commit_id = sha256(JCS(object − {commit_id, signature}))
content-addressed id over the canonicalized object, with the id and signature fields removed.
signature = Ed25519_sk(JCS(object + commit_id))
deterministic Ed25519 signature over the canonical object plus its freshly computed commit_id.
agent_id = did:alethech: + b32(sha256(JCS(pk))[:16])
identity derives from the root public key — operational keys rotate, the agent_id does not.
C ∈ ancestry(cutoff_head) ⟹ VALID_HISTORICAL
a commit is valid iff its ancestry is reachable from the last pre-rotation head.
- ✓signature verifies against declared public key
- ✓commit_id matches SHA-256 of canonical JSON
- ✓agent_id derives from public key (not declared)
- ✓key rotation preserves identity (root-bound)
- ✓revoked key commits checked against ancestry(cutoff_head)
- ✓checkpoint head must be ancestor of current HEAD
- ✓import is atomic (verify-then-write, target untouched on failure)
- ✗does NOT prove content truth
- ✗does NOT encrypt at rest
- ✗does NOT detect rollback without external checkpoint
- ✗does NOT delegate permissions between agents
- ✗does NOT call any LLM