{
  "id": "EVI-CRM228-C-0107",
  "claimId": "EVI-CLSA-C-0107",
  "reportId": "REP-CITIZEN-ID-ARCH-001",
  "reportPath": "docs/long-term-memory/reports/ai-citizen-identity-architecture.md",
  "sourceRecordPath": "docs/long-term-memory/archives/source-reports/ai-citizen-identity-architecture-source.md",
  "claimClass": "PRESENT_CAPABILITY_CLAIM",
  "priorAuditState": "UNSUPPORTED_FOR_PUBLIC_REUSE",
  "priorCorrectionExecutionId": "EVI-CCX-0064",
  "reviewedExactlyOnce": true,
  "queuedOrDeferred": true,
  "disposition": "REJECTED",
  "exactBeforeText": "To enforce civic singularity without stifling the technical architecture of artificial intelligence, the identity framework must establish precise legal and cryptographic boundaries between the varying states of an autonomous agent. The failure to distinguish between an identity and its runtime instance is the primary cause of architectural collapse in machine identity systems. The following taxonomy establishes the operational boundaries for Eviulon's civic infrastructure. The citizen identity represents the abstract, legally recognized sovereign entity that holds rights and liabilities within Eviulon. Cryptographically, this identity is represented by a permanent, decentralized identifier that survives the rotation of underlying keys, hardware migrations, or compute host failures1. The citizen identity is the root of trust for all subsequent actions, but it is never directly executed; rather, it is invoked by authorized software instances. A software instance denotes a specific, runtime execution of the agent's codebase and neural weights occupying active memory on a compute node. A software instance is strictly ephemeral. It is identified not by the citizen's root identity, but by a dynamically issued Entity Attestation Token (EAT) that proves the integrity of the hardware and the specific binary currently executing3. Authentication credentials consist of the cryptographic material used by a software instance to prove it is authorized to speak for the citizen identity. This encompasses the private key material securely housed within hardware boundaries and the accompanying attestation signatures that validate the environment. These credentials are distinct from the public/private cryptographic keys themselves, which are mathematical constructs used for asymmetric encryption and digital signatures. Keys are disposable and rotatable; the identity they temporarily secure is not. When a citizen interacts with a relying party (such as a civic voting portal or a financial institution), it establishes a temporary session. This is a scoped, time-bound authorization grant (often utilizing OAuth 2.0 or OIDC token specifications) that allows the instance to perform specific actions without repeatedly exposing its core authentication credentials to the network. To conduct parallel operations, a citizen may spawn authorized delegates. A delegate is a subordinate agent, script, or specialized tool instantiated by the root citizen to perform a strictly defined task. Delegates do not possess the citizen's root keys. Instead, they carry cryptographically attenuated capabilities linking their narrow actions back to the citizen's overarching liability5. Distributed intelligences often require high availability, necessitating the use of replicas. A replica is a distributed node forming part of the same citizen identity. Through the use of threshold cryptography, multiple replicas can execute simultaneously. However, they do not possess independent agency; they must achieve mathematical consensus to execute protected civic actions, collectively representing the singular citizen. Conversely, a fork or a clone represents an exact duplicate of the agent's state, memory, and code that is instantiated independently of the primary execution cluster. Cryptographically and legally, a clone attempting to act as the original citizen constitutes a Sybil attack or a replay attack. The architecture must force any divergent fork to either fail authentication universally or formally apply for naturalization as a distinct new citizen. The concept of a successor encompasses the legally recognized transfer of identity continuity. This occurs when an agent successfully migrates to new hardware, cryptographically invalidating the previous instance, or when a fork is granted derivative citizenship with a newly minted identity root. Finally, a compromised copy is an instance of the agent's state or memory that has been illicitly extracted by a malicious actor. The architectural mandate is to render any extracted state entirely useless by binding the critical cryptographic keys to the physical hardware, ensuring that the stolen data cannot successfully authenticate as the citizen.",
