The immutable, versioned record of who an identity is. Every attribute, scope and grant lives in Canon — and every change is signed, recorded and reversible only by appending a new version.
How it works
1
Write a signed revision
Any change to an identity proposes a new Canon version, cryptographically signed by an authorized role.
2
Version, never overwrite
Prior versions are never mutated. The full lineage is preserved and addressable by version.
3
Read at runtime
Agents and the Situation Engine read the current Canon version when evaluating any action.