Skip to content
ECZ-IDAgent

Time, state and evidence

An identity is also a question about when.

“What is this” is the easy half. The half that decides whether you can rely on the AI agent in front of you is what was true when you checked, what has changed since, and whether it is still the same logical entity — which is the one thing a record is built to keep steady.

Illustrative. This is the order in which things happen to a record of this kind, not anything that happened to anyone. There are no dates below because none of it has a date — a real record is your own, and starts with no bindings, no relationships and no evidence beyond its issue.

  1. When you create or claim it

    Public state after this step: active

    The identity exists, and the record says ACTIVE

    One Agent Passport is one logical AI agent operated by your organisation. It has one ECZ-ID from this moment, and that identifier does not change afterwards.

    Publishing the record is your decision. Nothing becomes public until you consent, and you can withdraw publication later.

    Included with the free Passport

  2. When you bind a representation

    Public state after this step: active

    A binding is added

    You record a public place where the same AI agent already appears — an agent card or manifest you publish. The record notes where the binding was learned, and the identity it belongs to is unchanged.

    The Passport identifies the AI agent. A binding records a public place it already appears. Adding a binding never creates a second identity.

    Included with the free Passport

  3. When a related identity changes

    Public state after this step: active

    A relationship is updated

    Agents call MCP servers for tools and data. The server is its own subject, with its own operator and its own Passport. When that identity changes, the link on your record is what updates — never the other entity's state, which belongs to its own operator.

    Included with the free Passport

  4. When authority changes in your systems

    Public state after this step: active

    An authority change is recorded

    Authority to act is granted, narrowed and withdrawn in your own systems. When you record that change against the identity, what the record gains is that it happened and when — the public record still publishes no delegated permission for anyone.

    A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act.

    Included with the free Passport

  5. When something decisive happens

    Public state after this step: active

    Evidence is recorded

    Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger. Essential LedgerCore evidence is kept for every identity, free ones included.

    An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true.

    Included with the free Passport

  6. When someone resolves it

    Public state after this step: active

    What was true when you checked

    On-demand and event-driven evaluation of your own entities. The state you are shown is the state as at your read — not a state something has been watching on your behalf since the step above.

    A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it.

    Free, and only when something asks

Identify, relate, revalidate, preserve.

Four parts, one record. Each line below is what the free Passport already gets from that part — not what the paid tiers above it add.

Agent Passport identifies
One Agent Passport is one logical AI agent operated by your organisation.
Digital Entity Graph and Graph Intelligence relates
Basic Graph participation and a current one-hop view.
PulseGuard detects and revalidates change
On-demand and event-driven evaluation of your own entities.
LedgerCore preserves enhanced evidence
Essential LedgerCore evidence is kept for every identity, free ones included.

What none of it changes

  • Every step above leaves the record ACTIVE. None of them is a change of identity.
  • Versions, deployments, replicas, regions and platforms of that agent are not separate Passports. None of them consumes AEC, and none of them becomes a second Passport.
  • Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC.

What a free Passport does not do

  • It includes no ongoing PulseGuard monitor. Nothing in the sequence happens on a schedule: state is evaluated when you ask for it, or when you raise an event.
  • Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month.
  • It reports state. It is not a safety verdict, and it never changes an identity or its tier.

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.