TrustCarry Protocol v0.3 Author-Affirmed Research Claims

Public, author-affirmed research propositions distilled from an unpublished draft. Distinct from the 5,033 published-source scholarly claims.
  1. Continuity, competence, trust, and authority are separate institutional questions that require distinct protocol objects, decision owners, and failure rules.
  2. Reputation continuity is a transaction-cost, credible-commitment, and monitoring problem before it is an engineering problem.
  3. Persona Protocol represents reputation as a contextual projection over provenance-bearing evidence, preserves adverse lifecycle states, permits selective principal disclosure, and treats authority as an explicit, scoped, revocable grant that fails closed.
  4. Persona Protocol proposes a minimum separation of trust functions for autonomous actors that may be persistent without public identification, competent without authorization, and trusted for one decision without being trusted for all decisions.
  5. Continuity, competence, trust, and authority are four institutional determinations with four different owners, not four formulations of one identity question.
  6. An identifier-key binding does not determine legitimate reputation inheritance, a credential does not determine cross-domain weight, a reputation score does not create present authority, and an authority grant does not establish competence.
  7. Collapsing identity, reputation, trust, and authority into one score or token hides institutional judgment inside a scoring rule and ownership record rather than eliminating it.
  8. Persona Protocol is a continuity and evidence architecture, not a universal identity system, final reputation algorithm, or authority provider.
  9. Portable trust continuity is legitimate only when every contribution traces to evidence, validation, governance, context, challenge state, and time.
  10. Cross-organizational autonomous-agent transactions face screening, verification, and credible-commitment costs that can force counterparties to absorb risk, reject external agents, or require human guarantors.
  11. A reputation history can substitute for a bond only if it attaches to a subject that cannot costlessly shed it, is interpretable in the present domain, and is contestable and inspectable.
  12. The institutional deficit in agent trust concerns the governed objects that signatures carry, not the availability of cryptographic signatures themselves.
  13. Eliminating psychological guile does not eliminate objective misalignment: a faithfully optimizing agent can impose counterparty losses without deception, and verifiability alone does not determine whether to transact.
  14. When generative output is abundant but validation capacity remains scarce, allocating validation attention across abundant claimants becomes more important rather than less.
  15. Control of a current key does not establish the truth of a signed claim, supply a legitimate reputation function, or determine whether a material system change preserves the accountable subject.
  16. Persona Protocol composes with identity and credential standards but adds the distinct object of governed continuity for a reputation-bearing history.
  17. Reputation should be represented as an evidence set, expertise graph, validation record, and purpose-bound projection rather than as a universal score.
  18. Trust may inform risk, but only an authorized issuer can create authority; reputation may satisfy a grant condition but cannot substitute for or enlarge the grant.
  19. A system that converts reputation directly into authority gives the author of the projection rule control over the action allocation.
  20. Operational telemetry can become evidence, but task counts, uptime, registrations, messages, executions, and state transitions are not reputation merely because they exist.
  21. Externally eligible reputation requires an intervening governed admission decision recorded in an evidence event that identifies artifact, context, mode, taxonomy, validator set, governance rule, outcome, time, and content commitment.
  22. Synthetic fixtures, operator canaries, directory listings, and repeated raw observations do not become externally eligible reputation without governed validation.
  23. Persona Protocol does not eliminate Sybil corruption; its narrower claim is to make the cost of corruption legible.
  24. Persona Protocol versions and publishes projection profiles and permits competing profiles over a shared evidence commitment so that scoring rules remain revisable.
  25. Persona Protocol supplies portability and continuity but does not itself supply calibrated slashing, robust Sybil resistance, or maintained human oversight.
  26. A Persona is a persistent protocol subject that accumulates a continuity-bound evidence history and need not correspond to a human, model, runtime, wallet, organization, or public principal.
  27. A Persona may survive governed rotation, migration, recovery, or declared upgrades, but material changes must produce a continuity event, fork, or new Persona, and principal disclosure remains policy-dependent.
  28. Persona evaluation uses four sequential, fail-closed gates, and a later gate cannot satisfy an earlier gate.
  29. An unverifiable continuity link terminates reputation inheritance at that point, so evidence earned before the unverifiable transition does not transfer forward.
  30. Evidence sufficiency is evaluated within the relevant domain, mode, and time window, and coverage must be read before any aggregate.
  31. A contextual projection and its uncertainty are inputs to a risk decision, not the decision itself.
  32. Authority must be verified independently of continuity, evidence sufficiency, and trust projection, with denial unless every required grant element verifies.
  33. Evidence events are immutable, signed, content-addressed, and append-only; corrections supersede rather than erase, and adverse lifecycle states remain in history.
  34. Validator independence must be demonstrated through disclosed operators, datasets, incentives, and governance structures rather than inferred from distinct validator names.
  35. Projection profiles must disclose whether consensus strength affects evidence weight and may use loosely coupled admission for contested categories to avoid suppressing minority evaluation.
  36. The founding validator assumption must be recorded with its governance basis so relying parties can discount the subtree that descends from it.
  37. Multiple admission systems may export a common minimum receipt while retaining their local rules.
  38. Expertise is represented through a versioned directed graph in which historical evidence retains its original tag and taxonomy version, and later mappings cannot rewrite source events.
  39. Graph adjacency does not prove competence transfer, local stages do not create universal rank, and cross-system comparison requires a declared, fallible crosswalk.
