This repository contains bounded reference applications for Agent Identity, permission enforcement, continuous assurance, scoped evaluator evidence, Trust Passport rendering, and external registry verification.
- Run
python demo.pyto see an enterprise agent move from ACTIVE to SUSPENDED when an unverified MCP endpoint is introduced. - Run
python verify_registry.py --helpto verify an exact certificate against a locally pinned issuer JWK and render a human-readable Trust Passport only when the record is ACTIVE. - Run
python -m unittest discover -s tests -vfor transition and cryptographic verification tests.
The continuous-assurance flow is a deterministic local demonstration. Its states are simulated technical assurance states, not AATS certificates. The registry verifier accepts only an ACTIVE record whose ES256 signature validates against the operator-pinned key; it does not decide whether the issuer or assessor is trustworthy. Production still needs identity-bound ingestion, tamper-resistant storage, independent assessment, key rotation, scoped evaluator authentication, and execution-boundary enforcement.