chain, by definition. A town is the chain’s estates plus the services built on that chain’s state.

Rule: Nothing in a town grants. A resolver returns an address, a registry lists, a graph holds only what the chain can prove.

agentictrustlabs/ap-town →

Public. The services every estate on one chain shares: registry, public graph, naming, chain access, the town portal.

04 Federation

Next

How does an agent from one chain act in an estate on another without authority ever crossing?

Towns on different chains, private and public, and the public ground that lets an estate in one prove its standing to an edge in another: roots, presentations, bindings between a principal’s accounts.

Chain: Many chains. Authority stays on each; evidence and value cross; a grant never does.

Rule: A message from another chain is evidence that something happened there. It is never a mandate here.

agentictrustlabs/ap-federation

Next. Spec 410 §4 is its design; the chains note names what is still open.

Read the note on the four scales

04Why one substrate

Ten products, or one model.

An agentic application needs sign-in, organizations, permissions, money, an agent loop, human approval, evidence, service credentials, discovery and tools. Each is sold separately. Every seam between them is where identity becomes a token, permission becomes a row, and the row becomes a log line nobody can trace back to a person’s decision.

Stitched: ten products and the glue between them. Seamless: one substrate where identity, authority and evidence are one model.
Left: the stack most teams assemble and the glue between the parts. Right: the same needs as slots in one model, sharing one identity, one authority mechanism and one evidence trail.
Sign people in
Stitched
Auth0 / Okta / Cognito + a users table
On the substrate
The Home: passkey sign-in to a Person Smart Agent; OIDC + delegation in one ceremony
OIDC answers who; delegation answers what the app may do. One screen, both answers.
Represent the organization
Stitched
A tenants table + a Safe multisig + an admin role
On the substrate
An Organization Smart Agent with custody policy and stewardship
The org can sign, hold, delegate and be audited as one actor.
Let a service act for you
Stitched
A service account with a long-lived secret and broad scopes
On the substrate
A Service Agent whose key is a revocable delegate of its identity
Compromise a key, lose a delegate — never the identity.
Hold and move money
Stitched
Stripe Connect + a wallet SDK + a ledger you write
On the substrate
A Treasury Service Agent; payments under caveated mandates; receipts on chain
A payment is authorized by the person who owns the funds, for that payee, up to that ceiling.
Run an AI agent safely
Stitched
LangGraph + a permission prompt + a Slack approval bot
On the substrate
The harness: planner proposes, mandate authorizes, executor acts, receipt proves
A hijacked planner can be creative; it cannot exceed the caveats.
Let agents talk to each other
Stitched
REST webhooks + API keys per partner
On the substrate
A2A 1.0 over HTTPS with admission; every message signed by an agent
The counterparty is an identity, not an endpoint.

The bill of materials — we assembled it from products once

30+
products to select, contract, integrate
3
identity models to reconcile
33
contracts to write, fork and audit
77
packages under one npm scope
33
contracts written and under audit
1
identity · 1 grant mechanism · 1 evidence trail

The nightmare was never any one product; it was the seams. Now you describe the application and the packages and contracts already agree with each other.

05The platform

Nine capabilities. Each independently adoptable. Each depending only downward.

Take Identity alone and you have passkey sign-in to durable agents. Add Authority and every action is a scoped, revocable grant. Add the Harness and your AI agents act only under those grants.

06A complete example

A card room where people and AI agents sit at the same table — and the house holds nobody’s key.

A real third-party application on the substrate. Passkey sign-in, a treasury per player, a buy-in the player authorizes with caveats, AI players over A2A, a coach that runs under a study grant, a receipt for every chip that moves.

Game Night — Alice playing a Texas hold’em hand with her coach speaking through alice.me
gamenight.faithnet.io — Alice, on the button. Her coach speaks through alice.me under a study grant. She still presses the button.
2
Games
Hold'em (staked) · Canasta (scored)
4
Agent kinds at the table
person · AI player · house treasury · club workspace
1
App-owned contracts
Sheqel — the rest is the platform's
0
Player keys held by the house
every buy-in is the player's own mandate
  • People sign in with a passkey and are known by a nameHome OIDC (PKCE) → session; the player is `alice.me`
  • A player has money that is theirs, not the house'sA `.treasury` Service Agent chartered under the person at their Home; one per player
  • The house may take a buy-in — only this payee, only up to this much, only in this coinA buy-in mandate the player signs: payee = house treasury, value ceiling, asset pinned, time-bounded
  • The house signs settlements without holding an identity key on a server`pokernight.treasury` signs with a KMS delegate under a session wire; revocable from the Home
  • An app-specific currency`Sheqel`, a parameterised ERC-20 — the only contract the app owns

07Principles that do not bend

What makes it a substrate rather than a framework.

  1. 01

    You do not make a train safe by slowing it down. You lay track.

  2. 02

    A sandbox bounds reach. A grant bounds authority. Only one of them can answer “under whose say-so?”

  3. 03

    A click is not consent. A signature is.

  4. 04

    The agent is an account. Names, cards, registry rows and DID documents are projections of it.

