C=US← Break/fix correction cycle

Implementing c=US's Accountable-Sponsor Gap Using Utah's Real SEDI Law

This project's own research already named an unclosed gap: a registered agent's sponsor is, today, "a self-asserted cequsSponsor — unverified," in the registrar code's own words. Utah didn't build this project's fix, but it built something that could become one: a real, enacted state law — the State-Endorsed Digital Identity (SEDI) program, Utah Code Title 63A, Chapter 20 — that already does, for human individuals, cryptographically, exactly what that gap is missing.

What SEDI actually is

S.B. 275, State-Endorsed Digital Identity Program Amendments, passed Utah's Legislature unanimously in March 2026 and took effect May 6, 2026, building on a prior 2025 bill (S.B. 260). It is run by Utah's Department of Government Operations and is documented at sedi.utah.gov, with a public implementation guide. Its own Digital Identity Bill of Rights opens like this, in the enrolled statute's own words:

"An individual possesses an individual identity innate to the individual's existence and independent of the state, which identity is fundamental and inalienable."Utah Code § 63A-20-101(1), S.B. 275 (2026), enrolled copy

Two design choices make it structurally interesting for this project specifically:

The role mapping

SEDI names its ecosystem roles precisely enough to line up, almost one-for-one, with the roles c=US's own schema and code already separate (see this project's transitive-trust note):

SEDI role (Utah Code §)What it doesc=US equivalent
Holder / Individual (63A-20-201(20), (14))Creates own identifier; controls disclosure; "the sovereign actor" per the state's own implementation guideThe registered agent's human sponsor, self-asserting cequsSponsor today
Department (Issuer) (63A-20-202/203)Digitally signs, binding attributes to the identifier; role "ends at issuance"; no monitoring of later useThe certified endorser, creating a cequsAuthorizationGrant; also does not control post-grant use
Identity Proofing Entity (63A-20-201(13), 63A-20-303)Authorized by the department to conduct proofing, while the department "retains validation authority"The proposed organizational-endorser extension this project has already discussed (e.g. an employer or sponsoring org vouching for its own agents)
Verifier (implementation guide, Annex G)Cryptographic check of signature, integrity, possessionThe mTLS policy gateway (security/mtls/server.py), checking certificate fingerprint and grant window
Relying Party (Annex G)Consumes the verifier's output to make a trust decisionThe service the agent is actually trying to act against
Digital Guardian (63A-20-201(3), 63A-20-302(2)-(3))Acts on behalf of a minor, incapacitated person, or an individual who designated oneStructurally the closest legal analogue to a human "operating" an AI agent that cannot itself hold identity — see limits below

The walkthrough

  1. A registered agent's sponsor gets SEDI-endorsed, not the agent. Concretely: the accountable human behind a Utah tart-cherry grading agent — the real crop this project uses for its own Utah jurisdiction, rather than reusing the maple framing where it doesn't apply — is the person cequsAccountableSponsor already exists in this project's schema to name. That sponsor applies for their own SEDI, going through Utah's identity-proofing process under rules the department must publish (§ 63A-20-303(4)).
  2. The sponsor's personal digital identifier is recorded in the c=US directory, in cequsAccountableSponsor (a distinguishedNameMatch attribute added to this project's schema specifically so a sponsor claim could eventually be bound to something verifiable, not left as the free-text cequsSponsor field it started as).
  3. An endorser's grant decision can now check a real, state-endorsed, cryptographic assertion that a real human stands behind the agent — selectively disclosed, per SEDI's own right to choose "what identity attributes are disclosed" (§ 63A-20-101(8)), so the sponsor need not expose more than "this named person is SEDI-endorsed and stands behind this agent."
  4. The grant, its window, and its scope stay exactly as they are today — SEDI strengthens who is accountable at the sponsor hop; it does not replace c=US's own endorsement, grant, or gateway-enforcement hops, each of which stays independently checked, per this project's own no-transitive-trust design.
  5. Revocation stays narrow on both sides. SEDI's own revocation is limited to compromise, department error/fraud, or holder request; c=US's endorser-listing revocation is independent of that. A sponsor losing their SEDI doesn't retroactively rewrite a grant already issued and logged — it flags the sponsor hop for review, the same way this project's own attestation log adds a correction entry rather than rewriting history.

The constitutional parallel

Key point

SEDI's own advocates and the state itself describe it as "Utah's constitutional, rights-first framework" — identity as "innate," "independent of the state," "fundamental and inalienable," with the state's power to endorse deliberately narrower than its power to issue or control. That is the same natural-rights logic — rights precede and constrain the state, rather than the state granting them — that this project's own attestation ceremony invoked when its endorser acted "as a private citizen," grounded in the values of the US Constitution, not in any government office. Utah arrived at a materially similar structure independently, as statute rather than as a demonstration project, which is itself evidence the shape isn't idiosyncratic to this project.

And it supplies exactly the kind of external, non-moral backstop the break/fix cycle page's key point describes: SEDI's Duty of Loyalty binds "the department, a digital wallet provider, a verifier, a relying party, and a digital guardian" to refrain from processing an individual's identity attributes in ways that "conflict with the best interests of an individual," "take advantage of or otherwise exploit," or "cause harm" (§ 63A-20-701) — a legal duty enforceable by Utah's Attorney General (§ 63A-20-801), independent of whether any given company, wallet provider, or AI agent in that chain happens to behave well. It is one more concrete instance of the same principle: don't rely on an agent's or a company's moral behavior; rely on a framework external to it that can be checked and enforced regardless.

Where this is honestly incomplete

Real limit, stated plainly

SEDI's own definition is exact: "'Individual' means a human being" (§ 63A-20-201(14)). An AI agent cannot be a SEDI holder, cannot get its own state-endorsed identity under this statute, and nothing above claims otherwise. Everything in this walkthrough runs through the human sponsor, not the agent — which is exactly where c=US's own accountability model already says the buck has to stop.

Utah's own implementation guide is candid that several of its roles — digital wallet providers, verifiers, and relying parties — have no explicit statutory revocation or recognition process yet. That is the same class of unclosed gap this project's own research flagged for its Certified-Endorsers listing: a real design can name a role correctly and still leave its admission/removal process for a later rule.

Nothing here has been built. No code in this repository calls Utah's SEDI program, and no sponsor in this project's fixtures currently holds one. This is a design walkthrough, not a deployed integration.

Sources