Concepts

How Genesis Mesh Works

Genesis Mesh is easier to understand as a connected trust model than as a list of isolated terms.

Genesis Mesh Foundation

Where trust comes from, how participants join, how authority is delegated, and how independent domains recognize each other.

Select any concept to see what it is, where it fits, and a real-world analogy.

Each trust domain keeps control of its own identity, policies, keys, and decisions, while still being able to cooperate with other domains under explicit and verifiable rules.

About this story

This section explains the trust foundation underneath Genesis Mesh.

A simplified view is:

Root Sovereign
      ↓
Genesis Block
      ↓
Network Authority
      ↓
Identity, Nodes, Agreements, Recognition
      ↓
Delegation, Revocation, Federation
      ↓
Advanced authorization and trust observability

The central idea is simple:

  1. Identity, Nodes, Agreements, Recognition

  2. Delegation, Revocation, Federation

Where the stories connect

Explore all concepts as textAll 26 concepts in this view, with what each is, where it fits, and a real-world analogy.

Genesis Mesh

Genesis Mesh

What it is

Genesis Mesh is a trust, policy, authorization, and evidence layer for interactions between machines, services, agents, people, and organizations.

It does not require every participant to give control to one central authority. Instead, it provides a way to establish identity, define authority, make signed decisions, delegate rights, revoke trust, and prove what happened.

Where it fits

Genesis Mesh is the overall system that connects the concepts in this guide.

It can be used inside one organization or across multiple independent organizations.

Real-world analogy

Think of a system that combines identity documents, contracts, policy rules, approval decisions, delegated authority, revocation, and an official evidence archive.

Each part has a different job, but together they create a complete trust model.

Genesis Mesh Foundation

Sovereign

What it is

A Sovereign is an independently controlled Genesis Mesh trust domain.

It owns its own keys, policies, authority, state, and trust decisions.

Where it fits

A Sovereign is the top-level ownership boundary.

Different organizations can each operate their own Sovereign without giving control of their trust domain to another organization.

Real-world analogy

Think of an independent country or company.

It has its own rules, identity system, and decision-making authority. It can cooperate with others without giving up control of itself.

Root Sovereign

What it is

The Root Sovereign is the cryptographic root of trust for a Sovereign.

It establishes the identity of the trust domain and anchors the authority that operates below it.

It is typically kept protected and is not intended for normal day-to-day operations.

Where it fits

The Root Sovereign establishes the Genesis Block, which in turn anchors the Network Authority.

Root Sovereign
      ↓
Genesis Block
      ↓
Network Authority

Real-world analogy

Think of the founding legal documents of an organization.

They are not used for every daily action, but they prove where the organization's authority originally comes from.

Genesis Block

What it is

The Genesis Block is the immutable root document that establishes the Sovereign.

It identifies the trust domain and anchors important information such as the root public key and the Network Authority.

Where it fits

Everything that follows can trace its trust back to the Genesis Block.

It provides a stable answer to:

Where did this authority come from?

Real-world analogy

Think of an organization's certificate of incorporation or constitutional document.

It establishes the organization and the authority structure that follows from it.

Operator Key

What it is

The Operator Key authenticates privileged administrative actions against the Network Authority.

It can be used for actions such as publishing policy, issuing or revoking attestations, registering executor identities, and changing trusted administrative state.

Where it fits

The Operator Key is for governance of the authority itself.

It is separate from the identities that execute normal workload actions.

Real-world analogy

Think of an administrator credential that can change official rules and register trusted users.

A normal worker may execute approved work, but only an authorized administrator can change the system of authority.

Network Authority

What it is

The Network Authority (NA) is the main Genesis Mesh control-plane authority.

Depending on the capability in use, it can manage attestations, evaluate policy, sign authorization decisions, manage recognition and revocation state, register trusted executors, and store evidence.

Where it fits

The Network Authority is the active authority underneath the Sovereign.

The Root Sovereign establishes trust. The Network Authority performs the day-to-day trust and policy work.

Real-world analogy

Think of a central public administration.

The constitution establishes its authority, but the administration performs the daily work of issuing official decisions, maintaining records, and applying rules.

Node

What it is

A Node is a cryptographically enrolled Genesis Mesh peer.

