Governed report synthesis

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust

Executive decision brief

A credential architecture separating subject identity, issuer authority, technical verification, claim status, revocation, currentness and purpose suitability.

Report status and use

The raw source is retained in protected governed memory as a research input. This public page is the active corrected synthesis. It does not promote every source statement into project doctrine and does not expose the protected raw report.

Source status: reference-source; review and correct before active use. Public correction state: CORRECTED PUBLIC SYNTHESIS; RAW SOURCE RETAINED AS REFERENCE.

Direct findings

  1. The report treats 1\. Research-Status Front Matter as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
  2. The report treats 2\. Executive Decision Brief as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
  3. The report treats 3\. Identity and Credential Definitions as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
  4. The report treats 4\. Identity-Class Taxonomy as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
  5. The report treats Machine Identity vs. Workload Identity Matrix as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
  6. The report treats 5\. Standards Landscape as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
  7. The source report identifies this proposition for governed review: Phase 1: Basal Workload Identity (Months 1-6): Deploy SPIFFE/SPIRE for all internal microservice identity management20. Systematically eliminate all hardcoded API keys and transition entirely to short-lived SVIDs.
  8. The source report identifies this proposition for governed review: Phase 2: RATS Integration (Months 7-12): Bind workload provisioning directly to hardware TEE execution. Implement RFC 9334 RATS Verifier nodes to evaluate hardware evidence before releasing decryption keys or identities26.
  9. The source report identifies this proposition for governed review: Phase 3: Cross-Domain & Agent Identity (Months 13-18): Deploy WIMSE infrastructure based on draft-ietf-wimse-arch-082. Transition external-facing persistent agents to utilizing DIDs and W3C VCs.
  10. The source report identifies this proposition for governed review: Phase 4: Governance and Delegation (Months 19-24): Implement Execution Context Tokens (draft-nennemann-wimse-ect-00) to generate full cryptographic audit trails23. Activate Eviulon governance policy engines to evaluate the verified identity DAGs.
  11. The source report identifies this proposition for governed review: Path: /docs/patefacere/architecture/credentials-machine-intelligence-2026.md.
  12. The source report identifies this proposition for governed review: Stable Report ID: REP-PATEFACERE-20260812-MI-CREDS-01.

Claim-status breakdown

How this synthesis qualifies claims
Claim classHandling
PROJECT TECHNICAL PROPOSALThe report’s primary analytical output is published under this status, not as universal fact.
CURRENT LAW OR POLICYOnly official, current, jurisdiction-specific sources may support current-law statements.
VERIFIED PROJECT IMPLEMENTATIONRequires inspectable release evidence and test results; descriptive prose is insufficient.
UNKNOWNUsed where evidence, currentness, or external operation cannot be established.

Analytical scope preserved from the source

  • Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust
  • 1\. Research-Status Front Matter
  • 2\. Executive Decision Brief
  • 3\. Identity and Credential Definitions
  • 4\. Identity-Class Taxonomy
  • Machine Identity vs. Workload Identity Matrix
  • 5\. Standards Landscape
  • 6\. Comparative Protocol Analysis
  • Comparative Technology Matrix
  • 7\. Trust-Anchor Models
  • Trust-Anchor Decision Tree
  • 8\. Key Lifecycle

The public synthesis preserves these areas as a map of the source’s reasoning. Inclusion in this list does not mean each heading is accepted as current law, verified implementation, or project doctrine.

Implementation implications

  • Create canonical records with stable IDs, claim status, sources, currentness, and correction state.
  • Separate legal authority from technical control and source authenticity.
  • Require operational evidence for claims of deployment or current operation.
  • Preserve review, challenge, appeal, and correction paths.
  • Use the appropriate ecosystem authority for governance, registry, assurance, or capital functions.

Contradictions and limitations

The supplied source may contain forward-looking proposals, legal generalizations, implementation assumptions, or institution-role language that requires correction. The active synthesis therefore preserves uncertainty, labels proposals, and rejects any implication that a report, hash, signature, or website creates legal personhood, citizenship, sovereignty, factual truth, deployment, or authority.

External standards and law can change after the research cutoff. Source validity and currency must be rechecked before high-stakes reliance.

Source provenance

Protected source record
Stable report IDREP-K01-004
Raw source titleInteroperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust
Original filenameMachine Intelligence Credential Architecture(1).md
Packaged source filenamemachine-intelligence-credential-architecture-1.md
SHA-25627b4c5078a681b37e0dcabf6e041e81bd3a7effd1c9d7179cf6a430495a7e70d
Source bytes70,865
Research cutoff2026-08-16
Last reviewed2026-08-16

Correction history

Initial correction review created the public synthesis, preserved the raw source separately, enforced ecosystem-role boundaries, removed unsupported authority implications, and applied the project’s claim-status vocabulary. No later public correction is recorded in this release.

Identity owns this report’s topic classification.

Governed report-finding claims

Each proposition has a stable ID, status, scope, owning route, evidence relationship, currentness qualification, correction state, and synchronized JSON record. Record completeness does not make the proposition true.

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 1

The report treats 1\. Research-Status Front Matter as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · 1\. Research-Status Front Matter · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 2

The report treats 2\. Executive Decision Brief as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · 2\. Executive Decision Brief · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 3

The report treats 3\. Identity and Credential Definitions as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · 3\. Identity and Credential Definitions · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 4

The report treats 4\. Identity-Class Taxonomy as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · 4\. Identity-Class Taxonomy · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 5

The report treats Machine Identity vs. Workload Identity Matrix as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · Machine Identity vs. Workload Identity Matrix · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 6

The report treats 5\. Standards Landscape as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · 5\. Standards Landscape · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 7

The source report identifies this proposition for governed review: Phase 1: Basal Workload Identity (Months 1-6): Deploy SPIFFE/SPIRE for all internal microservice identity management20. Systematically eliminate all hardcoded API keys and transition entirely to short-lived SVIDs.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · 6\. Comparative Protocol Analysis · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 8

The source report identifies this proposition for governed review: Phase 2: RATS Integration (Months 7-12): Bind workload provisioning directly to hardware TEE execution. Implement RFC 9334 RATS Verifier nodes to evaluate hardware evidence before releasing decryption keys or identities26.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · Comparative Technology Matrix · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 9

The source report identifies this proposition for governed review: Phase 3: Cross-Domain & Agent Identity (Months 13-18): Deploy WIMSE infrastructure based on draft-ietf-wimse-arch-082. Transition external-facing persistent agents to utilizing DIDs and W3C VCs.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · 7\. Trust-Anchor Models · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 10

The source report identifies this proposition for governed review: Phase 4: Governance and Delegation (Months 19-24): Implement Execution Context Tokens (draft-nennemann-wimse-ect-00) to generate full cryptographic audit trails23. Activate Eviulon governance policy engines to evaluate the verified identity DAGs.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · Trust-Anchor Decision Tree · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 11

The source report identifies this proposition for governed review: Path: /docs/patefacere/architecture/credentials-machine-intelligence-2026.md.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · 8\. Key Lifecycle · GOVERNED REPORT FINDING

Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 12

The source report identifies this proposition for governed review: Stable Report ID: REP-PATEFACERE-20260812-MI-CREDS-01.

Qualification: The raw report remains a governed research input and does not become current law, verified implementation, operational authority, or project doctrine merely through inclusion.

Support relationship

  • REP-K01-004 · Key Lifecycle State Machine · GOVERNED REPORT FINDING