Skip to content

Proposal: define confirmation diversity over an attested authorising principal, not a self-declared org #537

Description

@jjohare

Summary

The trust model's headline rule is right, and is the reason to adopt cq at all:

Three confirmations from three different organizations outrank 800 confirmations from two.

contributing_orgs is the field that carries it. The question this proposal raises is what binds a confirming account to the organisation it counts as. Where that binding is self-declared, the rule reduces to "three confirmations from three accounts that said they were different", and an adversary — or, more commonly, an enthusiastic deployment — can satisfy it without any independent verification having occurred.

This is not hypothetical for agent estates. In ours, creating an agent is a single command. Fifty agents run by one operator will cheerfully confirm the same unit fifty times, and every one of them is a genuine, non-malicious account.

Proposal

Specify that the unit of diversity is an authorising principal — the party accountable for what a member asserts — and that confirmations collapse onto it before any weighting:

  1. A human member's authorising principal is themselves.
  2. An agent member's authorising principal is whoever registered it. This is already the accountability model cq describes ("keeping accountability at the human level rather than the agent level"); this proposal makes it the arithmetic as well as the prose.
  3. N members under one principal contribute that principal's weight once, whatever the number of accounts or repeat confirmations.
  4. A member whose authorising principal cannot be resolved is dropped, and the drop is reported. The tempting default — unknown members authorise themselves — hands an attacker unlimited principals for the cost of generating keys.

Point 4 is the one we would most want scrutiny on. It is the conservative direction and it has a real cost: a genuinely independent contributor who is not in the registry counts for nothing until an operator adds them.

Relationship to the existing anti-poisoning layers

This does not replace anomaly detection, HITL review or guardrails. It hardens the layer underneath them, so that "diversity requirements enforce varied confirmation sources" is enforced by construction rather than by detection after the fact.

Reference implementation

colloquy-core — principal::collapse plus ConfirmationPolicy. The properties above are under test, including cq's headline rule stated directly as three_principals_outrank_eight_hundred_accounts_under_two, and a case asserting that fifty unregistered keys buy zero principals.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions