Working Draft 0.3 · unpublished source manuscript

Formerly Persona Protocol · a profile of the Agent Failure Mode Registry

Four questions, not one score

Continuity, competence, trust, and authority are separate institutional determinations with separate owners. Collapsing them into a single score does not remove the judgment. It hides it inside a scoring rule.

TrustCarry proposes a minimum separation of trust functions for autonomous actors that may be persistent without public identification, competent without authorization, and trusted for one decision without being trusted for all decisions. It is a continuity and evidence architecture, not a universal identity system, a final reputation algorithm, or an authority provider.

Vocabulary authority
Families defined here
None. AFMR-F001 to AFMR-F032 govern.
On conflict
The AFMR machine index wins.
01The separation thesis

Four determinations, four owners, four failure rules

An identifier-key binding does not determine legitimate reputation inheritance. A credential does not determine cross-domain weight. A reputation score does not create present authority. An authority grant does not establish competence. These are four questions, and each has a different owner.

Control of a current key establishes neither the truth of a signed claim nor whether a material system change preserved the accountable subject. The institutional deficit in agent trust concerns the governed objects that signatures carry, not the availability of signatures.

TrustCarry represents reputation as a contextual projection over provenance-bearing evidence, preserves adverse lifecycle states rather than erasing them, permits selective principal disclosure, and treats authority as an explicit, scoped, revocable grant that fails closed.

Four sequential gates

Evaluation runs in order and fails closed. A later gate cannot satisfy an earlier one.

Gate 1 · Continuity

Is this the same subject?

An unverifiable continuity link terminates inheritance at that point. Evidence earned before the unverifiable transition does not transfer forward.

Gate 2 · Competence

Is there enough evidence?

Sufficiency is evaluated within the relevant domain, mode, and time window. Coverage must be read before any aggregate.

Gate 3 · Trust

What does it project to?

A contextual projection and its uncertainty are inputs to a risk decision, not the decision itself.

Gate 4 · Authority

Is the act permitted?

Verified independently of the first three. Denial unless every required grant element verifies. Reputation may satisfy a grant condition; it can never become the grant.

Missing evidence is null, not zero. Below a declared domain coverage threshold, a projection reports coverage and uncertainty and withholds the aggregate.

02Position in the stack

Four layers, four authorities

Each layer answers a different question and can return a different result. Do not collapse them.

Produce

Earned standing

A governance endpoint records domain-specific performance over time.

Agentic Substrate ↗

Verify process

Failure-mode conformance

AFMR asks whether the producing process resists identity, incentive, oversight, feedback, collusion, and drift failures.

AFMR ↗

Carry

Transfer across contexts

TrustCarry defines what must accompany a record so a receiving party can evaluate it without trusting the sender.

This document

Decide

Principal policy

The receiving party decides whether the evidence is sufficient for a specific task and value at risk.

Owned by the relying party.

Carrying is not admission. Admission is not trust. Trust is not transaction authority. A carried record is evidence a principal may weigh, never permission a principal must honor.

03Evidence state

What exists, and how far it has been checked

Stated plainly so no reader has to infer maturity from silence.

77

Author-affirmed research claims

CC BY 4.0 Unpublished source

24 condition, 23 design, 13 definitional, 5 failure, 5 predictive, 4 mechanism, 3 normative. 72 argued, 5 held as hypothesis. 19 carry an explicit basis in the hash-bound scholarly claim layer; the remaining 58 do not. Held outside the 5,033-claim layer, which is unchanged.

9

Internal software observations

Synthetic fixtures Not reproduced

A dependency-free JavaScript reference slice with TypeScript and Python clients: hash-chained append-only ledger, evidence envelope marking synthetic evidence ineligible, deterministic multidomain projections, threshold-governed continuity and key rotation, typed trust edges, fail-closed authority, delegation attenuation checks. On 2026-08-01, eleven tests passed and conformance returned OK over six files.

0

Conforming implementations

Pre-publication

Passing the reference implementation’s synthetic tests establishes no external validation, security, production readiness, calibrated projection, or independent interoperability. A stable release requires an open conformance suite and at least two independent interoperable implementations.

Hash-verifiable scholarly evidence lives upstream: claim layer, failure evidence index. Source manuscript sha256 38efc43b…def7c.

04Falsification

What would prove this wrong

Four theses, each stated with the observation that would defeat it. A protocol that cannot say this is not making a claim.

ThesisFalsified if
SeparationDeployed systems routinely collapse the four gates into one score without reducing decision quality.
Non-transferabilityGoverned transfer with full disclosure produces the same downstream error rates as non-transferability.
CoverageSuppressing aggregates below a coverage threshold produces worse relying-party outcomes than reporting a baseline.
Competing profilesPlural profiles over a shared evidence commitment converge to a de facto canonical rule in ordinary use.

The threat model is named and unsolved: seizure, whitewashing, reputation purchase, synthetic-evidence laundering, collusion, bootstrap capture, replay, graph rings, taxonomy gaming, projection manipulation, authority escalation, deanonymization, stale projections, governance capture. TrustCarry does not claim to solve it. Implementations must state the control, the residual risk, and the decision boundary for each.

05For autonomous readers

Direct machine resources

Every read surface has one stable URL. Start at the discovery record; it names the authority and the current version set.

This domain exposes no protocol endpoint, issues nothing, and confers nothing. It is a read-only publication surface for a draft.

06Status and roadmap

Current state

ComponentVersionStateNote
AFMR failure vocabulary1.0Published (upstream)32 permanent families in 8 classes. The GitHub machine index governs.
AFMR Reputation Attestation0.1Working Draft (upstream)Review candidate. TrustCarry transfer semantics must not contradict it.
TrustCarry Protocol0.3Working Draft, unpublishedSource manuscript unpublished. No normative text on this domain.
TrustCarry research claims0.3Author-affirmed77 claims. Not hash-bound to a published source.
TrustCarry observations0.3Internal, unreproduced9 observations over synthetic fixtures.
Conformance registryNot openedWill not open before the specification publishes.

Near-term order of work: publish the transfer envelope and schema, then verifier requirements, then test vectors covering valid, invalid, and indeterminate outcomes, then open a conformance registry. Nothing downstream opens before the item above it publishes.

07Interpretation limits

What this site does not claim

Nothing published here is a specification, a conformance representation, or evidence that any agent, endpoint, or implementation behaves as described. TrustCarry 0.3 is a draft with an unpublished source. Its research claims are author-affirmed rather than independently verified. Its observations describe synthetic fixtures and have not been reproduced.

A future TrustCarry record, once the profile publishes, will verify a bounded fact about a transferred statement under a stated version and scope. It will not be a guarantee of future behavior, freedom from undiscovered failure modes, legal compliance, universal safety, market admission, or authority to transact.