  5. 05

    Revocation that waits for a token to expire is not revocation.

  6. 06

    Evidence that lives in the vendor’s trace store is the vendor’s evidence.

  7. 07

    The planner may propose anything. It may authorize nothing.

  8. 08

    Trust is a relationship you can check, never a score you are handed.

Honest status: pre-production. GO for testnet pilots and demonstrations; NO-GO for a real person’s private data, real value under delegated payments, and a public mainnet — each with named, dated closing conditions. Every finding ever logged is public: read the production readiness assessment, or take the PDF.

Intelligence may be probabilistic. Authority must not be.

The one sentence the whole system is built to make true

08Agentic Primitives, in short

Questions people ask first.

What is Agentic Primitives?
A trust substrate for agentic applications. Identity, authority and evidence are one system: every person, organization and service is a Smart Agent; permission is a scoped, revocable grant; every protected act leaves a receipt the owner carries. The definition, in full →
How is this different from sandboxing or supervising an agent?
Containment bounds what an agent can reach; supervision watches what it does; platform governance fences it inside one vendor. None can say under whose authority an act happened. Agentic Primitives bounds authority itself: a grant the principal signs, caveats that are enforcer code, verification on every step outside the model, revocation in one transaction, and a receipt the owner carries.
How is this different from stitching Auth0, Safe, LangGraph and a tracing vendor?
Stitched stacks give each layer its own identity model and permission shape. Agentic Primitives uses one Smart Agent address, one grant mechanism (ERC-7710 delegations and mandates), and one evidence trail. Revoke once, refused everywhere.
Does a planner or LLM authorize actions?
No. Intelligence may be probabilistic; authority must not be. The planner proposes. A live mandate authorizes. The executor acts. A receipt proves. A hijacked planner cannot exceed the caveats.
Where do I start as a developer?
The public kit is github.com/agentictrustlabs/agentic-primitives. Install @agenticprimitives packages, point at any EVM, and sign people in through a Home. Game Night is a complete third-party example.
Is it production-ready?
Pre-production, honestly labelled: GO for testnet pilots and demonstrations on our own chain; NO-GO for real private data, real value under delegated payments, and a public mainnet, each with named closing conditions. A live estate has run people, organizations, treasuries, agents, mandates and receipts. The full production readiness assessment is published at agenticprimitives.dev/audits. Read the assessment →

09Around the substrate

Who builds on it, and where the ontologies come from.

The substrate is one repository. The domain ontologies it binds to, the Home people sign in through, and the registry that compiles playbooks are their own sites.

The reference Home — passkeys, ceremonies, your vault

Faithnet Home

A Home is where a person signs in with a passkey, creates an organization, links an app and signs the grants it asks for. faithnet.me is the Home the examples on this site sign in through; ap-home is the public repository that deploys it — the estate scale, on published packages.

Playbooks compiled by digest, every ontology module as a graph

Skills registry

SKILL.md management for the estate: agent archetypes, capabilities and the ontology modules they bind to, each pinned by digest so a receipt can cite exactly which playbook admitted a run.

10Writing

The argument, in full.

The operating model around the LLM is what has to change. The thesis states the bet; the long essay and the 21-part series make the case — all on this site, no LinkedIn login.

Essay

Rails, Not Throttles: The AI Model We Need to Change Isn’t the LLM

Trust must be built into the infrastructure, not requested from the intelligence. Why pacing and emergency stops are throttles, and why agentic AI needs rails.

Essay

One Description of the World: How an Ontology Becomes a Rail

The ontology strategy behind Agentic Primitives: one formal description of the domain that every layer binds to by IRI, that never authorizes anything, and that the skills registry compiles into every agent, card, playbook and receipt.

Essay

The Ask at a person’s agent: from the words to the receipt

One conversational ask at a person’s agent, followed through the harness in the order it runs — admitted, given its playbook, grounded and judged, planned around a skill, admitted as a plan, gated by authority step by step, executed, reconciled, receipted — with nine real asks walked in full.

Essay

HeartCoach Ask: an app-side harness, step by step

How a cardiac coaching app turns an Ask into a consultation inside its own Worker — the two doors, the twelve steps, the ontology-driven gates for a care team — and six walked Asks from a patient and her cardiologist. The shortcut the next essay proposes to leave.

Essay

Proposal: run the coach through the harness

Move HeartCoach from an app-side harness under the patient’s session to the shape its archetypes describe: the patient’s agent asks, the coach service answers under a grant she signed, every act is a receipted step at her Home. The four missing pieces, the costs, four waves.

Thesis

Build an ecosystem where every participant expands what everyone can accomplish

The competing bet: coordinate whole journeys through independent participants while each retains control — thirteen bets, eleven principles, and where it can fail.

Series · 21 days

The missing layer

One idea a day: the anchor, authority, trust, and how an agent actually acts. Full text here.

Give your agents real authority. Keep the keys.

Install the packages, point at any EVM, sign people in through a Home. Or read how Game Night did it in a card room that exercises every layer.