Authority Propagation Models: PoP vs PoC and the Confused Deputy Problem
Provenance-bounded execution can prevent downstream privilege expansion, but continuity of authority does not establish the legitimacy of the authority at the origin.
Work on identity, credentials, trust registries, assurance and the institutional mechanisms that make claims actionable across organisational boundaries.
Membership is generated from controlled domain and topic rules, so future reviews appear automatically when their metadata matches this collection.
Provenance-bounded execution can prevent downstream privilege expansion, but continuity of authority does not establish the legitimacy of the authority at the origin.
A continuity model can prevent downstream authority manufacture, but a governable system still needs explicit rules for how legitimate authority is created, revoked, disputed, and restarted.
A public trust mark is recognition infrastructure whose legitimacy depends on the independence, revocability, and contestability of the accreditation and certification chain behind it.
An agent ID can make identity, provenance, and permission legible to a service, but it becomes governance infrastructure only when the authority behind those claims can be scoped, refreshed, revoked, contested, and independently trusted.
Split-knowledge identity can make an agent traceable without making its principal visible to business actors, but traceability becomes legitimate accountability only when tracing, revocation, delegated authority, and redress are independently governable.
Credential interoperability is not a property of shared formats alone: it exists only when verifiers can obtain the constitutional and logistical materials needed to decide what to trust, while retaining responsibility for the assumptions that make acceptance legitimate.
Cross-border digital identity interoperability fails when states can issue credentials but cannot export trust. The paper's central contribution is to relocate the binding constraint from protocols and enrollment infrastructure to assurance grammar, accreditation authority, trusted lists, and institutional capacity.
The paper's most consequential governance claim is that proprietary electronic bill of lading platforms have not solved the control problem but merely relocated it: authority over a trade document now depends on a commercial operator's continued existence, goodwill, and terms rather than on any independently verifiable cryptographic state. OpenETR's Three-Layer Model is architecturally correct in separating correctness, control, and recognition as distinct concerns, but the paper has not yet specified who governs the governance layer itself, how the attestation and trust-registry infrastructure will be built and held to account, or what enforcement and redress mechanisms will operate when cryptographic control and legal recognition conflict.
The paper frames self-sovereign identity as a strategic shift from institutional data accumulation to holder-mediated verification, but its governance model still depends on future trust registries, legal recognition, sectoral mandates, revocation controls, and redress institutions that are not yet operationalized.
Syntelos reframes trust as a runtime evaluation of attestations against policy, but leaves unresolved the governance of that policy layer, where real authority over system behavior resides.
The paper usefully formalizes privacy-preserving proof of personhood as a cryptographic problem, but its real governance challenge lies upstream of the proofs: who is allowed to issue personhood, what social relationships count, and how those judgments are revoked, contested, and made legible across institutions.
Digital identity succeeds not when a credential exists, but when governance, interoperability, trust, and everyday service relevance are engineered together as public infrastructure.
For agentic systems, governance must shift from persistent identity-based permission to action-bound, exhaustible authority that produces verifiable provenance at the moment an effect occurs.