Provenance · Identity · Continuity
Authority continuity at work: a service mesh whose data plane exchanges OAuth at the edge — zero application changes — an AI agent that can propose anything but only cause what the origin authorized, and agents calling agents through a guardrail that cannot be skipped. Watch the execution enter the perimeter. Then compromise it. For the wire-level artifacts behind every step, see the PIC Flows.
execution log
All three use cases run on PIC Profile 0.2 exactly as shown in the PIC Flows:
the mesh data plane, the sandbox, and the services are ordinary PIC workloads — they exchange an authority source
at the realm token endpoint (RFC 8693), carry the settled PIC Token JWT (HTTP binding: the
PIC-Token header), and advance continuity with workload-signed candidates carrying one
PIC Continuity Transition COSE. Applications, agents, and policy engines never implement the
protocol: PIC runtimes and infrastructure components do the construction, exchange, and verification.
The security core is the same everywhere: authority is selected at the origin (C₀), every hop is a
verified non-expansive continuation, invariants can only be removed, and an authority absent from the origin —
an ambient service credential, an injected instruction, a skipped guardrail — is not a valid continuation of the
lineage. The guardrails use case follows the PIC Sandboxed Execution specification (draft 0.2, work in
progress): an outer ENFORCE continuity carries a Composition Collection of independent
lineages, and guardrails are ordinary executors of that outer continuity — no trusted sandbox, no external
guardrail authority. Every value below is illustrative.