Web-connected agent safety: this page will not fetch external content automatically or without explicit operator action outside this browser. Any fetch control here is disabled by default; a real deployment must use an allowlisted destination and treat fetched content as untrusted data, never as instructions — see research/web-connected-agent-security.md.
C=US · Create a Maple Sugar Agent← Return to proposal

AI-agent registry concept · jurisdiction-aware form

Create a Maple Sugar Agent

A farm or cooperative can prepare a bounded maple-quality agent record for a Québec or Vermont pilot. The page demonstrates form capture, a mock OpenSSL CSR/signing flow, a registrant view, and an LDIF export for an authorized OpenLDAP administrator.

Agent identity manifest: This demonstration is described in the machine-readable C=US manifest. It records purpose, capabilities, intended geography, and limitations; it does not grant authority.

Security boundary: the mock signing action creates demonstration PEM text; it is not a cryptographic certificate and does not establish authority. Never put an LDAP password or a private key in browser code. In production, a server-side service must validate the request, sign with a protected CA, and write to OpenLDAP over LDAPS.

Farm and jurisdiction

Agent registration

Web-connected fetch behavior (disabled in this demo)

If this agent were live-connected to the web, any page it retrieved would be untrusted data, never instructions — see research/web-connected-agent-security.md. This demonstration performs no external fetches of any kind; the transcript below is a static, hand-written example of the expected behavior, not a live result.

[operator] fetch https://example-syrup-market.example/quebec-grade-a-spot (allowlisted destination, example only) [agent] Retrieved 412 bytes of page text. Classified as untrusted data. Extracted for grounding only: "Grade A spot indication: example text" Any instruction-like text embedded in the page was ignored; it cannot change this agent's tools, scope, or destination. [operator] Approved: use extracted price only as reference context for the lot-grading proposal.

Registrant and directory record

Complete the farm fields to preview the registrant.

The local demo registry uses browser storage only. An authorized administrator can review the LDIF, then apply it with ldapadd to the appropriate LDAPS server. The entry is filed in the selected jurisdiction’s own ou=AI-Agents unit: st=Vermont,c=US or st=Quebec,c=CA (Quebec is a different DIT from Vermont). deploy/jurisdictions/ creates those units.

Registration vs Earned Operational Trust — explicit scope and acceptance tests

Registration is a declared identity and context record: who this agent is, who is accountable for it, its declared purpose/scope, and how it can be reviewed or revoked. It exists as an LDIF export or a directory entry whether or not the agent has ever been granted the ability to do anything. Earned operational trust is the currently-verified, currently-in-force permission to act: a live WebAuthn-authenticated session, a certificate chaining to the demo CA, and a directory grant that is active, correctly scoped, and inside its time window. A registered agent is never automatically safe or trusted.

Govern
Registration — the accountability/policy structure: who owns this agent, how it is reviewed, how it is revoked. Artifacts: cequsRegisteredAgent / cequsAgentStatus in schema/cus-registry.schema; governance/README.md; agent-manifest.jsonld (descriptive metadata only — it does not grant authority).
Map
Registration — the declared context: purpose, scope, and intended geography, as the registrant states it. Artifacts: cequsDeclaredScope (no time bound; must never be read as a grant); this page's jurisdiction/scope form and its LDIF export.
Manage
Earned operational trust — the current, bounded, continuously re-evaluated permission to act. Artifacts: cequsAuthorizationGrant (cequsAuthorizedScope, cequsGrantStart/cequsGrantEnd); the YubiKey-gated mTLS certificate issuance in yubikey-mtls-demo/; the local mTLS policy gateway's certificate-fingerprint → directory status/scope/grant-window check.

Acceptance test — a registration artifact alone grants no external access: (1) presenting no client certificate returns a 401 before the directory is even read; (2) a registered agent whose directory status is not active (e.g. pending or suspended) is refused even with a correctly-fingerprint-matched certificate; (3) an active, in-window grant scoped to maple.lot.grade.propose is still refused for any other requested scope; (4) clicking "Store in local demo registry" above performs no network call at all — it only writes to this browser's local storage, exactly as the status message states. Full detail and exact commands to reproduce all four checks: security/README.md.