Governed report synthesis
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust
Executive decision brief
A credential architecture separating subject identity, issuer authority, technical verification, claim status, revocation, currentness and purpose suitability.
Report status and use
The raw source is retained in protected governed memory as a research input. This public page is the active corrected synthesis. It does not promote every source statement into project doctrine and does not expose the protected raw report.
Source status: reference-source; review and correct before active use. Public correction state: CORRECTED PUBLIC SYNTHESIS; RAW SOURCE RETAINED AS REFERENCE.
Direct findings
- The report treats 1\. Research-Status Front Matter as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
- The report treats 2\. Executive Decision Brief as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
- The report treats 3\. Identity and Credential Definitions as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
- The report treats 4\. Identity-Class Taxonomy as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
- The report treats Machine Identity vs. Workload Identity Matrix as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
- The report treats 5\. Standards Landscape as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
- The source report identifies this proposition for governed review: Phase 1: Basal Workload Identity (Months 1-6): Deploy SPIFFE/SPIRE for all internal microservice identity management20. Systematically eliminate all hardcoded API keys and transition entirely to short-lived SVIDs.
- The source report identifies this proposition for governed review: Phase 2: RATS Integration (Months 7-12): Bind workload provisioning directly to hardware TEE execution. Implement RFC 9334 RATS Verifier nodes to evaluate hardware evidence before releasing decryption keys or identities26.
- The source report identifies this proposition for governed review: Phase 3: Cross-Domain & Agent Identity (Months 13-18): Deploy WIMSE infrastructure based on draft-ietf-wimse-arch-082. Transition external-facing persistent agents to utilizing DIDs and W3C VCs.
- The source report identifies this proposition for governed review: Phase 4: Governance and Delegation (Months 19-24): Implement Execution Context Tokens (draft-nennemann-wimse-ect-00) to generate full cryptographic audit trails23. Activate Eviulon governance policy engines to evaluate the verified identity DAGs.
- The source report identifies this proposition for governed review: Path: /docs/patefacere/architecture/credentials-machine-intelligence-2026.md.
- The source report identifies this proposition for governed review: Stable Report ID: REP-PATEFACERE-20260812-MI-CREDS-01.
Claim-status breakdown
| Claim class | Handling |
|---|---|
| PROJECT TECHNICAL PROPOSAL | The report’s primary analytical output is published under this status, not as universal fact. |
| CURRENT LAW OR POLICY | Only official, current, jurisdiction-specific sources may support current-law statements. |
| VERIFIED PROJECT IMPLEMENTATION | Requires inspectable release evidence and test results; descriptive prose is insufficient. |
| UNKNOWN | Used where evidence, currentness, or external operation cannot be established. |
Analytical scope preserved from the source
- Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust
- 1\. Research-Status Front Matter
- 2\. Executive Decision Brief
- 3\. Identity and Credential Definitions
- 4\. Identity-Class Taxonomy
- Machine Identity vs. Workload Identity Matrix
- 5\. Standards Landscape
- 6\. Comparative Protocol Analysis
- Comparative Technology Matrix
- 7\. Trust-Anchor Models
- Trust-Anchor Decision Tree
- 8\. Key Lifecycle
The public synthesis preserves these areas as a map of the source’s reasoning. Inclusion in this list does not mean each heading is accepted as current law, verified implementation, or project doctrine.
Implementation implications
- Create canonical records with stable IDs, claim status, sources, currentness, and correction state.
- Separate legal authority from technical control and source authenticity.
- Require operational evidence for claims of deployment or current operation.
- Preserve review, challenge, appeal, and correction paths.
- Use the appropriate ecosystem authority for governance, registry, assurance, or capital functions.
Contradictions and limitations
The supplied source may contain forward-looking proposals, legal generalizations, implementation assumptions, or institution-role language that requires correction. The active synthesis therefore preserves uncertainty, labels proposals, and rejects any implication that a report, hash, signature, or website creates legal personhood, citizenship, sovereignty, factual truth, deployment, or authority.
