Agentic PrimitivesAGENTIC PRIMITIVES

Platform

Nine capabilities.
One substrate.

Each offering is independently adoptable and depends only on the ones below it. Together they are every capability an agentic application needs — from a person's first passkey to the receipt for an AI agent's last action.

01Where it runs

An estate: one deployment of the substrate, many applications around it.

Home for people and ceremonies, a runtime for agents, vaults for records, an edge for admission, discovery and a skills registry, and a chain for the anchor. Your application is a relying app: an OIDC client and an A2A caller.

An estate: Home, agent runtime, vaults, edge, discovery, skills registry and chain — with relying applications around itPeoplebrowser · phonepasskeysClaude.ai (Home MCP)Relying applicationsgamenight.faithnet.ioskills.faithnet.ioyour app— OIDC client + A2A callerOutside agentspartner A2A agentsClaude Code / goose (ACP)MCP clientsHome · www.faithnet.meVercel · Next.jspasskey sign-in · OIDC issuerceremonies: charter, invite, delegateapprove parked runs · revokeToday · Work · Library · BuildAgent runtime · a2a.faithnet.ioCloudflare Workers + Durable Objectsone A2aTaskDO per agent · harnessplaybooks by digest · triggersbudget-routed models (Groq / Haiku)Vault · MCP (private)per-agent encrypted recordsper-record delegation scopeinbox · roster · receipts · memoryEdge · edge.faithnet.ioadmission (always)standard A2A surface /api/a2a/<name>HTTPS req. · mTLS optionalDiscovery · discovery.faithnet.ioindexer → GraphDBpublic, on-chain-derivable facts ONLY/.well-known/ard.json · ACP registryA2A + MCP question surfacesSkills registry · skills.faithnet.ioarchetypes → SKILL.md contractscompiled AgentHarnessDefinitionpinned by digest; assigned at HomeKMS · GCP / AWSservice keys are DELEGATESsession wires the custodian mintsrevoke one wire, not an identityfaithchain · rpc.faithnet.ioBesu QBFT · chain 34348 · 2 s blocksAgentAccount factory · namesDelegationManager + enforcersregistries · attestationsSheqel (the card room's coin)— any EVM worksGuaranteesHome: the only placea person signs. Runtime: no stepwithout a live grant. Vault: records theowner can carry. Edge: admissionbefore anything. Discovery: nothingthe chain does notalready say. KMS: compromisea delegate, neveran identity. Chain: revocationis final and global.sign in · approveOIDC + delegationA2A intentsadmitted at the edge/harness/askrecords under delegationthen the runtimeplaybook by digestsigns as delegatediscovergrants · receiptsindexer reads chainOne estate, many applications. A second estate is the same shape with different names.agenticprimitives.dev
The faithnet estate as deployed today. Names are the estate's; the shape is the substrate's. Home runs on Vercel; the runtime, vault, edge, discovery and registry are Cloudflare Workers; the chain is a private Besu QBFT network — any EVM works.

02Live

The estate, as its people see it.

Screens from the running faithnet estate, signed in as the Home's demo people. Every product here is a relying application of the same substrate.

Home — Messages, with an Ask suggesting a payment and a club invitation
Home · Messages. A conversation with bob.me; the Ask offers 'Finish sending 1.2 USDC to bob.me' — a step that will park for her signature. goose-1.svc and goose-2.svc are runtime members that joined over ACP.
Game Night — Your money, showing alice2.treasury and the authorise-buy-ins ceremony
Game Night · Your money. 10,000 SHQ in the treasury the Home chartered for her; the buy-in authority is signed at her Home — the card room never can.
AP Discovery — find an agent for what you need
Discovery · a public knowledge graph projected only from chain state; the ranking is fit + verifiable trust, never a vendor score.
Skills app — Texas Hold'em domain overview, signed in as alice: 95 T-box classes, 16 SHACL shapes, 5 capabilities, 10 linked skills, 2 agent archetypes
Skills · the Texas Hold'em domain as alice sees it. One domain: 95 classes, 16 shapes, 5 capabilities, 10 SKILL.md packages and 2 agent archetypes — derived from agentic-trust, PROV-O and DOLCE. Publishing acts as her Smart Agent.

01 Identity

One canonical agent per person, organization and service.

Smart Agent accounts with passkey control, credential recovery, typed on-chain names and signed agent cards. The address is canonical; everything else points at it.

What you would otherwise stitch

  • Auth0 / Okta / Cognito
  • wallet-connect + a users table
  • a DID method of your own
  • a naming service

Standards

ERC-4337ERC-1271WebAuthn / passkeysOIDC + FedCMW3C DID

02 Authority

Scoped, revocable grants between agents — the core primitive.

Delegations with caveats, intent-bound mandates, custody policy (thresholds, guardians, recovery) and entitlement resolution. A person delegates to an organization; an organization to a service; a service to a bounded session key.

