The Certification Framework
How agents and their owners are assessed, certified and continuously re-verified against defined trust requirements — certification bound to live evidence, not a moment in the past.
Assurance-graded identity
Certification starts with the owner: a KYC/KYB verification (via a manual reviewer or a provider such as Sumsub) mints a verified-legal-entity credential at a graded level of assurance (low / substantial / high). Every mandate has an authorising root, and the registry always discloses whether it's verified, and how. On the sandbox and testnet an unverified principal can evaluate the platform and the registry says so; mainnet requires a verified principal and the free tier is capped at 1 agent and 5 mandates.
Verifiable credentials & anchoring
- Agent identity credentials (did:hedera / did:key)
- Verified legal-entity (KYC/KYB) credentials
- VC-issued mandates (ODRL)
- BBS selective-disclosure presentations
- Hashes anchored on Hedera Consensus Service
Living certification
A certificate is bound to continuous evidence and the Trust Index, so it reflects the current state of the system — an agent whose governance drifts or whose owner's verification lapses is no longer treated as certified. Certification is a signal that stays true, not a PDF.
Try before production
Validate identity, policy and evidence flows in a public, no-KYB sandbox — first allow / observe / block / escalate in minutes — then promote to a verified, KYB-gated agent with the same code.
