Solutions
One engine.
Many applications.
The same Mandate → Gate → Receipt engine, expressed for the environments where delegated authority is already failing. There is no per-industry logic: an industry is a data file, not a rebuild.
01 Applications
Five applications, one control point.
Availability is stated before any engagement begins. Nothing on this page is in production use.
02 Agents & APIs
Authority for autonomous agents.
An agent should be able to act on your behalf without being handed the keys to everything.
A Mandate bounds an agent to one task, one budget, one window. The Gate checks every consequential call and receipts it. Over-ceiling requests step up to you rather than fail silently or over-reach. When the Gate is in front of an API, the same holds for any automation that reaches an internal service, a data store or another team’s system.
- One task, one budget, one windowMandate
- Every consequential call checked and receiptedGate · Receipt
- Above the ceiling: ask, do not fail silentlySTEP-UP
- Resource scope, rate, delegation depth for software estatesLimits
03 Commerce
Let agents transact —
under authority you control.
Agents are already shopping, comparing and booking. There are two halves to being ready for them.
Prepare · WorldAuth DMI
Make your surface directly operable by machines
Being discoverable, understandable and safely transactable by AI means exposing authoritative state, capabilities, constraints and actions to machines directly, rather than asking them to reconstruct a human interface first. Non-authoritative and reversible, designed to be adopted widely without a sales conversation. The claims application’s free audit is live and paid publishing is not open yet: a free audit at claims.worldauth.com needs no account.
Authority · WorldAuth
Govern what an agent may actually do
Spend limits, approved actions, Receipts. Attach a Gate to checkout and booking so every consequential action runs under a Mandate and leaves a Receipt. This is the half this site is about, and it is delivered through certified partners.
The other side of the same transaction: DMI Runtime is the product line for teams whose agents act on other companies’ websites — reliably, cheaply and within the rules.
04 Media · Evidence
What the machine sees,
and how sure it is.
WorldAuth Evidence gives agents a structured way to understand rich media and content without repeatedly processing the full source — while preserving what was observed, inferred, declared, verified or still unknown.
| Class | What it means | Weight |
|---|---|---|
| Observed | Present in the source itself — read directly from the content, page or media. | Strong |
| Declared | Stated by the organisation about itself. Accurate or not, it is attributable. | Attributable |
| Inferred | Derived by a model. Useful, and never promoted to fact. | Qualified |
| Verified | Independently checked against evidence, with the check itself recorded. | Strong |
| Unknown | Genuinely absent. Distinguishing “unknown” from “false” is a security property, not a nicety. | Never guessed |
Inference is not verification.
And neither one is authority.
Evidence sits behind the Assurance Firewall: it can inform whether authority is granted or accepted and never becomes authority. Provenance travels with the asset (C2PA-aligned). Status: architectural direction and reference implementation; not a production service today.
05 Insurance & Risk
Evidence an underwriter can price.
Every WorldAuth decision produces attributable, signed evidence bound to the exact request.
Insurers, auditors and counterparties can verify what was authorised, by whom and within which limits — without a central surveillance trail. Priceable risk, provable controls.
Insurance and risk functions consume WorldAuth evidence and may set requirements. WorldAuth is not an insurer, makes no premium claims and carries no risk.
- What was authorised, by whom, within which limitsReceipt
- Verifiable by any party holding the Gate’s keyEd25519 · RFC 8785
- Held in your estate, not a global ledgerYour control
06 Sovereign
The same architecture,
under your control.
A high-assurance deployment profile for environments that require local control over policy, trust material and evidence — without forking the protocol or creating a separate authority system.
Local
Trust material
Trust anchors, issuer keys and status material are operated locally rather than depending on an external directory.
Local
Policy
Policy authoring, distribution and evaluation stay in the operator’s control, using their own engines where they prefer.
Local
Coordination
Consumable authority is coordinated by an operator-run reservation service, not a shared external one.
Local
Evidence
Receipts and evidence remain in the operator’s estate. Nothing about the profile requires exporting them.
Not a surveillance system, not a separate protocol, not a compliance guarantee. Same objects, same invariants, same decisions; a Sovereign deployment stays interoperable rather than becoming a national fork. Status: architectural direction; deployments are scoped case by case.
07 Where it applies
The same question, in different clothes.
Each of these is a case where something acts on behalf of someone else and the limits matter. Illustrative applications of the architecture, not a list of shipping integrations.
| Setting | The authority question | What bounds it |
|---|---|---|
| Procurement | An agent negotiates and places an order with an approved supplier on a buyer’s behalf. | Value ceiling · supplier scope · expiry |
| Customer service | An assistant issues a refund, changes a booking or updates a record for a customer. | Action scope · per-case limit · escalation |
| Software estate | An automation reaches an internal API, a data store or another team’s service. | Resource scope · rate · delegation depth |
| Field operations | A contractor or device is granted access to a site, a system or an asset for one job. | Time window · single resource · revocation |
| Finance | A system moves value or commits spend within a delegated budget. | Coordinated reservation · step-up above a threshold |
| Insurance & risk | An underwriter or risk function needs to see what an automated action was actually permitted to do. | Receipt evidence · under your control |
Keep
Your identity provider
WorldAuth binds to the identity and workload systems you already operate. It does not become your system of record.
Keep
Your policy engine
The Gate evaluates your policy locally using supported engines and standard policy interfaces where appropriate.
Keep
Your data
Sensitive evidence and Receipts stay in your estate by default. WorldAuth is designed to hold as little as possible.
The point is not to add a checkpoint.
It is to make the checkpoint mean something.