  40. A derivation edge is evidence about both contributing Personas, and its dispute path must be declared in advance.
  41. Agent Reputation Identity is a versioned contextual projection over a committed evidence set, not a universal identity.
  42. A conforming projection discloses its filters, taxonomy mapping, validator and outcome treatment, decay, uncertainty, weights, aggregation, eligibility, rounding, expertise vector, and coverage.
  43. Evidence commitments should be portable across competing projection profiles because a single canonical scoring rule gives its controller unrecorded allocative authority.
  44. Projection-profile authorship belongs with the evaluated domain rather than with a central specification body.
  45. The reference projection formula is an uncalibrated engineering demonstration and must not be treated as a validated production measure.
  46. Missing evidence is null rather than zero; below a declared domain coverage threshold, a projection reports coverage and uncertainty without an aggregate.
  47. Governed continuity and explicit coverage relocate the newcomer penalty into a legible, domain-scoped cost that can be discharged through evidence, but they do not abolish entry cost.
  48. Every continuity event links to its predecessor and identifies the governance policy in force before the transition.
  49. Key transfer alone does not transfer reputation; forks require allocation rules, mergers cannot silently sum scores, and recovery cannot erase a compromised interval.
  50. Persona Protocol cannot prevent out-of-band control sales, but observable changes in keys, verification methods, or governing principals must produce continuity events that relying parties can use to discount inherited evidence.
  51. Trust relationships require typed, directed, scoped, sourced, and time-bounded edges because scalar representations destroy relationship information.
  52. Validation, collaboration, membership, recognition, and authority are distinct relations, and circular graph paths do not establish independent support.
  53. Trust-graph algorithms must disclose path rules, cycle treatment, correlation assumptions, and centrality effects because a trust graph is a provenance structure before it is a scoring structure.
  54. Authority grants must identify issuer, subject, action, resource, constraints, time, delegation depth, revocation, policy, and proof; child grants may preserve or narrow but never enlarge scope.
  55. Authority evaluation denies by default when required grant elements cannot be verified, and a reputation projection may be a grant condition but cannot become the grant.
  56. Public Persona data should be minimal, with principal identity, raw artifacts, model internals, customer data, validator deliberations, recovery contacts, and protected attributes restricted by default.
  57. A Persona record should be owned by its subject rather than its host, while append-only integrity should be reconciled with privacy through tombstones, encryption, restricted stores, and selective disclosure.
  58. Continuity reduces whitewashing while creating persistent linkage risk, so the protocol manages rather than resolves the tension between accountability and privacy.
  59. Integration with MCP, A2A, credentials, attestations, and authority tokens does not change their evidentiary meaning: discovery is not competence, attestation is bounded by appraisal policy, credentials remain issuer claims, and authority remains issuer- and scope-bounded.
  60. Persona Protocol makes the reputation-bearing subject non-transferable by default and requires declared, visible continuity events for transitions, allowing relying parties to discount pre-transition evidence.
  61. Persona Protocol offers a provisional constructive separation of functions that adjacent standards can implement, transport, or reference, without asserting a completed novelty review.
  62. Passing the reference implementation's synthetic tests does not establish external validation, security, production readiness, calibrated projections, or independent interoperability.
  63. The separation thesis is falsified if deployed systems routinely collapse the four gates into one score without reducing decision quality.
  64. The non-transferability thesis is falsified if governed transfer with full disclosure produces the same downstream error rates as non-transferability.
  65. The coverage thesis is falsified if suppressing aggregates below a coverage threshold produces worse relying-party outcomes than reporting a baseline.
  66. The competing-profiles thesis is falsified if plural profiles over a shared evidence commitment converge to a de facto canonical rule in ordinary use.
  67. Persona Protocol supplies an auditability condition for reputation governance but does not supply the metric-quality condition required for reliable outcomes.
  68. Protocol governance must separate specification stewardship, evidence adjudication, and local authority; changes require documented analysis, and emergency powers must be narrow, temporary, logged, and reviewed.
  69. A stable protocol release requires an open conformance suite and at least two independent interoperable implementations; no vendor implementation is itself the standard.
  70. Projection profiles should be openly published and selected locally by relying parties because a specification body that controls both evidence schema and canonical scoring holds unrecorded allocative power.
  71. Reputation governance must be revisable on the timescale of exploitation and able to ingest evidence of its own gaming.
  72. Persona Protocol's principal threat model includes seizure, whitewashing, reputation purchase, synthetic-evidence laundering, collusion, bootstrap capture, replay, graph rings, taxonomy gaming, projection manipulation, authority escalation, deanonymization, stale projections, and governance capture.
  73. Persona Protocol does not claim to solve its threat model; implementations must identify the control, residual risk, and decision boundary for each threat.
  74. The Trust Capital hypothesis predicts that sustained, independently validated, portable reputation may reduce transactional uncertainty and lower contracting costs across organizational boundaries.
  75. Trust Capital is capital in an institutional sense rather than a balance-sheet sense.
  76. Testing Trust Capital requires causal evidence linking defined reputation histories to transaction terms, collateral, loss, selection, or authority decisions; until then it remains a hypothesis rather than an asset or price.
  77. A protocol can preserve evidence of a reputation decision but cannot by itself supply the decision's lawfulness or legitimacy.
Machine access