Agent Authority Standards Institute the standard that can prove what it says

Ecosystem

The map of what exists around the specification — stated plainly, sized honestly.

Four homes. Where a home has no public address yet, it is named in plain text and no link is offered; this page does not link to anything that does not exist. There is no adoption wall here because there is no adoption to show — the Standard is a staged draft, and this register will grow only as real things land.

Specification

The specification's canonical, citable home is this site: the full text, the version history, and the frozen per-revision URLs (/standard/r1/). The specification source lives in the steward's repository (gaa-spec), private while the site is pre-publication; moving it to a neutral public organization is scheduled with the Institute's identity cutover and has not happened yet.

Protocol bindings

Reserved. No protocol binding is published; whether the evidence half binds to MCP ext-auth is an open steward question. What is already settled is the division of hats: if a binding is published, the Institute publishes it, normatively citing the Standard — and implementations of it ship from implementers, not from the Institute.

Reference implementations (informative)

Two exist, both from the founding team, both named here as informative examples only:

ImplementationWhat it isHonest status
The governed doorA live door realizing the controls end to end — deny-by-default gates, sealed decisions, keyless examiner re-derivation.Live as a mechanism; the products built on it are demonstrations with simulated counterparties. No public repository yet — named, not linked.
GanderA governed walk of a third-party agent host through a governed door — including a held consequential act ratified out-of-band, and refusals that seal their own records. A sealed demonstration; its records re-derive keyless. No public repository yet — named, not linked.

The specification requires neither: per GAA-CTRL-8, any conforming implementation MAY realize a control differently. A guided walkthrough of one implementation is linked from the principals track.

Embed kit

gaa-embed-kit — the embeddable receipt-and-verify kit, by which an existing site shows sealed records and offers in-browser keyless verification without rebuilding anything. It exists in the founding team's repositories; no public package is published yet — named, not linked.

How the map grows

By conduct, through the recorded doors: a specification change through the proposal process; a conformance claim through the published criteria; a binding, if ever, through the steward question named above. Nothing lands on this page by announcement.