Delegations

Small keys, smaller permissions.

A device should receive only the narrow authority it needs, for a visible duration, under the current root epoch.

Authorization required

Activation ledger

What must be true first

Current root
Not authenticated
Scope registry
Read-only protocol design
Finality verification
Not connected

No operation attempted

No delegated authority was resolved.

No identity authority or exhaustive delegation projection is available to this browser. It cannot safely list, create, extend, or revoke delegated keys.

Scope

One job per delegation

Posting, profiles, social graph, communities, and moderation use distinct explicit scopes.

Least authority

Time

Authority has an end

Expiry and root-rotation epoch are checked at the exact position of every attempted action.

Fail closed

Revocation

A clean way back

A current root can revoke a delegation without relying on the delegated device.

Root-controlled