Concepts
Passport, Mandate, Ledger, Door, Witness, Anchor — the model in plain words.
Door
Any Mandare component an action must pass through: the LLM gateway, the credential vault, the card rail. Doors share one discipline — log-before-act: write the intent to the ledger, execute, write the result. No entry, no action. A refused action is also an entry: the system records its no's.
Passport (who)
Each agent holds its own Ed25519 key. A delegation credential (SD-JWT VC)
signed by the owner — and countersigned by an attestation authority — binds
that key to the accountable human. Agents sign every request under their key
(RFC 9421 HTTP Message Signatures, with a Content-Digest over the exact body
bytes), so the door verifies who acted, not just who held a token. All
identifiers are did:key: verification is offline, no resolver, no phone-home.
Mandate (may)
The signed permission slip: spend caps per transaction / day / task / total, validity window, allowed scopes, and an approval threshold above which a human must asynchronously approve. Mandates are signed by the owner and self-verifying; the policy engine evaluates the same fixed order on every action (identity → window → scope → budget → counterparty → approval). Caps are enforced by reservation: an intent reserves its estimated cost inside the ledger transaction before the call; results settle the true cost. Two concurrent calls cannot both squeeze through the last euro of a budget — that is structural, not statistical, and there is a red-team test racing 20 calls to prove it.
Ledger (did)
Append-only, hash-linked, door-signed entries in SQLite (solo) or Postgres
(team). Budget counters and revocation state are projections of the
ledger — derived tables, rebuildable from the entries, with a verifier
(mandare verify --spend) that recomputes them from scratch and compares.
The ledger's RFC 6962 Merkle tree head is the chain's fingerprint: inclusion
proofs disclose single entries; consistency proofs prove append-only growth.
Kill switch (stop)
mandare kill <agent> (or --mandate, or --all) writes a revocation entry
locally — offline, no cloud dependency, nothing to jam. The gateway checks
revocation state on every request, before auth, so even a killed agent's
refusal lands on the ledger. Scoped tokens die with their actor; virtual
cards decline at the network. Revocation state renders into one IETF Token
Status List bitstring — agents, mandates, doors, and cards share a single
revocation vocabulary.
Witness (can't rewrite)
A ledger on your own disk can be truncated or re-signed by whoever holds the
machine. The witness closes that: the door streams salted chain-head
fingerprints (32 bytes, content-free) to an external witness that enforces
append-only consistency at submission time and signs acknowledgements.
mandare verify --witness convicts truncation and rewrites that self-anchored
verification cannot see. High-value actions (the mandate's approval-threshold
set) can be gated on a verified witness ack — a zero tamper window for
the actions that matter. A dead witness fails those actions closed and never
blocks a kill.
This holds against the machine's own operator only when the witness runs somewhere the operator does not control — team mode, or a second host. In the single-host solo stack the witness shares the machine, so a full-root operator holds both the ledger and the witness key and can rewrite + re-witness consistently; see the threat model for that residual.
The journal explains why the record stays on your machine and only a fingerprint leaves it.
Anchor (even we can't)
The witness aggregates all sources into one Merkle tree and anchors the root
publicly (OpenTimestamps by default: a receipt stays pending until the
calendars' Bitcoin attestation lands, hours later). The integrity certificate
(mandare certify) packages selective disclosures with inclusion proofs,
witnessed-head consistency, and the public anchor — verifiable by a third
party with no ledger access and no trust in Mandare.