Track: Agents (Concept lane)

The Problem

Egoist's AI Passport already lets a person connect their apps, review new context before it's shared, and audit receipts of what each app used. That model works well for a human sharing their own preferences. It breaks down the moment an AI agent is the one acting on someone's behalf: an agent doesn't just read context, it spends money, sends messages, and signs up for things -- and if it does real damage while staying fully inside its granted permissions, today's passport has no way to make the victim whole. Reviewing and revoking access after the fact does not undo a bad trade, a wrong payment, or a leaked deal. Permission and receipts answer "what happened." They do not answer "who compensates the person who got hurt, and how fast."

Who Is Affected

Anyone who delegates real-world tasks to an agent connected through their passport (spending, negotiating, messaging on their behalf), and anyone on the receiving end of that agent's actions -- a client double-billed, a vendor underpaid, a customer misled -- who currently has no built-in way to be compensated even though the agent's own receipts prove exactly what it did.

The Idea: AgentPass Surety

AgentPass Surety adds one missing layer on top of Egoist's existing connect -> review -> control -> receipts flow: a bond behind every permission an agent is granted.

  • Bond at grant time: when a person approves an agent's access in their passport (the same review step Egoist already has), any permission with real-world financial or reputational risk requires a small staked bond, sized to that risk, held in escrow.
  • Receipts become claims, not just logs: Egoist's existing audit receipts already show exactly what an app or agent did. AgentPass Surety reuses that same receipt to automatically trigger a payout from the bond the moment a receipt shows verified harm inside the agent's authorized scope -- no lawsuit, no support ticket.
  • A trust score that travels with the passport: an agent's bonded history becomes a portable score attached to the same identity Egoist already verifies, so the next app or business deciding whether to grant that agent access can see real track record, not just a permission request.
  • Revocation stays exactly as-is, plus a payout: the person keeps the same one-click control Egoist already offers to cut off an app or agent instantly; now revocation after harm also releases the bond to whoever was affected.

Context, Permission, Proof, and Access Involved

  • Context: the task category and real-world risk level of the permission being granted (e.g. "send payment," "sign contract") at the moment it is reviewed and approved.
  • Permission: the same explicit, human-approved grant already in Egoist's flow, now tagged with a bond size proportional to its risk.
  • Proof: the existing audit receipt, extended to double as a claims trigger when it shows the agent caused verified harm while acting inside its granted scope.
  • Access: apps and other agents can check bond status and trust score before accepting a request, without ever seeing the person's raw passport data.

Who Controls Access

The person, exactly as in Egoist's current model: they approve every new connection, choose the bond level for risky permissions, and are the only one who can revoke access -- now with a payout attached when a revoked action already caused harm.

What Can Be Revoked or Changed

  • Access can be revoked instantly, same as today, releasing any unclaimed bond back after a short claim window if no harm was reported.
  • Bond size can be raised any time a permission's risk increases; it can only be lowered when no pending claim exists.
  • Trust scores update automatically from receipts and can never be manually cleared by the agent or its operator.

Risks and Misuse Concerns

  • Under-bonding risky permissions: prevented by tying bond size to permission category, not letting the agent operator self-select a lower amount.
  • False claims to drain a bond: prevented by requiring the same cryptographic receipt Egoist already generates before any payout is released.
  • Reputation reset via a new agent identity: reduced by anchoring the trust score to the verified human/org identity behind the agent, not a disposable connection ID.
  • Bond costs discouraging adoption: mitigated by only requiring bonds on permissions with real financial or contractual risk -- low-risk context sharing stays exactly as free and frictionless as it is today.

Why This Is the Natural Next Version

This is not a separate product bolted onto AI Passport's name -- it is the next logical layer on the exact flow Egoist already ships: connect, review, control, receipts. It just adds the one piece missing for agents to be trusted with real consequences: a bond behind the permission, so the receipt that already proves what happened also pays for what went wrong.

Built With

  • ai-agents
  • cryptography
  • jwt
  • node.js
  • policyengine
  • public-key
  • reputation-scoring
  • smart-contracts
Share this project:

Updates

Submission history