Spherity AI Safety Series — Paper 3 of 3

Private Verification of Action Eligibility across Trust Domains

AI Safety: Evidence Semantics and Controlled Execution for Cross Organisation Agents

Author
Affiliation
Dr. Carsten Stöcker — Spherity GmbH
Published
Updated
Research cut-off
· Research, protocols and implementation evidence reviewed to this date
This version
https://spherity.github.io/spherity-research/private-verification-action-eligibility-trust-domains.html
Latest version
https://spherity.github.io/spherity-research/private-verification-action-eligibility-trust-domains.html
Browse this paper

In brief

What does this research establish?

The paper defines typed claims, recognition rules and a deterministic eligibility evaluator that binds an exact AI-agent operation to a versioned evidence view, including prohibitions and adverse findings. A separate protected admission controller and resource-specific effect adapter preserve local authority, replay safety, pending effects and containment across trust domains.

Key takeaways

  • Eligibility must bind the exact operation, continuation and evidence version; a general identity or capability claim is insufficient.
  • Typed claims and explicit recognition rules prevent semantic mapping or delegation from silently expanding issuer scope.
  • Revocation blocks future admissions but does not erase an effect already in flight; containment and verified closure need their own protocol.
  • The paper validates reference logic and scenarios but does not present a deployed privacy-proof system or measured operational safety rate.

Download Paper 3

Download the full paper

The typed evidence model, private eligibility protocol, deterministic evaluator, protected controller and cross-domain scenarios.

Start with the executive brief

Download the executive brief

Read the leadership case and how all three technical papers form one AI Safety control chain.

First page of Private Verification of Action Eligibility across Trust Domains.
AI Safety Series — Paper 3. Private verification, evidence semantics and controlled execution for cross-organization agents. Published under CC BY 4.0.

Abstract

This paper develops a protocol for verifying exact AI-agent action eligibility across trust domains while limiting disclosure of underlying evidence. A versioned evidence view includes positive claims, prohibitions and adverse findings. Typed claims and explicit recognition rules preserve issuer scope across delegation and semantic mapping. A pure deterministic evaluator decides eligibility; a separate serialized admission controller prevents replay, reserves resources and binds the exact operation; and resource-specific adapters enforce the covered effect. Persistent logical operation identifiers and pending-effect state preserve accountability through cancellation, renewal and worker replacement.

Keywords: private verification; action eligibility; AI agents; trust domains; evidence semantics; verifiable credentials; controlled execution; revocation

The cross-domain problem

An agent may need to act in a domain that does not operate its identity provider, evidence registry or policy engine. The relying organization must decide whether to recognize foreign claims, how to interpret delegation, which adverse findings override positive evidence and how to enforce its own resource policy. Simply forwarding a credential bundle can disclose too much and still fail to establish exact action eligibility.

The paper therefore treats eligibility as a scoped statement about one actor, operation, evidence version and continuation. The relying domain remains sovereign: it chooses recognition rules and performs local protected admission even when source evidence originates elsewhere.

Typed claims, recognition rules and exact-operation binding

Claims are typed by issuer, subject, scope, purpose, validity and evidence semantics. Recognition rules specify how a relying domain accepts or maps each claim. Prohibitions and adverse findings are first-class inputs rather than inconvenient exceptions hidden outside the proof.

The evaluator is pure and deterministic: the same evidence view and policy version produce the same eligibility decision. That makes it testable and auditable. It does not create an external effect. The admission controller separately serializes requests, checks operation IDs, reserves resources and commits the exact payload.

Reference architecture for cross-domain controlled execution

Two trust domains separate private eligibility evaluation, protected admission and local effect enforcement while sharing bounded evidence and records.
Figure 1. Two trust domains retain separate pure eligibility evaluation, protected admission and effect enforcement. Joint assurance preserves continuation and episode state while local authority remains sovereign. Dashed lines carry evidence and records; solid paths carry protected control and effects. Source: Spherity GmbH.

