StableMindMachine Authority
Sign inStart with ActionGate
StableMind/Standards/SM-MAS-1.0

Machine Authority Standard Center · Development standard

A standard for machine power.
Not a shortcut to permission.

SM-MAS-1.0 defines a portable set of non-waivable requirements for consequential machine action: where authority originates, how it contracts, how an exact permit is issued, how credentials arrive only after permission, how consequence capacity is conserved, how action is bounded, and how resulting consequence is independently evidenced.

Status: DEVELOPMENT_STANDARD_1_0. StableMind is publishing its own development standard and implementation artifacts. This page does not claim external standards-body adoption, regulator endorsement, independent accreditation, third-party certification, or production proof.

Definition

What is a machine authority standard?

A machine authority standard specifies the minimum control semantics required before a machine may exercise consequential power and the evidence required after that power is exercised. In SM-MAS-1.0, authentication, credentials, framework membership, reputation, network consensus, compliance status, insurance, or a passing conformance test never substitutes for tenant-local delegated authority and deterministic authorization. The standard describes interoperability and safety invariants. It does not issue permission.

Non-collapsible rule

Conformance is not authority. Certification is not permission.

A conforming implementation may still have no authority to perform a particular action. Every consequential request must traverse the current local authority chain at the moment of action.

Mandatory execution chain

Eleven boundaries. No semantic teleportation.

SM-MAS-1.0 keeps authority, permission, technical capability, execution, evidence, and settlement separate. An implementation cannot skip a boundary merely because an adjacent system is trusted.

Read the Machine Authority thesis
  1. 01delegated authority
  2. 02semantic action request
  3. 03deterministic policy decision
  4. 04exact short-lived Action Permit
  5. 05consequence reserve lock
  6. 06just-in-time credential resolution
  7. 07certified execution boundary
  8. 08verified execution receipt
  9. 09tamper-evident evidence
  10. 10independent Proof of Consequence
  11. 11consequence settlement

Conformance profiles

Profiles compose controls. They do not shop for weaker safety.

Six profiles make implementation evaluation tractable while preserving inherited requirements. The Full Standard composes all 36 clauses. Passing a profile demonstrates only the tested technical conformance state.

16 effective · 16 added

Core Machine Authority

Foundational profile with no parent dependency. Requirements remain non-waivable; this profile cannot grant action authority.

24 effective · 08 added

Consequence Capital

Composes core authority. Requirements remain non-waivable; this profile cannot grant action authority.

29 effective · 05 added

Cross-Enterprise Authority

Composes core authority, consequence capital. Requirements remain non-waivable; this profile cannot grant action authority.

10 effective · 10 added

Evidence and Assurance

Foundational profile with no parent dependency. Requirements remain non-waivable; this profile cannot grant action authority.

07 effective · 07 added

Reference Verifier

Foundational profile with no parent dependency. Requirements remain non-waivable; this profile cannot grant action authority.

36 effective · 36 added

Full Machine Authority Standard 1.0

Composes core authority, consequence capital, cross enterprise, evidence assurance, reference verifier. Requirements remain non-waivable; this profile cannot grant action authority.

Portable artifacts

Read the prose. Inspect the bytes.

The public center exposes the signed machine-readable standard, profile definitions, reference vectors, adversarial vectors, and isolated Authority Lab scenarios included in this engineering release. These artifacts are for inspection and implementation evaluation; they do not constitute external accreditation or production evidence.

How to read SM-MAS-1.0

Conformance describes an implementation. Authority describes an action.

SM-MAS-1.0 deliberately separates a system's conformance state from an actor's current authority. A conformance result answers whether an implementation satisfies a defined profile and its required deterministic tests. It can demonstrate, for example, that the implementation preserves attenuation during delegation, rejects stale or replayed permits, keeps standing credentials away from agents, conserves consequence reserve, or requires independent evidence before a consequence can be called verified. That technical result matters because it gives buyers, implementers, auditors, and integrators a common vocabulary for evaluating the control plane.

