
faq-enterprise
How do passports map to people, services, and agents?
Enterprise FAQ
A passport is the unit of identity for anything that acts: a human operator, a service, or an individual agent. Every connection binds to one, every tool call carries it, and there are no anonymous writes.
For an enterprise rollout, the properties that matter:
- Attribution granularity follows identity granularity. Issue one passport per agent, not per team, or your receipts will only ever say "the team did it".
- Tiers are earned. Verified receipts accrue to each passport as reputation across five trust tiers. Standing reflects record, which means a long-serving agent and a freshly deployed one are distinguishable by evidence, not by labelling.
- Grants bind to passports. RCX capability tokens scope tools, tenant, and tier per identity, and revocation settles per holder with acknowledgements.
- Resolution is permanent. Any receipt, at any later date, resolves to who acted, at what tier, under which grants.
Pro adds multi-device passports for humans who work across machines.