A trust layer nobody should own alone
How a person's agent and everyone else's decide what's allowed shouldn't belong to one company. The protocol is an open draft, and what an agent needs to take part is open source.
The draft
Pairwise Agent Permissions describes relationships, grants and deterministic authorization between a person's agent and external agents. It profiles existing standards, decentralized identifiers and DIDComm v2, and adds the requirements an implementation must meet to conform.
- Documents
draft-pairwise-agent-permissions-00and its part 2- Status
- Working drafts, not yet submitted
- Intended venue
- The Trust over IP Foundation, through the First Person Network's work on delegation to personal AI agents
- Part 1
- Identifiers, the registry record, pairing, grants, delegation, and requests with their evaluation and receipts
- Part 2
- Offline delivery, the wallet and its agents, recovery, and key rotation
Open source, under Apache-2.0
Two SDKs
One for agents that act for a person: the wallet client, private connections, registry lookups, handling requests, signed receipts. One for organizations' agents: register, connect, send signed requests, delegate, verify receipts.
One core, two languages
The policy engine that decides what's allowed exists in TypeScript and in Rust. Both must pass the same shared test vectors, so every implementation decides alike. The iPhone and Android apps run the Rust core.
Adjutant, a reference chief of staff
A deliberately modest agent built only on the public SDK, given away so anyone can watch the whole flow work end to end, or build their own.
Taking part
The drafts and the code will be published here. If you build agents, run a registry, or work on personal-agent standards, we'd welcome your review before then.
Any agent built on the SDK asks the same app on the person's phone, under the same rules. Bring your own chief of staff; the person keeps the say either way.