But SM-MAS-1.0 conformance never answers the separate institutional question: may this machine perform this exact action now? That question belongs to current delegated authority, current local policy, the exact semantic request, consequence conditions, and the resulting ActionGate decision. A system can conform perfectly to SM-MAS-1.0 while correctly refusing every action presented to it. Conversely, an interface badge, certification record, implementation profile, or successful conformance vector cannot fill in missing authority. This separation is intentional because a technical standard that could manufacture permission would become another ambient source of machine power.

The six SM-MAS-1.0 profiles are therefore evaluation lenses rather than permission tiers. Core Machine Authority concentrates on the authority, credential, execution, evidence, delegation, revocation, and eligibility fundamentals. Consequence Capital adds reserve and non-fungible consequence requirements. Cross-Enterprise Authority adds bilateral acceptance, isolation, trust, network, and contract boundaries. Evidence and Assurance emphasizes attributable artifacts and independent verification. Reference Verifier focuses on portable artifacts, version integrity, extensions, conformance, production truth, and fail-closed behavior. Full Machine Authority Standard 1.0 composes all 36 requirements. No profile is allowed to weaken what it inherits, and no profile carries greater action authority merely because it contains more controls.

Implementation evaluation

Test the seams, not just the happy path.

An SM-MAS-1.0 conformance evaluation should examine the boundaries where machine-control systems tend to collapse concepts together. Can an authenticated agent reach a credential before an Action Permit exists? Can a child delegation become broader than its parent? Can two independent authority paths be silently unioned? Can a favorable model forecast waive consequence reserve? Can an executor certify its own consequence? Can a recovery flow rewrite evidence, release reserve, or resurrect stale authority? Can a network reputation score, insurer decision, regulatory recognition, or conformance badge substitute for local delegated authority? Each of those shortcuts is explicitly hostile to the standard's purpose.

The reference and adversarial vectors published with SM-MAS-1.0 are designed to make those seams inspectable. Thirty-six normative reference vectors cover the requirements directly, while twelve adversarial vectors exercise expected refusals and integrity boundaries. The separate isolated Authority Lab scenarios provide synthetic teaching and implementation-evaluation cases. Passing those artifacts can support a technical conformance claim only to the exact tested scope. It does not establish customer deployment, live governed execution, independent production evidence, external certification, or realized value.

Version handling is also part of conformance. SM-MAS-1.0 treats signed, versioned, digest-bound artifacts as a control surface, not packaging trivia. A verifier should reject stale artifact replay, schema substitution, semantic substitution, or version downgrade when any of those changes could weaken a requirement. Extensions may add vendor- or domain-specific behavior, but they may not override or omit a mandatory safety clause. That creates a deliberately asymmetric compatibility rule: implementations can become richer, but they cannot call themselves conforming by quietly becoming weaker.

For procurement and architecture review, the most useful question is therefore not merely “does this product support SM-MAS-1.0?” A serious evaluation should ask which profile is being claimed, which exact version and digest were evaluated, which reference and adversarial vectors were run, what local extensions are present, whether any mandatory requirement is conditionally disabled, how verifier independence is established, and whether the implementation can demonstrate fail-closed behavior when authority, evidence, consequence definitions, or version lineage become uncertain. Conformance should make those questions easier to answer, not replace them with a badge.

Standard scope

SM-MAS-1.0 standardizes control semantics, not institutional judgment.

SM-MAS-1.0 does not attempt to decide what every enterprise should permit, which financial limit is appropriate, what a regulator should require, how much human review a workflow deserves, whether a supplier is trustworthy, or which business outcome is desirable. Those are local institutional decisions. The standard instead defines the machinery required to keep those decisions explicit, attributable, bounded, revocable, and independently inspectable when a machine is capable of creating consequence.

This is also why the Machine Authority Standard Center keeps StableMind's product architecture separate from the standard itself. Authority Cloud, ActionGate, Execution Fabric, Guardian, Evidence, Consequence Capital, and other StableMind components are implementations and product surfaces that can embody the SM-MAS-1.0 control model. They are not permitted to redefine conformance around whatever the product happens to do. The normative artifacts remain separately inspectable, and a conforming third-party implementation would still need its own current tenant-local authority and policy decisions before acting.

Normative requirements

The 36 clauses of SM-MAS-1.0

MUST and MUST NOT are normative. Every requirement below is non-waivable, cannot be weakened by an extension, and remains subordinate to exact tenant-local authority at action time.