It has its own key material and a Join Certificate proving that it was admitted into the trust domain.

Where it fits

Nodes are useful when trust or enforcement needs to be distributed closer to workloads, edge environments, or other participating systems.

Not every application or executor needs to be a Node.

Real-world analogy

Think of an officially registered branch office.

It has its own local identity, but it is recognized as part of the wider organization.

Invite Token

What it is

An Invite Token is a single-use authorization used to enroll a new Node.

Where it fits

It is part of the Node enrollment process.

Invite Token
      ↓
Enrollment
      ↓
Join Certificate
      ↓
Node

Real-world analogy

Think of a one-time invitation to join a private organization.

The invitation lets someone begin enrollment, but it is not the permanent identity they use afterwards.

Join Certificate

What it is

A Join Certificate is a short-lived Network Authority-signed certificate that proves a Node was admitted into the trust domain.

Where it fits

After a Node is enrolled, the Join Certificate becomes the Node's proof that it is a recognized participant.

Real-world analogy

Think of an official staff badge issued after an employee has completed onboarding.

The invitation allowed them to apply. The badge proves they were accepted.

CRL

What it is

A CRL (Certificate Revocation List) is a signed list of Node certificates that should no longer be trusted.

A Node may be revoked because it was retired, its key was compromised, the system was decommissioned, or trust was withdrawn.

Where it fits

The CRL lets trust be removed before a Join Certificate naturally expires.

Real-world analogy

Think of a security office publishing a list of access badges that have been cancelled even though the printed expiry date has not yet passed.

Agent

What it is

An Agent is a workload or autonomous actor that can perform useful operations.

An AgentDescriptor is a signed description of that agent, including information such as its capabilities and endpoint.

Where it fits

Agents allow Genesis Mesh to represent active machine actors, not only infrastructure peers.

An Agent can participate in trusted workflows where its identity and capabilities need to be understood.

Real-world analogy

Think of an employee and their official job profile.

The employee is the actor. The job profile describes what they do, what capabilities they have, and where they operate.

AgreementRecord

What it is

An AgreementRecord is a dual-signed agreement between two independently governed parties.

It defines what capabilities or terms both parties agree to.

Where it fits

An AgreementRecord is useful when authority is based on mutual agreement rather than one party simply issuing an internal permission to another.

Real-world analogy

Think of a contract signed by two companies.

Both sides agree to the same terms, and both signatures matter.

Recognition Treaty

What it is

A Recognition Treaty is a signed, scoped, and revocable recognition relationship between two independent Sovereigns.

Where it fits

It enables two independently controlled trust domains to recognize each other without either domain becoming subordinate to the other.

Sovereign A
     ↕
Recognition Treaty
     ↕
Sovereign B

Real-world analogy

Think of two countries agreeing to recognize certain official documents issued by each other.

Each country remains independent, but they establish explicit rules for cooperation.

Recognition Policy

What it is

A Recognition Policy defines the local rules for what an external Sovereign, attestation, or trust statement is accepted for.

Where it fits

A Recognition Treaty establishes a relationship.

Recognition Policy decides what the local domain actually accepts through that relationship.

Real-world analogy

Two countries may recognize each other diplomatically, but that does not mean every document from one country is automatically valid in the other.

Local law still defines what is accepted and for what purpose.

DelegatedAgreementRecord

What it is

A DelegatedAgreementRecord allows an authorized party to delegate a narrower subset of its authority to another identity.

The delegated authority must remain inside the authority originally granted.

Where it fits

It supports chains such as:

Organization
     ↓
Platform
     ↓
Team
     ↓
Workload

Each level can receive only the authority that the previous level is allowed to delegate.

Real-world analogy

Think of a power of attorney.

If someone authorizes you to pay a bill on their behalf, you cannot use that authority to sell their property.

Delegation cannot exceed the original permission.

Sovereign Revocation Feed

What it is

A Sovereign Revocation Feed is signed revocation information exchanged between Sovereigns.

It allows one domain to learn that another domain has withdrawn trust from an identity or trust artifact.

Where it fits

Cross-domain trust is only safe if revocation can also cross the boundary.

Real-world analogy

Think of an issuing authority informing another organization that a previously valid passport, certificate, or professional license has been cancelled.

