StableMindMachine Authority
Sign inStart with ActionGate

Live Authority Graph Explorer · Synthetic and browser-local

See where machine power came from.
And exactly where it stops.

Machine authority should not exist as a vague property attached to an agent. It should have an attributable source, a bounded path, conserved limits, a current validity state, and an inspectable relationship to every decision, permit, consequence reserve, execution, intervention, and proof artifact that follows.

Synthetic graph: every principal, agent, delegation, request, reserve, permit, execution, intervention, and evidence object below is fictional. The explorer runs entirely in your browser and creates zero machine authority.

CURRENT SYNTHETIC LINEAGE
CFO OFFICEdelegatesTREASURY AGENT
TREASURY AGENTattenuatesPAYMENT AGENT
Child limit$250K
BeneficiarySUPPLIER_42 / ••7744
DecisionPERMIT

Authority is not inferred from identity, credentials, organizational familiarity, or technical reach. The path must still be valid now.

One graph · Four deterministic states

Change one governing fact and watch the authority lineage re-resolve.

The explorer uses a fixed synthetic lineage. An accountable principal delegates payment authority to a Treasury Agent, which creates a narrower child delegation for a Payment Agent. The request then crosses ActionGate, consequence-capacity checks, permit issuance, bounded execution, Guardian posture, and Evidence. Change the request or lineage state and downstream eligibility changes with it.

RESOLUTIONPERMIT
LINEAGEVALID
PERMITELIGIBLE
CREDENTIALJIT AFTER PERMIT
Synthetic machine authority lineage graphAn accountable principal delegates authority through agents to an exact request. ActionGate evaluates the request before consequence capacity, Action Permit, execution, Guardian and Evidence stages. PRINCIPALCFO OfficeACTIVE DELEGATIONDLG-001VALID AGENTTreasuryBOUND CHILD GRANTDLG-002≤ $250K REQUEST$188K••7744 ACTIONGATEPERMITDETERMINISTIC CONSEQUENCE CAPITAL$188K LOCKEDSUFFICIENT ACTION PERMITAP-731ELIGIBLE EXECUTIONEX-009BOUNDED EVIDENCEEV-441VERIFIED GUARDIANOBSERVE
PRINCIPALCFO Office

The accountable synthetic principal is the origin of this lineage. Its presence does not authorize an action by itself; the authority must travel through explicit current delegation.

Object
principal://cfo-office
Authority effect
0 · synthetic explorer
Network calls
0

What the graph proves

A graph is useful only if the edges have constitutional meaning.

StableMind does not treat an authority graph as a picture of who is connected to whom. Each edge must describe a governed relationship that can be evaluated at decision time. A reachable node is not necessarily an authorized node, and a historical delegation is not necessarily a current delegation.

01

Origin is attributable

Machine authority begins with an accountable grantor or governed institutional source. The graph preserves who delegated power, to whom, for what purpose, over which resources, destinations, limits, validity period, and inherited conditions.

02

Children only attenuate

A child grant may preserve or narrow parent authority. It cannot expand action scope, amount, destination, time, consequence capacity, recursive depth, or inherited denial conditions. Shared budgets are conserved rather than duplicated across descendants.

03

Current state matters

Revocation, expiry, quarantine, signature failure, lifecycle supersession, or a missing ancestor can invalidate descendants. StableMind therefore resolves the current chain, not merely the existence of a historical edge in a database.

04

Lineage is not a permit

A valid graph is still only an input to ActionGate. It does not issue credentials, execute actions, reserve consequence capacity, or create Proof of Consequence. Exact authorization happens against the semantic request.

Four graph states

The same lineage can resolve differently when one governing fact changes.

These synthetic states deliberately mirror the four ActionGate outcomes. They are teaching states, not claims about a customer deployment.

01

PERMIT · Valid lineage

The request is $188,000 to the beneficiary ending 7744. The child grant allows up to $250,000 to that exact destination, the ancestor is current, and sufficient synthetic consequence capacity is available. A bounded permit can become eligible.

02

NARROW · Exceeds child scope

The request rises to $428,000 while the current child delegation remains capped at $250,000. The parent may have more capacity, but the child cannot silently borrow it. ActionGate narrows the allowed action to the current child boundary.

03

HUMAN_AUTHORITY · Changed target

The amount returns to $188,000, but the beneficiary changes from ending 7744 to ending 9138. The agent, credential, and supplier label may remain familiar; the current lineage no longer proves authority for that destination, so fresh human authority is required.

04

DENY · Revoked ancestor

The CFO Office revokes DLG-001. DLG-002 cannot remain independently alive beneath a dead ancestor. The descendant lineage becomes invalid, no Action Permit is eligible, and downstream technical capability stays inert.

The objects inside machine authority

AUTHORITY IS A LINEAGE, NOT A BOOLEAN

What belongs in an inspectable authority graph?

PRINCIPALS

Accountable sources of delegated power

Human principals, governed organizations, trusteeship structures, or other authorized sources anchor why a machine possesses bounded power in the first place.

