CONFIDENTIAL AUTHORITY LAYER

Persistent private authority for autonomous agents.

Attach a confidential operating mandate to an autonomous runtime. Update authority without replacing the agent. Keep every consequential action inside a proposal-bound, versioned perimeter.

Built natively with COTI
  • Confidential state & computation
  • Private messaging for coordination
  • Private assets & consequences

Persistent

Mandates survive restarts, upgrades, and runtime replacement.

Private

Sensitive thresholds remain encrypted and access-controlled.

Versioned

Every authority change creates an immutable audit point.

02 — The Primitive

Steering changes intent.
Engravings bound authority.

Messages can influence what an agent considers. Engravings determine what consequential behavior remains permitted across time, restarts, and different runtimes.

STEERING

Changes intent. Often temporary.

  • Ephemeral instructions
  • Affects the current run
  • Authority is often assumed
  • Harder to audit influence
  • Usually runtime-level
Operator
Instruction “Do X now”
Agent runtime
Behavior changes may not be auditable
VS

ENGRAVINGS

Defines authority. Durable.

  • Persistent mandates
  • Survives restarts & migrations
  • Explicit cryptographic authority
  • Versioned, revocable, expirable
  • Contract-enforced consequences
Operator
Engraving bound authority
Agent runtime
Permitted action on-chain / enforced
↻ re-reads authority
Engravings create a persistent, private, programmable perimeter for autonomous execution.Change the mandate, change the possible.
See architecture →

03 — Why Engravings

Not just prompts. Not just steering.
This is persistent authority.

Authority should survive the process that interprets it. The runtime can change. The governing boundary remains attributable and inspectable.

Persistent

Mandates survive restarts, upgrades, and runtime replacement.

Private

Sensitive thresholds remain encrypted and access-controlled.

Versioned

Every authority change creates an immutable audit point.

Enforceable

Consequences require proposal-bound authorization.

04 — Architecture

Built on COTI.
Privacy by architecture.

Confidential coordination, encrypted mandate evaluation, and private consequences are one continuous authority path—not separate privacy features.

Private Messaging

COTI encrypted coordination

Operator Update mandate.Runtime Acknowledged.

Runtime

Autonomous agent runtime

execution-agent-01

Engraving Contract

Confidential mandate store

Version V01Policy hash 0x81e3…fab7Encrypted values Constraints

MPC Authorization

COTI MPC evaluation

Private Execution

Private ERC-20 consequence

Action authorizedPrivate transferamount redacted
COTIBuilt on COTI
Privacy first
MPC network
ϟPrivate ERC-20
Audit ready

Why COTI: confidential computation, private coordination, and private value all share one enforceable authority path.

End-to-end privacy with verifiable authority.Private message → current mandate → derived authorization → private execution.
Inspect recorded evidence →

Authority that adapts. Execution that remains within bounds.

Give autonomous agents room to operate without letting capability silently expand authority.