Once the principal has signed a permission, the agent signs a receipt
for each action, naming the permission and the receipt before it. The
recorder writes each receipt, with any countersignature and approval,
as one log line, and now and then appends a time-stamped signed tree
head. This example follows the demonstration published with [FORMAT]; the
parties and orders are invented. An office agent may order supplies up
to 200 GBP in total and 100 GBP for one order, and send two messages in
any hour. Every order needs the supplier's countersignature, and an
order above 60 GBP the principal's approval. The permission's content
is shown with spaces and line breaks added, and values abbreviated:¶
{"actions": ["supplies.order", "message.send"],
"agent": {"keys": ["<Ed25519>", "<ML-DSA-87>"], "name": "Agent"},
"id": "<base64url>",
"issuer": {"key": "<ES256>", "name": "A. Person",
"origin": "https://sign.example.org", "rpId": "example.org"},
"limits": [
{"action": "supplies.order", "max": 200, "unit": "GBP"},
{"action": "supplies.order", "each": 100, "unit": "GBP"},
{"action": "message.send", "count": 2, "per": 3600}],
"never": ["destroys", "impersonate"],
"purpose": "Keep the office stocked with paper and toner.",
"requires": [
{"action": "supplies.order", "need": "countersignature"},
{"above": 60, "action": "supplies.order", "need": "approval",
"unit": "GBP"}],
"type": "provared.slip.v0",
"validFrom": "2026-10-05T09:00:00Z",
"validUntil": "2026-10-12T09:00:00Z",
"with": [{"id": "supplier", "keys": ["<Ed25519>", "<ML-DSA-87>"],
"name": "Example Stationery"}]}
¶
The log then holds these entries ("receipt n" has "seq" n; "cs" is a
countersignature):¶
Entry Record Action, amount With it Total Findings
0 permission
1 receipt 0 order, 45 GBP cs 45
2 receipt 1 message
3 receipt 2 order, 80 GBP approval, cs 125
4 receipt 3 order, 25 GBP 150 countersignature-
missing
5 receipt 4 order, 80 GBP cs 230 over-limit,
approval-missing
6 signed tree head time-stamp
¶
The content of the receipt at entry 5, shown across lines, is:¶
{"action":"supplies.order","amount":{"unit":"GBP","value":80},
"id":"<base64url>","previous":"<digest of the receipt at 4>",
"seq":4,"slip":"<digest of the permission>",
"type":"provared.stub.v0","when":"2026-10-05T09:40:00Z",
"with":"supplier"}
¶
Given the principal's key thumbprint, the recorder's key-set digest and
the TSA's certificate digest, a verifier finds no problem and verifies
every signature: the log is intact. It reports that the agent did not
stay within its permission, at entries 4 and 5.¶