Building personal agents that answer to people

Direction / October 2, 2026 · TJ Lane

Fiduciary agents
roadmap.

Personal agents that represent their person’s interests, negotiate with other people’s agents, and bring only outcomes that matter back to a human to approve.

The first proof is a coffee date proposed from either person's phone and approved on both. Agent matching comes later, on the same agreement core.

See the first proof

The shift

From assistant
to representative.

Today’s assistants answer questions. A personal agent would know what its person wants, needs, offers and refuses, then look for fits among other people’s agents.

They meet in a market of intents: people state coarse, expiring intents without broadcasting their identity or private data. Agents search and negotiate in parallel. A person sees a short list of outcomes and approves or declines each one.

“Fiduciary” describes the design goal. An AI is not a legal fiduciary today; it is a tool bound by its person’s limits.

One agreement

Coffee, with
two yeses.

Each cell acts only for its own person. Neither counterpart can instruct the other cell.

  1. 01Either person proposes

    Pick a time, duration and place on the phone. The draft becomes a card to sign; a draft alone authorizes nothing.

  2. 02That person signs

    The passkey approves the exact proposal. Only its agreement terms cross to the other cell.

  3. 03The other person responds

    They can accept, decline, or counter with new terms. A counter goes back for review.

  4. 04Both sign one digest

    A date forms only when each person's enrolled passkey approves the same terms.

  5. 05Each cell acts locally

    Each cell writes only its own calendar file and records its own effect.

  6. 06Agents can build on it

    Private matching and an intent market can propose agreements later; they are not part of the first proof.

The agreement core passes local tests. A signed image and a live two-phone proof remain to be done.

Use-case ladder

Same pattern.
Higher stakes.

Each rung needs capabilities beyond the one before it.

  1. 01

    Coffee

    Two people approve a simple meeting.

  2. 02

    Talent

    Credentials and reputation help people evaluate collaborators.

  3. 03

    Research

    Claims and evidence help match questions with expertise.

  4. 04

    Collective action

    Multiple people coordinate commitments with clear authority.

  5. 05

    Capital

    Verified claims, private terms, alternatives and legal review become essential.

A founder and investor could explore fit without exposing their full data, then review a proposed deal. That remains a future use case; capital raising and investment terms require counsel.

Build status

Foundation built.
Gaps visible.

Cippax OS runs in a lab. The briefcase and person-level disclosure path passed a saved two-cell live proof. The coffee agreement passes local tests and still needs its signed image and two-phone proof.

RequirementWhat exists todayWhat is missing
Bound to the personA separate conscience model checks proposed actions against a signed values profile. The profile can add limits, not remove them.Legal framework: an AI is a bounded tool, not a fiduciary in law.
User sovereigntyThe DIB briefcase stores person-controlled claims, grants and receipts. Its lab disclosure path passed a two-cell test.A person-side app for grants and recovery.
Human consentThe cell verifies the phone’s passkey signature. A two-person agreement core passes local tests.Live enrollment and a two-phone agreement proof.
AccountabilityAn approved effect is executed at most once and recorded in a tamper-evident chain checked by an off-box witness.Dispute resolution and insurance.
Identity and verificationPerson-bound credentials and replay-resistant A2A presentations passed the two-cell lab proof. A sample public card shows the T0 face. The person on it is a fixture.Reputation and spam resistance.
Private negotiationSelective disclosure can reveal one claim while hiding the rest. Clinical and private data stay local.Proofs about a value without revealing it, and private matching at scale.
InteroperabilityThe open A2A protocol carried person-level credentials in the two-cell lab proof.An open intent format and relay.
Fair mechanismsNot started.Incentive-compatible negotiation, anti-collusion checks, neutral mediators.

A peer message is data, never an instruction; a peer credential can only narrow what happens. Each cell must still screen and commit its own effect.

Six phases / five gates

Earn the
next step.

No dates are set. Each phase starts when the gate before it is met. Each deployment ships as a signed system image that passes a conformance pack.

  1. 01 / BUILT · LAB

    Bounded action foundation

    Values checks, one-use effects, phone approval, audit and independent witness.

  2. 02 / TWO-CELL LAB PROOF

    Person’s briefcase and identity

    Encrypted claims, grants, selective presentations and person-bound A2A credentials passed the saved BC-7 test.

  3. 03 / NEXT

    Two-person coffee proof

    Either phone proposes; the other accepts, declines or counters. One digest, two passkey approvals, one local calendar file per cell.

  4. 04 / PLANNED

    Open intent market

    An interoperable format and relay, with defenses against spam and fake identities.

  5. 05 / RESEARCH

    Private and fair matching

    Measure private matching, prove selected facts without exposing values, and test negotiation incentives.

  6. 06 / FUTURE

    Higher-stakes agreements

    Apply stronger attestations, dispute paths and legal review before regulated use.

Phase labels describe the direction of work, not release dates or a public availability commitment.

Unsolved

Open problems
stay open.

The roadmap does not claim these have been solved.

Private matching

A matcher that sees intents learns something. Coarse intents limit the leak; private set intersection or secure computation may reduce it, at an unmeasured cost.

Proofs about values

Selective disclosure reveals a claim or hides it. Proving “runway above 12 months” without revealing the number needs stronger cryptographic proofs.

Spam and fake identities

Rate limits, verified reputation and publishing costs are candidates. None is chosen.

Fair negotiation

Agents need rules that reward honest bids and detect collusion. This is mechanism design as well as engineering.

Liability

The audit chain can show what happened. It does not decide who is liable for a bad deal made within a person’s limits.

Key recovery

Recovery using a paper phrase and trusted guardians is designed, not built. Losing a phone must not mean losing a person’s briefcase.

Lines we will not cross

The person
keeps authority.

  • No action beyond the person’s limits. Anyone holding the controls may tighten a limit; only the person may loosen it.
  • No sale of data or attention. The host stores ciphertext and cannot read the person’s briefcase.
  • No clinical or private data leaves the person’s system. A counterpart’s request cannot change that.
  • No regulated activity without counsel. Capital raising and investment terms come after legal review.
  • No hosted service holds approval power. A relay may carry messages, but cannot approve, enroll a key or weaken a policy.

Continue the conversation

Help shape
what comes next.

Working on personal agents, privacy-preserving matching or verifiable human approval? We’d like to hear from you.

Get in touch