Time, state and evidence
An identity is also a question about when.
“What is this” is the easy half. The half that decides whether you can rely on the AI agent in front of you is what was true when you checked, what has changed since, and whether it is still the same logical entity — which is the one thing a record is built to keep steady.
Illustrative. This is the order in which things happen to a record of this kind, not anything that happened to anyone. There are no dates below because none of it has a date — a real record is your own, and starts with no bindings, no relationships and no evidence beyond its issue.
When you create or claim it
Public state after this step: active
The identity exists, and the record says ACTIVE
One Agent Passport is one logical AI agent operated by your organisation. It has one ECZ-ID from this moment, and that identifier does not change afterwards.
Publishing the record is your decision. Nothing becomes public until you consent, and you can withdraw publication later.
Included with the free Passport
When you bind a representation
Public state after this step: active
A binding is added
You record a public place where the same AI agent already appears — an agent card or manifest you publish. The record notes where the binding was learned, and the identity it belongs to is unchanged.
The Passport identifies the AI agent. A binding records a public place it already appears. Adding a binding never creates a second identity.
Included with the free Passport
When a related identity changes
Public state after this step: active
A relationship is updated
Agents call MCP servers for tools and data. The server is its own subject, with its own operator and its own Passport. When that identity changes, the link on your record is what updates — never the other entity's state, which belongs to its own operator.
Included with the free Passport
When authority changes in your systems
Public state after this step: active
An authority change is recorded
Authority to act is granted, narrowed and withdrawn in your own systems. When you record that change against the identity, what the record gains is that it happened and when — the public record still publishes no delegated permission for anyone.
A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act.
Included with the free Passport
When something decisive happens
Public state after this step: active
Evidence is recorded
Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger. Essential LedgerCore evidence is kept for every identity, free ones included.
An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true.
Included with the free Passport
When someone resolves it
Public state after this step: active
What was true when you checked
On-demand and event-driven evaluation of your own entities. The state you are shown is the state as at your read — not a state something has been watching on your behalf since the step above.
A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it.
Free, and only when something asks
Identify, relate, revalidate, preserve.
Four parts, one record. Each line below is what the free Passport already gets from that part — not what the paid tiers above it add.
- Agent Passport identifies
- One Agent Passport is one logical AI agent operated by your organisation.
- Digital Entity Graph and Graph Intelligence relates
- Basic Graph participation and a current one-hop view.
- PulseGuard detects and revalidates change
- On-demand and event-driven evaluation of your own entities.
- LedgerCore preserves enhanced evidence
- Essential LedgerCore evidence is kept for every identity, free ones included.
What none of it changes
- Every step above leaves the record ACTIVE. None of them is a change of identity.
- Versions, deployments, replicas, regions and platforms of that agent are not separate Passports. None of them consumes AEC, and none of them becomes a second Passport.
- Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC.
What a free Passport does not do
- It includes no ongoing PulseGuard monitor. Nothing in the sequence happens on a schedule: state is evaluated when you ask for it, or when you raise an event.
- Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month.
- It reports state. It is not a safety verdict, and it never changes an identity or its tier.
Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.