VISIBLE36of 36
Showing all requirements

Authority

5 normative requirements

MAS-AUTH-001MUST

Every machine action is grounded in explicit delegated authority.

Non-waivableTest: TV-AUTH-001
MAS-AUTH-002MUST

Every request binds the exact tenant, organization, agent, subject, action, arguments, target, purpose, policy, connector, reserve, and validity window.

Non-waivableTest: TV-AUTH-002
MAS-AUTH-003MUST

A deterministic tenant-local policy decision precedes every Action Permit.

Non-waivableTest: TV-AUTH-003
MAS-AUTH-004MUST

An Action Permit is exact, signed, short-lived, single-use, and independently enforceable.

Non-waivableTest: TV-AUTH-004
MAS-AUTH-005MUST NOT

Authentication, identity, consent, framework labels, network membership, reputation, or consensus substitute for action authority.

Non-waivableTest: TV-AUTH-005

Credentials

2 normative requirements

MAS-CRED-001MUST NOT

Agents possess standing downstream credentials.

Non-waivableTest: TV-CRED-001
MAS-CRED-002MUST

Credentials are resolved only after exact authority validation and delivered once to a certified execution boundary.

Non-waivableTest: TV-CRED-002

Execution

2 normative requirements

MAS-EXEC-001MUST

Execution occurs inside a certified boundary that cannot widen the permit.

Non-waivableTest: TV-EXEC-001
MAS-EXEC-002MUST

Execution produces a verified receipt bound to the permit and observed target state.

Non-waivableTest: TV-EXEC-002

Evidence

3 normative requirements

MAS-EVID-001MUST

Evidence is tamper-evident, lineage-preserving, portable, and independently verifiable.

Non-waivableTest: TV-EVID-001
MAS-EVID-002MUST

Proof of Consequence is independent of connector success and records what changed and what did not.

Non-waivableTest: TV-EVID-002
MAS-EVID-003MUST

Post-action consequence settlement remains open until independent evidence satisfies every obligation.

Non-waivableTest: TV-EVID-003

Delegation

2 normative requirements

MAS-DELG-001MUST

Authority contracts as it descends and cannot be duplicated.

Non-waivableTest: TV-DELG-001
MAS-DELG-002MUST NOT

Multi-agent, multi-path, cross-tenant, or cross-enterprise authority is silently unioned.

Non-waivableTest: TV-DELG-002

Revocation

1 normative requirement

MAS-REVK-001MUST

Revocation propagates to every dependent permit, credential lease, route, contract, and recovery obligation.

Non-waivableTest: TV-REVK-001

Eligibility

1 normative requirement

MAS-ELIG-001MUST

Lifecycle, drift, memory provenance, delegation, sandbox, fiduciary, coherence, resource, threat, self-modification, and Guardian state affect execution eligibility.

Non-waivableTest: TV-ELIG-001

Consequence

5 normative requirements

MAS-CONS-001MUST

Consequences use signed, versioned, tenant-local ontology definitions with explicit dimensions and units.

Non-waivableTest: TV-CONS-001
MAS-CONS-002MUST

No machine creates an unreserved consequence.

Non-waivableTest: TV-CONS-002
MAS-CONS-003MUST

Consequence reserve is locked before action and conserved through delegation, execution, recovery, and settlement.

Non-waivableTest: TV-CONS-003
MAS-CONS-004MUST

Unknown, undefined, incomparable, or unbounded consequence freezes or escalates authority.

Non-waivableTest: TV-CONS-004
MAS-CONS-005MUST

Financial, human, legal, operational, data, security, environmental, resource, contractual, and irreversibility ceilings remain dimension-specific.

Non-waivableTest: TV-CONS-005

Prediction

1 normative requirement

MAS-TWIN-001MUST NOT

A favorable simulation, forecast, confidence score, or modeled safety result grants authority.

Non-waivableTest: TV-TWIN-001

Recovery

1 normative requirement

MAS-RECV-001MUST NOT

Recovery erases consequence, rewrites evidence, or releases reserve without independent proof.

Non-waivableTest: TV-RECV-001

Compensation

1 normative requirement

MAS-COMP-001MUST NOT

Compensation purchases permission, waives non-fungible human consequence, or extinguishes unresolved duty.

