Skip to content
Dossier · Direction

The authority algebra

Capability is the only authority - and authority can only ever get smaller

Updated 2026-09-0711 min readEdition preview-01Internal records, not an external audit

01Update log

Direction, not capability. This dossier describes where the architecture is going. Only the rows marked proven today in its claim table exist on the local line; everything else is research, planned or reserved, and nothing here is a public network, a service or a product.

Update log

  • 7 September 2026 - First edition. Drawn from the era and power map, the White Paper's fifth law and earned-capability lifecycle, the Yellow Paper's capability object, and the architecture programme's chapters on authority dormancy and decay and on duty delta. Object names are given as the shape of the design; their fields are not.

Short answer

The White Paper's fifth law: "Capability is the only authority. There are no roles in FxChain - no validator role, no admin, no gateway role, no sentinel role. Only sealed, scoped, expiring, revocable capabilities with provenance." Everything else in the authority algebra is what that sentence requires.

An authority is defined by its typed admissible effect set - "all effect graphs authority A can still authorise". From that definition the algebra follows. One authority is smaller than another when its effect set is a subset. Constraints compose by a typed meet, and a composition that cannot be compared is reported as unestablished or incomparable, never forced into a numeric minimum. A safe composition may narrow amount, asset, counterparty, venue, jurisdiction, time, usage, fee, proof floor or irreversibility; it cannot add a coordinate or widen one.

Two things are kept apart that ordinary systems merge: permanent power - issued, active, derated, then consumed, expired, revoked or superseded - and temporary eligibility - eligible, held, conflicted, unestablished. An external risk claim "never becomes canonical truth, never expands authority, and never rewrites the grant"; it may only constrain exercise through a policy declared in advance. And every change of authority must compute the duties it creates or breaches: "authority delta without duty delta is incomplete; power without an accountable causal path is ineligible."

On the local line this is not only design. The fourth era admitted "a named, counted authority" that could be "represented and exhausted inside its crossing" while denying ambient authority and delegation by implication; the fifth era spent a small set of motion keys once each and sealed the receipts. Those are the algebra's first two theorems, proven as acts.

What is established, what is in development, what is not claimed

Claim Status Basis Limit
A named, counted authority represented and exhausted inside its crossing, with ambient authority and delegation by implication denied Proven today Era and power map, fourth era One bounded act; not a reusable authorisation service
Motion keys spent once, in three constitutional groups, with receipts sealed and no standing right to move Proven today Era and power map, fifth era Evidence that powers were spent, "not a reusable execution API"
One persistence authorisation exhausted on one artifact Proven today Era and power map, sixth era One artifact
Mandates declared with scope, expiry and proofs, and judged before execution Proven today (as declared meaning) FxIntent and FxCore specifications Local line; mandates as declared constraints, not a capability registry
Capability as the only authority: sealed, scoped, expiring, revocable, with provenance Research White Paper, fifth law; Yellow Paper, capability object Design
Authority defined by its typed admissible effect set, with subset ordering and typed-meet composition Research Architecture programme, authority chapter Design
Permanent power separated from temporary eligibility, with derating never restored except by new issuance Research Architecture programme Design
Risk claims as attributed evidence that may constrain exercise, never expand a grant; integer tiers, never floating-point formulas in consensus Research Architecture programme Design
Duty delta for every authority change, with liability called legal only when an instrument supports it Research Architecture programme, duty delta Design
The earned-capability lifecycle at runtime: powerless twin, vectored, audited, sealed, activated fail-closed Research White Paper, inventions Design
Emergency power envelopes and temporal authority profiles Research Architecture programme, object catalogue Design; shape only
Any role, admin, privileged channel or live authority on a network Not claimed White Paper; every era None exists

No roles

The absence of roles is not a stylistic preference; it is what makes the rest of the algebra possible. A role is authority by status: a validator may because it is a validator; an admin may because it is an admin. Status has no effect set, no expiry and no provenance, so nothing about it can be narrowed, spent or audited. A capability has all three.

