Implementing c=US's Accountable-Sponsor Gap Using Utah's Real SEDI Law
This project's own research already named an unclosed gap: a registered agent's sponsor is, today, "a self-asserted cequsSponsor — unverified," in the registrar code's own words. Utah didn't build this project's fix, but it built something that could become one: a real, enacted state law — the State-Endorsed Digital Identity (SEDI) program, Utah Code Title 63A, Chapter 20 — that already does, for human individuals, cryptographically, exactly what that gap is missing.
What SEDI actually is
S.B. 275, State-Endorsed Digital Identity Program Amendments, passed Utah's Legislature unanimously in March 2026 and took effect May 6, 2026, building on a prior 2025 bill (S.B. 260). It is run by Utah's Department of Government Operations and is documented at sedi.utah.gov, with a public implementation guide. Its own Digital Identity Bill of Rights opens like this, in the enrolled statute's own words:
Two design choices make it structurally interesting for this project specifically:
- The individual creates their own identifier; the state only endorses it. A "personal digital identifier" must be "created by or at the direction of an individual," "mathematically provable to be under a holder's control," and "transportable to technical infrastructure of the holder's choosing" (§ 63A-20-201(20)). The department's own role, per its implementation guide, "ends at issuance" — it endorses, it does not own or operate, the identifier afterward.
- Revocation is narrow and enumerated, not discretionary. "The department may only revoke an individual's state-endorsed digital identity if: the state-endorsed digital identity has been compromised; the department's endorsement was issued in error or based on fraudulent information; or the holder requests" it (§ 63A-20-301(5)). Nothing else qualifies.
The role mapping
SEDI names its ecosystem roles precisely enough to line up, almost one-for-one, with the roles c=US's own schema and code already separate (see this project's transitive-trust note):
| SEDI role (Utah Code §) | What it does | c=US equivalent |
|---|---|---|
| Holder / Individual (63A-20-201(20), (14)) | Creates own identifier; controls disclosure; "the sovereign actor" per the state's own implementation guide | The registered agent's human sponsor, self-asserting cequsSponsor today |
| Department (Issuer) (63A-20-202/203) | Digitally signs, binding attributes to the identifier; role "ends at issuance"; no monitoring of later use | The certified endorser, creating a cequsAuthorizationGrant; also does not control post-grant use |
| Identity Proofing Entity (63A-20-201(13), 63A-20-303) | Authorized by the department to conduct proofing, while the department "retains validation authority" | The proposed organizational-endorser extension this project has already discussed (e.g. an employer or sponsoring org vouching for its own agents) |
| Verifier (implementation guide, Annex G) | Cryptographic check of signature, integrity, possession | The mTLS policy gateway (security/mtls/server.py), checking certificate fingerprint and grant window |
| Relying Party (Annex G) | Consumes the verifier's output to make a trust decision | The service the agent is actually trying to act against |
| Digital Guardian (63A-20-201(3), 63A-20-302(2)-(3)) | Acts on behalf of a minor, incapacitated person, or an individual who designated one | Structurally the closest legal analogue to a human "operating" an AI agent that cannot itself hold identity — see limits below |
The walkthrough
- A registered agent's sponsor gets SEDI-endorsed, not the agent. Concretely: the accountable human behind a Utah tart-cherry grading agent — the real crop this project uses for its own Utah jurisdiction, rather than reusing the maple framing where it doesn't apply — is the person
cequsAccountableSponsoralready exists in this project's schema to name. That sponsor applies for their own SEDI, going through Utah's identity-proofing process under rules the department must publish (§ 63A-20-303(4)). - The sponsor's personal digital identifier is recorded in the c=US directory, in
cequsAccountableSponsor(adistinguishedNameMatchattribute added to this project's schema specifically so a sponsor claim could eventually be bound to something verifiable, not left as the free-textcequsSponsorfield it started as). - An endorser's grant decision can now check a real, state-endorsed, cryptographic assertion that a real human stands behind the agent — selectively disclosed, per SEDI's own right to choose "what identity attributes are disclosed" (§ 63A-20-101(8)), so the sponsor need not expose more than "this named person is SEDI-endorsed and stands behind this agent."
- The grant, its window, and its scope stay exactly as they are today — SEDI strengthens who is accountable at the sponsor hop; it does not replace c=US's own endorsement, grant, or gateway-enforcement hops, each of which stays independently checked, per this project's own no-transitive-trust design.
- Revocation stays narrow on both sides. SEDI's own revocation is limited to compromise, department error/fraud, or holder request; c=US's endorser-listing revocation is independent of that. A sponsor losing their SEDI doesn't retroactively rewrite a grant already issued and logged — it flags the sponsor hop for review, the same way this project's own attestation log adds a correction entry rather than rewriting history.
The constitutional parallel
SEDI's own advocates and the state itself describe it as "Utah's constitutional, rights-first framework" — identity as "innate," "independent of the state," "fundamental and inalienable," with the state's power to endorse deliberately narrower than its power to issue or control. That is the same natural-rights logic — rights precede and constrain the state, rather than the state granting them — that this project's own attestation ceremony invoked when its endorser acted "as a private citizen," grounded in the values of the US Constitution, not in any government office. Utah arrived at a materially similar structure independently, as statute rather than as a demonstration project, which is itself evidence the shape isn't idiosyncratic to this project.
And it supplies exactly the kind of external, non-moral backstop the break/fix cycle page's key point describes: SEDI's Duty of Loyalty binds "the department, a digital wallet provider, a verifier, a relying party, and a digital guardian" to refrain from processing an individual's identity attributes in ways that "conflict with the best interests of an individual," "take advantage of or otherwise exploit," or "cause harm" (§ 63A-20-701) — a legal duty enforceable by Utah's Attorney General (§ 63A-20-801), independent of whether any given company, wallet provider, or AI agent in that chain happens to behave well. It is one more concrete instance of the same principle: don't rely on an agent's or a company's moral behavior; rely on a framework external to it that can be checked and enforced regardless.
Where this is honestly incomplete
SEDI's own definition is exact: "'Individual' means a human being" (§ 63A-20-201(14)). An AI agent cannot be a SEDI holder, cannot get its own state-endorsed identity under this statute, and nothing above claims otherwise. Everything in this walkthrough runs through the human sponsor, not the agent — which is exactly where c=US's own accountability model already says the buck has to stop.
Utah's own implementation guide is candid that several of its roles — digital wallet providers, verifiers, and relying parties — have no explicit statutory revocation or recognition process yet. That is the same class of unclosed gap this project's own research flagged for its Certified-Endorsers listing: a real design can name a role correctly and still leave its admission/removal process for a later rule.
Nothing here has been built. No code in this repository calls Utah's SEDI program, and no sponsor in this project's fixtures currently holds one. This is a design walkthrough, not a deployed integration.
Sources
- Utah S.B. 275, State-Endorsed Digital Identity Program Amendments, enrolled copy: le.utah.gov/Session/2026/bills/enrolled/SB0275.pdf — all Utah Code section quotes above were read directly from this PDF.
- Utah's own program site and implementation guide: sedi.utah.gov, Annex G: Roles and Actors.
- Secondary explainer (not a primary source, used only for context): Spruce ID, "Utah SB 275 Explained".
- This project's own transitive-trust-and-endorsement-chains.md and
schema/cus-registry.schema(cequsAccountableSponsor,cequsSponsor). - The real Utah agent this walkthrough uses: Create a Utah Tart Cherry Grading Agent, targeting the
st=Utah,c=USjurisdiction node added for it (deploy/jurisdictions/utah.ldif).