Home/Trusted Bot Programme
The Trusted Bot Programme

One authority. One credential. Three levels of assurance.

A bot joins the programme by getting certified, and membership is not a name on a list. It's the full envelope traveling with the bot, and every verification traces back to a single authority.

The AIN

A passport for agents, structured like a UPC.

The Agent Identification Number is readable so it can be checked at a glance, sealed into a signed birth record so it can't be forged, and it binds the real-world identity by hash rather than carrying personal data in the clear. It comes in two tiers: a Build AIN that seals what a release may do, and a Deployment AIN whose reach is a provable subset of it, explained in full under how it works.

Agent Identification Number● Certified
Build AIN · capability envelope
KMC.BLD.acme.1.4.0.9a2f…c71b
↓ ⊆ deployment sealed as a provable subset
Deployment AIN · this running instance
KMC.DPL.acme.0001.4e91…8d3a
Origin  ✓ authenticHistory  ✓ intactManifest  ⊆ envelope
The trust ladder

Identity is the base. Some receivers will want more.

The base AIN certifies who stands behind an agent and that its history is intact. It doesn't claim the agent has been inspected. Each rung is worth more to the receivers who care most, and the rungs are kept distinct so a receiver can always tell which one they're looking at.

01

Identified

The base AIN. A real party stands behind this agent, and its origin is cryptographically authentic.

02

Accountable

Identity plus a tracked, tamper-evident history and behavioral monitoring that watches conduct separately from authenticity.

03

Audited

A deeper examination of what the agent actually does, scoped to what it can affect — from answering questions to moving money.

The audit

The premium rung, for agents that can do real damage.

The base AIN certifies identity and provenance, not capability or intent. It says a real party stands behind this agent and its history is intact. It does not say the agent has been inspected and provably does only what it claims. That deeper assurance is a cyber audit.

Kept separate
The audit is deliberately distinct from the AIN, so a receiver can always tell whether a bot is merely identified or actually audited. Mixing them would blur exactly the distinction that matters.
Scoped to the stakes
What an audit certifies depends heavily on what the bot can affect, from answering questions to making commitments to moving money. It's offered as an optional premium service, performed by MeshKor to start, and priced to the stakes.
Learned, not guessed
The detailed definitions aren't written in stone yet, on purpose. The first few engagements will teach what an audit should certify, rather than committing to a rigid checklist before the practice exists.
Early access

Prove your agents are who they say they are.

MeshKor is in preview. Join the waitlist and we'll reach out as we open enrollment to the first builders.

Join the waitlist →