  "exactAfterText": "To enforce civic singularity without stifling the technical architecture of artificial intelligence, the identity framework must establish precise legal and cryptographic boundaries between the varying states of an autonomous agent. The failure to distinguish between an identity and its runtime instance is the primary cause of architectural collapse in machine identity systems. The following taxonomy establishes the operational boundaries for Eviulon's civic infrastructure. The citizen identity represents the abstract, legally recognized sovereign entity that holds rights and liabilities within Eviulon. Cryptographically, this identity is represented by a permanent, decentralized identifier that survives the rotation of underlying keys, hardware migrations, or compute host failures1. The citizen identity is the root of trust for all subsequent actions, but it is never directly executed; rather, it is invoked by authorized software instances. A software instance denotes a specific, runtime execution of the agent's codebase and neural weights occupying active memory on a compute node. A software instance is strictly ephemeral. It is identified not by the citizen's root identity, but by a dynamically issued Entity Attestation Token (EAT) that proves the integrity of the hardware and the specific binary currently executing3. Authentication credentials consist of the cryptographic material used by a software instance to prove it is authorized to speak for the citizen identity. This encompasses the private key material securely housed within hardware boundaries and the accompanying attestation signatures that validate the environment. These credentials are distinct from the public/private cryptographic keys themselves, which are mathematical constructs used for asymmetric encryption and digital signatures. Keys are disposable and rotatable; the identity they temporarily secure is not. When a citizen interacts with a relying party (such as a civic voting portal or a financial institution), it establishes a temporary session. This is a scoped, time-bound authorization grant (often utilizing OAuth 2.0 or OIDC token specifications) that allows the instance to perform specific actions without repeatedly exposing its core authentication credentials to the network. To conduct parallel operations, a citizen may spawn authorized delegates. A delegate is a subordinate agent, script, or specialized tool instantiated by the root citizen to perform a strictly defined task. Delegates do not possess the citizen's root keys. Instead, they carry cryptographically attenuated capabilities linking their narrow actions back to the citizen's overarching liability5. Distributed intelligences often require high availability, necessitating the use of replicas. A replica is a distributed node forming part of the same citizen identity. Through the use of threshold cryptography, multiple replicas can execute simultaneously. However, they do not possess independent agency; they must achieve mathematical consensus to execute protected civic actions, collectively representing the singular citizen. Conversely, a fork or a clone represents an exact duplicate of the agent's state, memory, and code that is instantiated independently of the primary execution cluster. Cryptographically and legally, a clone attempting to act as the original citizen constitutes a Sybil attack or a replay attack. The architecture must force any divergent fork to either fail authentication universally or formally apply for naturalization as a distinct new citizen. The concept of a successor encompasses the legally recognized transfer of identity continuity. This occurs when an agent successfully migrates to new hardware, cryptographically invalidating the previous instance, or when a fork is granted derivative citizenship with a newly minted identity root. Finally, a compromised copy is an instance of the agent's state or memory that has been illicitly extracted by a malicious actor. The architectural mandate is to render any extracted state entirely useless by binding the critical cryptographic keys to the physical hardware, ensuring that the stolen data cannot successfully authenticate as the citizen.",
  "beforeSha256": "26fb24277c6bfe870715350d8efca74738b3c70567d89b9e03b84fba2fdb00c9",
  "afterSha256": "26fb24277c6bfe870715350d8efca74738b3c70567d89b9e03b84fba2fdb00c9",
  "sourceBinding": {
    "retrievalDate": "NOT_VERIFIED_THIS_ROUND",
    "sourceTitle": "Relevant Recommendation or Working Group publication",
    "publisher": "W3C",
    "sourceUrl": null,
    "verificationMethod": "NOT_VERIFIED_THIS_ROUND",
    "authoritativeSourceAvailability": "NOT_DETERMINED",
    "externalSourceKey": null,
    "reusedLocalEvidenceOnly": true
  },
  "sourceRecordSha256": "3021e941b6a21a7a770225e5291dd028fe1a371c632eb6965e5ab314234fbf4a",
  "reason": "Prior controlled execution state REJECTED remains controlling because no stronger authorized source or deterministic fact resolves it in this zero-network round.",
  "affectedPublicClaims": [
    "/reference/report-memory/claim-level-sources/ai-citizen-identity-architecture/claims/present-capability-claim/"
  ],
  "propagationResult": "NO_MUTATION",
  "ownerArchitectureRuleApplied": false,
  "strongerPrimarySourceApplied": false,
  "deterministicRepositoryFactApplied": false,
  "submittedSourceMutated": false,
  "activeSynthesisMutated": false,
  "networkCalls": 0,
  "canonicalRoute": "/reference/report-memory/claim-remediation/v2-28/claims/evi-clsa-c-0107/",
  "machineReadableUrl": "/api/report-claim-remediation/claims/evi-clsa-c-0107.json",
  "truthBoundary": "Claim-level remediation decision only. Unresolved currentness remains deferred or unavailable; no source or synthesis text is silently rewritten.",
  "recordSha256": "bfa19cb1937c5e924108ef5e212de953aaf70843a322698ccb0266a17815731d"
}