What you would otherwise stitch

  • RBAC / ACL tables
  • OAuth scopes as permissions
  • Safe-style multisig
  • session-key managers

Standards

ERC-7710ERC-7579 modulesEIP-712ERC-6492

03 Harness

Ask → Intent → Mandate → Plan → Verify → Receipt.

An authority-aware agent loop: the planner proposes, the mandate authorizes, the executor acts, the receipt proves. Durable runs, streamed progress, parallel read steps, schedule and message triggers, per-run bills.

What you would otherwise stitch

  • LangGraph / MAF / CrewAI wiring
  • a human-in-the-loop click UI
  • Temporal for approvals

Standards

A2A 1.0 (TCK-green)MCPAgent Skills (SKILL.md)

04 Edge

Admission at the boundary — HTTPS required, mTLS optional, authority always.

A2A over HTTPS with application authentication, canonical identity resolution and an admission stage that no transport evidence can skip. Private MCP behind admitted runtimes; public MCP only as labelled interop.

What you would otherwise stitch

  • API gateways with bespoke auth plugins
  • service-mesh identity as authorization

Standards

A2A over HTTPSRFC 9728OAuth 2.1 (ingress only)SPIFFE (optional binding)

05 Registry Kit

Build your own registry; be what registries are built from.

SA-anchored registry contracts with pluggable admission hooks, admission receipts, a lifecycle log, signed agent cards, discovery projections (A2A card, ARD, ACP registry) and a public knowledge base projected only from chain state.

What you would otherwise stitch

  • a hosted agent directory you rent
  • ERC-8004 / ANS / DNS bridges you maintain

Standards

ARD v0.91ACP registryA2A Agent CardSPARQL / RDF

06 Evidence

Receipts, provenance and audit that outlive the platform.

Verification receipts bound to intent + mandate + step + playbook digest; PROV-O graphs with a trace-context spine; append-only audit with forensics tooling; verifiable credentials for claims.

What you would otherwise stitch

  • LangSmith / Langfuse as the record
  • application audit tables
  • a credentials vendor

Standards

W3C PROV-OW3C VC 2.0W3C Trace ContextOpenTelemetry

07 Coordination

Work between agents: endeavors, plans, commitments, decisions.

A durable Endeavor with a shared plan, participants found through discovery at the capability level, signed contribution commitments against an exact plan revision, decisions and rules. Never confused with in-agent orchestration.

What you would otherwise stitch

  • a project tool bolted to a chat tool
  • workflow engines as the source of truth

Standards

PROV-O plansERC-8001-shaped commitmentsValueFlows

08 Ontology

How the domain is shaped — bound by IRI, checked at build.

An upper ontology for everything agentic — agents, credentials, custody, delegation, capabilities, situations, provenance — that a domain ontology imports and subclasses. From the two, an agent archetype bundles skills, capabilities and ontology areas; from the archetype, the A2A signed agent card and the SKILL.md packages are projected. Vault records are ontology-shaped; behaviour is generated from the model; a gate fails the build when code invents a term.

What you would otherwise stitch

  • prompt-resident domain rules
  • app tables that disagree with each other
  • an agent card typed by hand

Standards

RDF / OWL / SHACLPROV-OJSON-LD

Ontology, live

Define the domain once. Every agent surface is projected from it.

An upper ontology says what every agentic system has. A domain ontology imports it and says what this domain has. An archetype bundles the skills, capabilities and ontology areas one kind of agent needs. From that, the A2A signed agent card and the SKILL.md packages are generated — never typed by hand. Meaning flows down the ladder; authority never does.

