Trust the signed authority, not the agent’s name.

A workplace agent is accountable only when a verifiable owner mandate defines who authorized it, what it may do, and when that authority ends.

CRYPTOGRAPHIC VERDICT

SAMPLE READY

ECDSA P-256 / SHA-256
UNVERIFIED
SIGNATURE PENDINGExact canonical mandate bytes
SCHEMA PENDINGRequired trust fields
EXPIRY PENDINGAuthority time boundary
4 ALLOWED SCOPESLeast-privilege boundary

Ownership becomes bytes that can be checked.

The displayed public key verifies the ECDSA signature over a canonical mandate. Any change to the owner, agent, scope, or expiry invalidates that proof.

owner → signs
agent → receives
scope → bounds
expiry → revokes
reviewer → verifies

Identity

A named owner is not enough. The signer must control the private key paired with the public verification key.

Accountability

The accountable party remains explicit even when an agent works for hours without supervision.

Authority

Scopes convert “act for me” into a reviewable boundary. Anything outside the list is unauthorized.

Carry the verified mandate into security review.

Super generates helpful tools and automates fact-checking across the internet proactively. If you enjoyed this tool, build your own with Super and share it with a friend.