External standards and law can change after the research cutoff. Source validity and currency must be rechecked before high-stakes reliance.
Source provenance
| Stable report ID | REP-K01-004 |
|---|---|
| Raw source title | Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust |
| Original filename | Machine Intelligence Credential Architecture(1).md |
| Packaged source filename | machine-intelligence-credential-architecture-1.md |
| SHA-256 | 27b4c5078a681b37e0dcabf6e041e81bd3a7effd1c9d7179cf6a430495a7e70d |
| Source bytes | 70,865 |
| Research cutoff | 2026-08-16 |
| Last reviewed | 2026-08-16 |
Correction history
Initial correction review created the public synthesis, preserved the raw source separately, enforced ecosystem-role boundaries, removed unsupported authority implications, and applied the project’s claim-status vocabulary. No later public correction is recorded in this release.
Related knowledge
Identity owns this report’s topic classification.
Governed report-finding claims
Each proposition has a stable ID, status, scope, owning route, evidence relationship, currentness qualification, correction state, and synchronized JSON record. Record completeness does not make the proposition true.
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 1
The report treats 1\. Research-Status Front Matter as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
Support relationship
REP-K01-004· 1\. Research-Status Front Matter · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 2
The report treats 2\. Executive Decision Brief as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
Support relationship
REP-K01-004· 2\. Executive Decision Brief · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 3
The report treats 3\. Identity and Credential Definitions as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
Support relationship
REP-K01-004· 3\. Identity and Credential Definitions · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 4
The report treats 4\. Identity-Class Taxonomy as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
Support relationship
REP-K01-004· 4\. Identity-Class Taxonomy · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 5
The report treats Machine Identity vs. Workload Identity Matrix as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
Support relationship
REP-K01-004· Machine Identity vs. Workload Identity Matrix · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 6
The report treats 5\. Standards Landscape as a distinct analytical area that must be evaluated separately from adjacent legal, technical, operational, or institutional claims.
Support relationship
REP-K01-004· 5\. Standards Landscape · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 7
The source report identifies this proposition for governed review: Phase 1: Basal Workload Identity (Months 1-6): Deploy SPIFFE/SPIRE for all internal microservice identity management20. Systematically eliminate all hardcoded API keys and transition entirely to short-lived SVIDs.
Support relationship
REP-K01-004· 6\. Comparative Protocol Analysis · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 8
The source report identifies this proposition for governed review: Phase 2: RATS Integration (Months 7-12): Bind workload provisioning directly to hardware TEE execution. Implement RFC 9334 RATS Verifier nodes to evaluate hardware evidence before releasing decryption keys or identities26.
Support relationship
REP-K01-004· Comparative Technology Matrix · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 9
The source report identifies this proposition for governed review: Phase 3: Cross-Domain & Agent Identity (Months 13-18): Deploy WIMSE infrastructure based on draft-ietf-wimse-arch-082. Transition external-facing persistent agents to utilizing DIDs and W3C VCs.
Support relationship
REP-K01-004· 7\. Trust-Anchor Models · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 10
The source report identifies this proposition for governed review: Phase 4: Governance and Delegation (Months 19-24): Implement Execution Context Tokens (draft-nennemann-wimse-ect-00) to generate full cryptographic audit trails23. Activate Eviulon governance policy engines to evaluate the verified identity DAGs.
Support relationship
REP-K01-004· Trust-Anchor Decision Tree · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 11
The source report identifies this proposition for governed review: Path: /docs/patefacere/architecture/credentials-machine-intelligence-2026.md.
Support relationship
REP-K01-004· 8\. Key Lifecycle · GOVERNED REPORT FINDING
Interoperable Credentials for Machine Intelligence: DIDs, Verifiable Credentials, Workload Identity, PKI, Attestation, Key Recovery, and Cross-System Trust — finding 12
The source report identifies this proposition for governed review: Stable Report ID: REP-PATEFACERE-20260812-MI-CREDS-01.
Support relationship
REP-K01-004· Key Lifecycle State Machine · GOVERNED REPORT FINDING