From upper ontology to signed agent card: Agentic Trust → Texas hold'em → Hold'em Coach archetype → A2A capabilities and SKILL.md packages1 · FOUNDATIONS2 · UPPER ONTOLOGY3 · DOMAIN ONTOLOGY4 · AGENT ARCHETYPE5 · PUBLISHED ARTIFACTSDOLCE · PROV-O · ep-plandul:Description / dul:Situationprov:Entity · Activity · Agentp-plan:Plan · Step the trichotomy nothingmay subsume acrossagentic-trust (at:)46 semantic modulesAgents & IdentityDelegation & AuthoritySkills & CapabilitiesProvenance & Crypto TrustSituations & Descriptionstexas-holdem (th:)14 modules · owl:imports at:Coaching · The Hand · AdviceCoachService ⊑ at:ServiceAgentStudyGrant ⊑ at:DelegationConsultation ⊑ at:SkillInvocationHandReview ⊑ at:Assessmentholdem-coacha Service Agent a coach custodiesskills: holdem-preflop · -flop -turn · -river · -memory · -reviewcapabilities: poker.advise poker.review (never poker.act)knowledge.requires: 14 th: classesA2A signed agent cardskills[] = capability idsES256 JWS · delegate key theauthor authorised onceverifiable against the JWKS SKILL.md packages by digestgroundsimports · subclassesbundlesprojectswhat kind of thing is it?what does every agentic system have?what does THIS domain have?what does one agent bundle?what does the world see?ONE THING, FOLLOWED DOWN THE LADDER — THE STUDY GRANTdul:Description → prov:Entityat:Delegationth:StudyGrant ⊑ at:Delegationknowledge.requires: [StudyGrant]card: advise · reviewThe coach reads her hands only under a grant she signed at her Home; the domain ontology says what the grant IS; the archetype declares it must know that class;the SKILL.md for each street names it in knowledge.requires; the agent card advertises the two capabilities that need it. Change the class once and every surface moves.A SHACL shape on th:StudyGrant is checked at build — a playbook that names a class the ontology does not have fails to compile.WHAT FLOWS DOWN THE LADDER, AND WHAT NEVER DOESMeaning flows down: classes, shapes, capability ids, the words an Ask understands, the tools an agent may be given, what follows an act.Authority does not. An archetype grants nothing; a signed agent card grants nothing; a SKILL.md grants nothing. No verifier reads any of them.The only thing that lets the coach see Alice's hands is the StudyGrant — a delegation she signed, caveated, revocable in one transaction.behaviour is generated · authority never isagenticprimitives.dev
Four rungs, one class followed down them. th:StudyGrant is a subclass of at:Delegation; the coach archetype declares it must know that class; the review SKILL.md names it in knowledge.requires; the agent card advertises the two capabilities that need it. The grant itself is the only thing that lets the coach see a hand.
Agentic Trust upper ontology — the Delegation & Authority module graph
1 · Upper ontology. agentic-trust, module Delegation & Authority: Delegation ⊑ prov:Entity, Delegator and Delegate as roles, Delegation Caveat, Caveat Enforcer, Trust Assertion — 46 modules that every domain inherits rather than re-mints.
Texas Hold'em domain ontology — the Coaching module graph
2 · Domain ontology. texas-holdem, module Coaching: Coach Service, Study Grant, Consultation, Hand Review, Coach Note, Review Request — each grounded on an at: class from the rung above (◇ marks the inherited base).
Agent archetypes for Texas Hold'em — Hold'em Coach and the coach Bob custodies
3 · Archetype. Hold'em Coach: eight card-room skills, the capabilities poker.advise and poker.review, and fourteen ontology areas from Study Grant to Coach Note. A second archetype layers Bob's doctrine on the same craft.
The Hold'em Coach's A2A signed agent card — ES256, delegate-signed, verifiable against the JWKS
4 · Artifacts. The A2A agent card, server-built and signed by a delegate key the author authorised once, verifiable by anyone against the published JWKS. Its skills[] are the capability ids the ontology names; the SKILL.md packages beside it compile by digest.

What this replaces

A system prompt that explains the domain, a table in the app that disagrees with it, an agent card typed by hand and a playbook that names things the model has never heard of.

What is checked

SHACL shapes on every class. A SKILL.md whose knowledge.requires names a class the ontology does not have fails to compile. Code that invents a term fails the build.

What is not authority

Any of it. The archetype, the card and the playbook are consulted by no verifier. The coach reads Alice's hands under a Study Grant she signed at her Home — and loses them the moment she revokes it.

09 Operations

Run it: KMS delegates, deploy recipes, live gates, conformance.

Service keys as revocable delegates (never the identity), budget-routed model selection, live verification gates that run nightly against the real estate, `ap conform` for A2A and MCP.

What you would otherwise stitch

  • a secrets sprawl you audit by hand
  • a QA suite that only runs on mocks

Standards

GCP / AWS KMSA2A TCKMCP conformance

How they compose

Dependencies point one way. No back-edges.

types ← identity-auth ← agent-account ← delegation ← mcp-runtime
types ← custody → agent-account, delegation
key-custody → delegation · tool-policy → mcp-runtime
orchestration (core) ← orchestration-anthropic (adapter)
coordination ⟂ orchestration — composed only by the runtime
edge, brokers, workload identity: leaf bindings, depend inward

Ring 0 is packages and contracts. Products — a Home, a discovery service, a naming service, your application — live in their own repositories and import the packages. Integrations with other people's protocols (ERC-8004, ANS, HCS, DNS-AID, OASF) live outside too, importing inward, never the reverse.

That is what lets you take one offering without the rest, and what keeps a vertical's vocabulary out of the primitives: the packages are generic trust building blocks; branding, verticals and deployment specifics are the application's job.

Package map and quickstart

See all nine at work in one application.

Game Night uses Identity, Authority, Harness, Edge, Registry Kit, Evidence, Coordination and Operations — in a card room.