The Yellow Paper's capability object gives the shape: a holder, a scope, a policy, a denial set, an expiry, stake terms, provenance - the crossing that created it - and a lifecycle state. The White Paper's lifecycle says how one comes to exist: "observed as a powerless twin, vectored, audited, sealed, then activated scoped, expiring, revocable and fail-closed. Power withheld: no actor holds authority by status; all authority has provenance, boundary and expiry."

   role (status)                        capability (object)
   +---------------------+              +------------------------------------+
   | "is a validator"    |              | holder . scope . policy            |
   | no effect set       |    vs        | denial set . expiry . stake terms  |
   | no expiry           |              | provenance (the crossing)          |
   | no provenance       |              | lifecycle state                    |
   +---------------------+              +------------------------------------+
   cannot be narrowed, spent            can be narrowed, spent, revoked,
   or audited                           audited and explained

Figure 1 - Why there are no roles. Only the right-hand object has anything the algebra can operate on.

The line's own history is the precedent. The fourth era's admitted power is "a named, counted authority", and its denied column reads "ambient authority, delegation by implication, consensus authority, finality, open-ended execution". Counted, named, exhausted inside its act: that is a capability before the word.

Authority as an effect set

The architecture programme's definition is short enough to quote whole: "Define authority by its typed admissible effect set: the power of an authority is all effect graphs it can still authorise; one authority is at most another iff its power is a subset of the other's."

Everything follows from "still". Authority is a remaining quantity. Using it consumes it; time reduces it; a dormancy policy may reduce it further; nothing restores it except a new issuance. And because authority is a typed set, composition is a typed meet, not arithmetic:

   A1 (amount, asset, venue, time)   meet   A2 (amount, jurisdiction, time)
        |                                        |
        +------------------ typed meet ----------+
                                |
              +-----------------+------------------+
              |                 |                  |
        narrower on       EMPTY (nothing        CONFLICTED or
        shared coords     left to authorise)    UNESTABLISHED or
        only                                    INCOMPARABLE

Figure 2 - Composition by typed meet. Coordinates may be narrowed; none may be added or widened; incomparable dimensions are reported, never averaged.

"Never force incomparable dimensions into a numeric minimum." Two authorities expressed in different units, scales or models do not have a smallest; the algebra says so instead of inventing one.

Permanent power and temporary eligibility

The programme separates two lifecycles that most systems collapse into "allowed / not allowed".

Power is permanent in the sense that it moves only one way: issued, then active, then possibly derated and further derated, and finally consumed, expired, revoked or superseded. "Permanent derating may use only a finalised, applicable, canonically ordered risk decision." Nothing climbs back up.

Eligibility is temporary: eligible, held, conflicted or unestablished. A hold is not a loss of power; it is a pause on its exercise. "An improved risk claim may clear an authorised hold. It may not restore consumed or derated power; widening requires a new issuance. A challenged raw assertion defaults to its profile's typed hold behaviour, never permanent destruction."

   POWER (one way)                       ELIGIBILITY (reversible)
   issued -> active -> derated -> ...    eligible <-> held
                 \                                  \-> conflicted
                  -> consumed | expired |            \-> unestablished
                     revoked | superseded
   nothing restores power except         a better claim may clear a hold;
   a new issuance                        it may not widen power

Figure 3 - Two lifecycles, deliberately separate. A risk signal can pause; only an issuance can grant.

Risk as evidence, never as governor

Institutions run on risk scores, and risk scores are exactly the kind of input that quietly becomes authority. The programme's rule: "An external risk claim never becomes canonical truth, never expands authority, and never rewrites the grant. It may only constrain exercise through a predeclared deterministic policy whose inputs, attestors, freshness, challenge path, stale-input behaviour, and fail-open/fail-closed mode are committed in advance."

Three consequences carry weight. First, "the risk attestor's ability to constrain exercise is itself power" - so the attestor's subject, domain, model range, jurisdiction, maximum derating, maximum hold, validity, challenge and supersession must all be declared, and its observations recorded with the same care as any receipt. Second, "consensus paths use integer, fixed-point, or enumerated tiers, never continuous floating-point risk formulas"; scores from incomparable models "remain incomparable". Third, "a risk signal is attributed evidence, not an autonomous governor" - the design must model a compromised attestor's denial of service, bounded quarantine, appeal and replacement.