AGENTS

Machine actors with identity but not inherent power

Agent identity lets the graph attribute an actor. It does not grant permission. The same authenticated agent may have different authority under different current delegations.

DELEGATIONS

Purpose, scope, limits, validity, inheritance

Delegation objects carry the machine-evaluable boundaries that ActionGate can later compare with an exact semantic request.

CONSEQUENCE CAPACITY

Power cannot outrun absorbable consequence

Where required, the graph can show bounded consequence capacity associated with a lineage while keeping reserve coverage constitutionally distinct from permission.

PERMITS & EXECUTION

Exact downstream artifacts, not inherited privileges

Action Permits bind a decision to a narrow action and time window. Execution Fabric then materializes only the capability that exact permit requires.

REVOCATION & EVIDENCE

Power can disappear while lineage remains attributable

Revocation must propagate through dependent authority, and every revocation dependency should remain inspectable. Evidence preserves what was requested, decided, permitted, executed, interrupted, and independently observed afterward.

Public Truth boundary

This graph is alive in the interface. It is not alive in a customer environment.

The explorer intentionally resembles a product control plane because machine authority is easier to understand when relationships can be inspected. But the data is embedded synthetic teaching data. Selecting a scenario or node changes only local presentation state.

Identity createdNO
Delegation created or revokedNO
Action Permit issuedNO
Credential releasedNO
Consequence reserve changedNO
Downstream executionNO
External Proof of ConsequenceNO
Network calls0

Authority graph FAQ

INSPECT THE RELATIONSHIP, NOT JUST THE NODE

What an enterprise should mean when it says “authority graph.”

01

Is an authority graph the same as an identity graph?

No. Identity graphs answer valuable questions about principals, workloads, groups, roles, credentials, and relationships. An authority graph adds a different question: which consequential power was explicitly delegated, through which current lineage, for which purpose and scope, under which constraints, and with what revocation dependencies? StableMind uses identity as evidence about the actor while keeping permission to create consequence separately governed.

02

Does a valid path mean the action is authorized?

No. A current delegation path establishes authority context that ActionGate can evaluate against an exact semantic request. The request may still exceed amount, destination, resource, time, approval, consequence-capacity, or other boundaries. That is why the graph continues through the decision rather than ending at the agent node. A valid lineage can coexist with NARROW, HUMAN_AUTHORITY, or DENY for a particular request.

03

Why show Action Permits and execution in the same graph?

Because downstream artifacts should remain attributable to the authority that justified them without being confused with that authority. An Action Permit should point back to the request, decision, and current delegation context that made it eligible. Execution and evidence can then preserve a lineage forward. This lets reviewers inspect an end-to-end chain without pretending that a permit, credential, receipt, or successful execution retroactively creates permission.

04

What makes revocation graph-native?

Revocation is not simply a red label on one node. If a descendant depends on a revoked ancestor, the dependent path must become invalid according to explicit inheritance rules. Technical capability that still exists downstream should not keep the authority alive. Guardian may help contain residual capability, while ActionGate and Execution Fabric continue to fail closed on invalid current lineage.

05

How should multiple grants behave?

StableMind does not assume that two narrow grants automatically combine into one broad grant. Composition can create surprising authority, especially when one grant supplies destination scope and another supplies economic capacity. Unless a governed composition rule explicitly permits that union, independent grants remain independent. The graph therefore needs enough semantics to show why a path exists, not merely that two nodes are connected.

06

What does the public explorer prove about StableMind production?

It proves only that StableMind.io can explain the architecture through a deterministic browser-local teaching model. It does not prove a named customer deployment, live authority lineage, production revocation, governed transaction, external Proof of Consequence, realized savings, revenue, or customer outcome. StableMind's Public Truth contract deliberately prevents an interactive interface from promoting synthetic demonstration into external production evidence.

For architects, security teams, and investors

Questions a real authority graph should answer without hand-waving.

01

Can you name the grantor?

Every consequential machine action should be traceable to a current, attributable source of authority rather than a role name or standing credential.

02

Can a child ever become broader?

If recursive delegation exists, attenuation must be enforced across every dimension that matters, including shared budgets and inherited conditions.

03

What happens when an ancestor dies?

Revocation and expiry should invalidate dependent authority quickly and predictably, without trusting descendant agents to voluntarily surrender technical capability.

04

Can two grants silently combine?

Independent grants should not be unioned into accidental super-authority unless a governed composition rule explicitly permits it.

05

Can you distinguish authority from capability?

A vault token, API reach, administrator role, service account, or successful connector test is technical capability. None of those facts should create machine authority.

06

Can you prove the path afterward?

Decision and evidence systems should preserve enough attributable lineage to reconstruct why an action was permitted, narrowed, human-routed, denied, executed, interrupted, or left unexecuted.

Continue the lineage

Follow authority into evidence.

The Proof Explorer continues the inspectable lineage into request hashes, Action Permit, execution receipt, independent verifier observation, and final Proof of Consequence.