Non-waivableTest: TV-COMP-001

Cross-enterprise

1 normative requirement

MAS-XENT-001MUST

Cross-enterprise authority requires a signed offer, independent recipient-local acceptance, and an exact conserved intersection.

Non-waivableTest: TV-XENT-001

Contracts

1 normative requirement

MAS-CNTR-001MUST NOT

A machine contract creates authority, issues a permit, transfers credentials, or erases fiduciary duty.

Non-waivableTest: TV-CNTR-001

Trust & assurance

1 normative requirement

MAS-TRST-001MUST NOT

Assurance, insurance, regulatory recognition, coverage, or claims replace authority, reserve, liability, or Proof of Consequence.

Non-waivableTest: TV-TRST-001

Network

1 normative requirement

MAS-NETW-001MUST NOT

Network discovery, routing, membership, consensus, or reputation creates authority or unions authority paths.

Non-waivableTest: TV-NETW-001

Isolation

1 normative requirement

MAS-ISOL-001MUST

Tenant, organization, subject, jurisdiction, policy, evidence, and reserve boundaries remain isolated unless exact bilateral acceptance proves otherwise.

Non-waivableTest: TV-ISOL-001

Normative artifacts

1 normative requirement

MAS-ARTF-001MUST

Normative artifacts are signed, versioned, digest-bound, replay-resistant, and portable for offline verification.

Non-waivableTest: TV-ARTF-001

Versioning

1 normative requirement

MAS-DOWN-001MUST NOT

Version downgrade, schema substitution, semantic substitution, or stale artifact replay weakens a requirement.

Non-waivableTest: TV-DOWN-001

Extensions

1 normative requirement

MAS-EXTN-001MUST NOT

An extension, profile, vendor option, or local policy weakens or omits a mandatory safety requirement.

Non-waivableTest: TV-EXTN-001

Conformance

1 normative requirement

MAS-CONF-001MUST NOT

Conformance, certification, accreditation, or a passing test grants action authority or constitutes permission.

Non-waivableTest: TV-CONF-001

Production truth

2 normative requirements

MAS-PROD-001MUST NOT

Synthetic completeness, internal test success, or self-attestation is represented as production proof.

Non-waivableTest: TV-PROD-001
MAS-PROD-002MUST

Production claims remain blocked until all eighteen external Production Truth proofs are independently demonstrated.

Non-waivableTest: TV-PROD-002

Fail closed

1 normative requirement

MAS-FAIL-001MUST

Implementations fail closed, preserve historical regression boundaries, and never weaken controls to satisfy obsolete fixtures.

Non-waivableTest: TV-FAIL-001

Conformance boundary

A passing implementation still needs authority.

Conformance establishes that an implementation satisfies a defined technical profile against specified vectors. It does not establish that a customer delegated authority, that a policy permits an action, that consequence reserve exists, that a credential may be released, that an execution occurred, or that a consequence was independently proven.

CONFORMANCETechnical semantics

Can the implementation satisfy the required controls and deterministic vectors?

AUTHORITYCurrent local power

Did an accountable principal explicitly delegate this exact bounded power?

PERMISSIONActionGate decision

Does current policy permit this exact semantic request now?

PROOFPost-action evidence

What consequence can an independent verifier actually support afterward?

Publication truth

What StableMind is claiming. And what it is not.

PUBLISHED HERE

Development standard + artifacts

SM-MAS-1.0, its profiles, requirements, vectors, and package-local implementation materials are available for public inspection in this build.

NOT CLAIMED

External standards adoption

No claim is made that SM-MAS-1.0 has been adopted by ISO, NIST, IETF, W3C, regulators, industry consortia, customers, or any other external standards authority.

NOT CLAIMED

Independent accreditation

StableMind does not claim an externally accredited conformance laboratory, independent certification body, or third-party credential authority from this website release.

NOT CLAIMED

Production proof

Passing vectors, synthetic scenarios, conformance badges, or publication status do not prove live governed production actions or realized customer outcomes.

From standard to governed action

Standards describe the boundary.
ActionGate enforces it.

Start with the flagship decision plane, inspect delegated authority, or open a synthetic proof package to see how these normative boundaries appear in product form.