Each domain retains three distinct functions: eligibility evaluation, protected admission and resource-specific effect enforcement. Joint assurance can carry continuation and episode state across the boundary, but it does not eliminate local authority. Outcome records flow back into the evidence view so later actions can account for what actually occurred.

This pattern applies to B2B procurement agents, data-space access, Digital Product Passport disclosures, cross-provider agent tools and industrial workflows where no single organization controls the complete trust chain.

Revocation, containment and verified closure

An adverse evidence update blocks future AI-agent admissions while earlier remote effects remain pending until containment and verified closure.
Figure 2. An adverse update can block future admission while an earlier remote effect remains pending. Revocation is therefore distinct from containment, kill-switch action and verified closure. Source: Spherity GmbH.

An adverse update can immediately block future admissions. It cannot retroactively cancel an effect that another system has already accepted. Cross-domain safety therefore needs explicit containment messages, local kill-switch or compensation logic, durable pending-effect identifiers and evidence of verified closure.

This is especially important for long-running tools, shipments, data releases and physical operations. The protocol must distinguish no longer eligible to start from confirmed to have stopped.

Use cases and standards alignment

The paper proposes an A2A extension using W3C Verifiable Credentials and a bounded ODRL profile. It also relates the design to the A2A protocol, Model Context Protocol authorization and remote-attestation architecture. These references provide interoperability building blocks; they do not by themselves implement the complete safety protocol.

Evaluation evidence and limits

The reported controller exploration covers 16,020 states and 60,238 transitions against nine invariants. Eight omission variants yield counterexamples, and 29 plaintext reference-gate scenarios exercise positive and adverse evidence paths.

The work does not report a deployed privacy-proof implementation, measured operational safety probabilities or general AI alignment. Cryptographic proof-system selection, performance, revocation distribution, policy governance and production adversarial testing remain implementation responsibilities.

Selected references

  1. W3C, Verifiable Credentials Data Model v2.0.
  2. W3C, ODRL Information Model 2.2.
  3. A2A Project, Agent2Agent Protocol Specification.
  4. Model Context Protocol, Authorization.
  5. IETF, RFC 9334: Remote ATtestation procedureS Architecture.
  6. European Union, Artificial Intelligence Act.
  7. NIST, Artificial Intelligence Risk Management Framework.

How to cite Paper 3

Stöcker, Carsten (2026). Private Verification of Action Eligibility across Trust Domains: AI Safety—Evidence Semantics and Controlled Execution for Cross Organisation Agents. Spherity GmbH. https://spherity.github.io/spherity-research/private-verification-action-eligibility-trust-domains.html. Licensed CC BY 4.0.

Creative Commons Attribution 4.0 International

Open research

License and citation

This research page and the linked Paper 3 PDF is licensed by its named author under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Reuse must credit every named author, link to this canonical version and the license, and indicate whether changes were made.

How to cite this work

Dr. Carsten Stöcker (2026-09-28). “Private Verification of Action Eligibility across Trust Domains: AI Safety: Evidence Semantics and Controlled Execution for Cross Organisation Agents.” Spherity GmbH. https://spherity.github.io/spherity-research/private-verification-action-eligibility-trust-domains.html. Licensed CC BY 4.0.

Direct answers

Questions this research answers

What does private verification of action eligibility establish?

It establishes that a specific actor, operation and continuation satisfy a versioned set of recognized claims, prohibitions and adverse-evidence rules for a relying domain, while allowing the proof interface to disclose less than the full source evidence.

Why must eligibility evaluation be separate from protected admission?

A pure evaluator can determine whether submitted evidence satisfies a policy, but only a serialized protected controller can prevent replay, reserve resources, bind the exact effect and update state atomically. Both layers are required.

Does revocation stop an effect that is already pending?

Not by itself. Revocation can block future admission, while an earlier remote effect may still require a containment request, kill-switch action, compensating control and independently verified closure.