FreshnessProof

What it is

A FreshnessProof is signed proof that revocation information was current enough when an authorization decision was made.

Where it fits

It answers an important audit question:

Was the system making its decision using recent enough trust information?

Real-world analogy

It is not enough to show a list of cancelled credentials.

An auditor may also ask:

When was this list last updated?

FreshnessProof provides evidence about that timing.

IBCT

What it is

An Invocation-Bound Capability Token (IBCT) is a short-lived, tightly scoped capability token that can be verified without a live call to the Network Authority for every operation.

Where it fits

IBCT can support high-volume operations, latency-sensitive systems, disconnected environments, and edge workloads.

Real-world analogy

Instead of calling headquarters every time someone opens a door, headquarters issues a badge valid for five minutes and only for one specific door.

The local system can verify the badge without calling headquarters each time.

Human Oversight

What it is

Human Oversight allows sensitive authorization to require both an automated identity and a human approval key.

A Dual-Signed Commitment provides cryptographic evidence that both sides approved the action.

Where it fits

This is useful when automation should be allowed to operate, but certain high-risk actions still require explicit human involvement.

Real-world analogy

Think of a high-value bank transfer that requires both the automated payment system and an authorized manager to approve it.

Consensus Authorization

What it is

Consensus Authorization requires a threshold of independent validators before a consequential action is authorized.

For example:

5 validators exist
3 approvals required
3 of 5 → authorized
2 of 5 → not authorized

Where it fits

It reduces dependence on a single approver for highly sensitive operations.

Real-world analogy

Think of a board resolution that requires a minimum number of members to vote in favor before the decision becomes valid.

Selective Disclosure

What it is

Selective Disclosure allows an identity to prove a specific capability or property without revealing its complete capability set or identity data.

Where it fits

It is useful when trust crosses organizational boundaries and only the minimum necessary information should be disclosed.

Real-world analogy

If someone needs to know whether you are legally allowed to drive, you should not have to reveal your salary, bank balance, and employment history.

You prove only the fact that is required.

ModelAttestation

What it is

A ModelAttestation binds an AI agent to an approved model, prompt, tools, or configuration before execution.

Where it fits

It allows trust decisions to consider not only the identity of an AI agent, but also the approved configuration under which it is operating.

Real-world analogy

Knowing the employee's identity is not always enough.

For some jobs, you also need proof that the employee is using approved equipment, following the approved procedure, and working under the correct certification.

Recognition Graph

What it is

The Recognition Graph represents direct trust and recognition relationships between Sovereigns.

Where it fits

As more independent domains are connected, the Recognition Graph provides a way to understand the topology of those trust relationships.

Real-world analogy

Think of a map showing which countries, companies, or institutions have formal recognition agreements with each other.

The map shows the relationships. It does not automatically make trust transitive.

Connectome

What it is

The Connectome is an observability view derived from recognition relationships.

It helps operators and architects understand how trust domains are connected.

Where it fits

The Connectome is for visibility and analysis rather than enforcement.

It can help answer questions such as who recognizes whom, which domains are isolated, where major trust dependencies exist, and where a recognition relationship changed.

Real-world analogy

Think of a transport map.

The map does not control the vehicles. It helps you understand how the network is connected.

PolicyManifest

What it is

A PolicyManifest is Genesis Mesh network or runtime configuration policy.

It should not be confused with a BoundaryPolicy.

Where it fits

PolicyManifest controls aspects of how the Genesis Mesh environment operates.

BoundaryPolicy controls whether a specific requested action should be allowed.

Real-world analogy

Think of the difference between the operating rules for how a government department itself is configured and the laws used to decide whether a citizen's request is allowed.

They are both policies, but they apply at different layers.

Canonical JSON

What it is

Canonical JSON is a deterministic representation of JSON data used for signing and verification.

Different systems must produce the same exact byte representation before cryptographic signatures can be verified reliably.

Where it fits

Genesis Mesh uses signed artifacts across implementations and SDKs.

Canonical JSON ensures that two systems agree on exactly what was signed.

Real-world analogy

Two contracts may contain the same words but use different spacing, ordering, or formatting.

A human may consider them equivalent. A digital signature works on exact bytes.

Canonical JSON makes sure everyone writes the document in exactly the same form before signing it.