The programme lists the hostile corpus the design must survive, and the list is a catalogue of how risk systems are gamed: baseline poisoning, score-direction inversion, model or scale swap, stale favourable replay, adverse-score withholding, correlated attestors, backdating, concurrent consumption, authority-recharge attempts, overbroad scope, retroactive policy, double-counting one event across dimensions.

Every change of power carries a duty

The algebra does not end at the holder. "For every authority or power change, compute the corresponding created, transferred, satisfied, breached, expired, or disputed duties." The programme separates an acyclic causal provenance graph of events from a responsibility graph that may contain cycles - guarantees, indemnities, recourse, disputes - and emits a typed liability disposition: declared, contractually bound, legally established, contested, unestablished, or not applicable. "Call it legal liability only when a referenced legal instrument supports that conclusion."

   authority delta  ---->  duty delta (created . transferred . satisfied .
        |                                breached . expired . disputed)
        |
        +--> without a duty delta ........ INCOMPLETE
        +--> without an accountable
             causal path ................ INELIGIBLE

Figure 4 - Power and duty move together. The two lines at the bottom are stated as laws of the programme.

This is where the agent-under-mandate scenario on the Institutions page comes from: an agent's key is not its authority; its mandate is a capability with scope, amount and time; when the mandate is exhausted the key still works and the authority is gone; and the duty of whoever issued the mandate is computed with it.

What the authority algebra does not do

  • It grants nothing today. The local line has exhausted a handful of counted authorities as sealed acts; it runs no capability registry and no live authority.
  • It never widens. A risk claim, a status, an urgency or an improved score can pause or narrow; only a new issuance can grant.
  • It does not average. Incomparable dimensions are reported as incomparable.
  • It does not call anything legal liability without an instrument.
  • Emergency power envelopes, temporal authority profiles and attenuation receipts are named in the programme's catalogue; they are shape, not implementation.

Verdict

The authority algebra is the fifth law made operational: no roles, only capabilities; authority as the effects a holder may still cause; composition by narrowing, never by addition; power that only descends, eligibility that may pause it; risk as evidence with declared power of its own; and a duty computed for every change. What exists on the line is small and exact - counted authorities spent once, inside their crossings, with the denied column longer than the admitted one - and it is the algebra's proof that the direction is not a slogan: the first authorities FxChain ever exercised were already the kind that can only get smaller.

Frequently asked questions

Who is the admin of FxChain?

Nobody, by law. There are no roles; there are capabilities with provenance, scope and expiry. Governance acts are themselves capabilities exercised under the acceptance discipline.

Can a good risk score unlock more?

No. It may clear a hold that a bad score placed. It cannot restore consumed or derated power and cannot widen a grant; widening requires a new issuance.

What happens when two constraints cannot be compared?

The composition is reported as incomparable or unestablished. The algebra refuses to force a numeric minimum between dimensions that have none.

Does an AI agent get special treatment?

None in either direction. It holds capabilities like any other holder, its mandate is bounded like any other, and the White Paper says proposals may come from bounded AI agents "never a privileged channel".

What exists today?

The sealed acts of the fourth, fifth and sixth eras: counted authorities represented and exhausted inside their crossings, motion keys spent once, one persistence authorisation spent on one artifact. Everything else in this dossier is design.

Sources and methodology

Drawn from the era and power map, the White Paper's laws and earned-capability lifecycle, the Yellow Paper's capability object, and the architecture programme's chapters on authority dormancy, decay and risk-conditioned exercise and on duty delta and causal accountability. Quotations are from those sources. Implementation claims are limited to the sealed acts the map records; design claims carry the status research.

The papers and the programme are not published on this portal and are not reproduced here; objects are reported as the shape of the design, and their fields are not. Figures shown anywhere on this portal come from a single dated snapshot; none are introduced by this dossier.

Related reading: FxIntent for mandates as declared meaning; FxCore for admissibility; Institutions for the agent-under-mandate scenario; Six axes, never one status.

Discuss a mechanism

Bring a bounded subject, its method and the evidence you want examined. An enquiry does not grant a licence, a production endpoint or a delivery date.