The Service Twin, and the naming collision
Summary
The newest and strongest material, and the document that resolves the problem it describes. It sets out the execution broker (an agent presents a cryptographic identity, a signed mandate and contextual evidence; the broker verifies, performs only the permitted operation with credentials held inside its own boundary, and returns a signed receipt), states the boundary it closes that short-lived credentials and gateway policy cannot, and adds the two costs the original did not foreground: the concentration risk that inverts the estate's catastrophic failure property, and the fact that enforcement is interpretation rather than proxying, making the broker an interpreter per provider per capability. It then rules on the naming collision the corpus flagged in itself.
Key concepts
- Authorised action — the unit of delegation stops being credential access
- The concentration risk — the highest-value target in the estate
- Interpreter, not gateway — one interpreter per provider per capability
- The naming ruling — twin keeps its corpus meaning; the broker is named by its function
Key ideas
- A system can say this agent may hold this token for five minutes; it cannot say this agent may perform exactly this operation, once, at this stage.
- The broker can, because the agent does not perform the action at all.
- Encryption and authorisation must remain separate concepts.
- Receipts create an evidence chain rather than relying on mutable platform audit logs.
- The two designs compose: the twin carries the persona and the reasoning, the broker carries the credential and the enforcement.
On this site
Split across the broker page (sections one and two) and the naming ruling (sections three and four), with the composition stated on actors.