0:00 Cole Davis | Contract Credentials & Verifiable Identity | KERI Conference 2026
0:02 Hey everyone. I'm Cole Davis. I am
0:05 the founder of Switchchord, which is a
0:09 music, we're legal tech and digital
0:12 identity company building products
0:14 in the music industry. That is one
0:16 brand under sort of an IP holding
0:18 company we have called Steamroller
0:20 Systems that is industry agnostic to
0:22 apply machine learning and
0:26 decentralized identity techniques to
0:28 legal workflows. So we kind of blend
0:30 the worlds of legal tech and digital
0:32 identity primarily using
0:34 decentralized identity. And I'm going to
0:38 talk today though not about music
0:39 because I always talk about music and I
0:40 wanted to change it up. And today I'm
0:42 going to talk about, I call these
0:45 things, contract credentials. So I've for
0:47 years advocated that legal contracts and
0:51 and verifiable credentials should be
0:53 sort of married together like a legal…
0:56 like I wanted to create a dual root of
0:59 trust like a legal root of trust and a
1:01 cryptographic root of trust and I want
1:02 them to be inherent in everything you
1:05 do when you prove you have contractual
1:07 authority. So I spent years looking for
1:09 solutions starting in the blockchain
1:11 world and then the W3C DID VC world
1:14 discovered KERI in 2021 and finally was
1:18 like that's what I need. Primarily
1:20 because it doesn't require like an
1:22 underlying ledger. I can get into why
1:26 the Switchchord stack is built the way
1:28 it is but for now I'm just going to
1:30 focus on the general concept. And then I
1:33 did a demo in the real estate industry
1:35 because it tends to be easier to
1:37 understand and you don't need a whole
1:38 lot of like domain specific knowledge
1:40 about music to really appreciate it.
1:43 Because you apply the tech anywhere,
1:45 anywhere you have a legal contract or
1:47 contractual authority or contractual
1:48 relationship you can apply this
1:51 framework to it. So that's what we're
1:54 going to talk about today.
1:57 Credentials a lot of times at IIW
1:59 and the W3C and the KERI community, we
2:01 talk about credentials proving who you
2:04 are. You know, you're a human. You're an
2:07 organization. I don't often see them
2:10 proving what you have the contractual
2:13 authority to do. It's like not a concept
2:15 that comes easy to people. But when I
2:18 explain this to the music industry, I
2:20 often use the example and this actually
2:21 did start to resonate of a mobile
2:23 driver's license cuz some states have
2:25 mobile driver's licenses and they sit in
2:27 their Apple or Google wallet. So I
2:29 explain, driver's
2:32 license is a credential issued to you
2:34 from an issuer. It has claims about what
2:36 you can do and it's kind of digitally
2:37 signed and you can prove to third
2:39 parties that you have the authority to
2:41 do something. That's easier for
2:43 people to make that mental leap of ..,
2:45 Okay. The contract
2:47 credential is kind of like this, but it
2:48 tells me I can sign documents over 10
2:53 million dollars cuz I have this authority from
2:55 the board of directors or I can enter
2:58 this building because my employer has a
3:01 lease with the building owner and I am
3:03 an active employee with the right to
3:05 enter the premises. What I
3:08 wanted to do was the way a lot of
3:12 people talk about creating like
3:14 verifiable presentations or capturing
3:17 claims from different credentials and
3:18 presenting them about you. Oh, I'm Cole.
3:21 I graduated from TCU. This is my GPA. I
3:24 have this job. Okay, cool. I'm more
3:27 interested in the commercial
3:28 applications of this, as far as
3:29 commercial transactions go. I want to
3:31 be able to say "I'm this organization. I
3:34 have the contractual right to do this.
3:35 I have contractual right to do this."
3:37 I want to be able to pull select from
3:39 different contracts that give me the
3:40 authority to do transactions on a market
3:43 and I want that to be instantly
3:45 verifiable to third parties who want to
3:47 maybe do business with me. Because it
3:50 gets into that Ronald Coase world of
3:52 like transaction cost. How can we reduce
3:53 transaction cost? Verifying
3:55 counterparties and their reputations and
3:58 all that and their authority to do
3:59 things is like really important
4:01 for transaction costs. If you can
4:02 reduce some of this technology, you can
4:04 have more transactions on the market.
4:06 That's what my concept of a contract
4:09 credential is is like "What if they're
4:11 the same thing. What if the contract is
4:13 the credential? Like what if you can
4:14 hold your lease up to the smart lock or
4:16 what if you can [make it the same thing, red], the stock
4:20 option agreement or this stocks
4:23 purchase agreement is the stock
4:25 certificate?" Stop taking the
4:27 contract here and then the authority or
4:29 the thing it represents over here and
4:30 like "No, make them the same thing and
4:33 have a shared cryptographic and legal
4:35 root of trust." That's basically what
4:38 this is. There's an authority
4:40 gap like credentials they don't model
4:43 contracts they live in separate systems.
4:45 You have a contract in your rights
4:46 management system or or contract life
4:48 cycle management system. And then you
4:50 have the operational aspects of the
4:52 contract, what you can do or what you're
4:54 required to do or can't do. Those
4:57 tend to live in different systems. What
4:59 if we collapse them into a single
5:00 system? You know, what if it's all the
5:02 same? Like it's a really weird concept,
5:04 but it's really powerful. And we've been…
5:07 Did you have a… saw hand for just a
5:09 second?
5:09 – I have a question [inaudible].
5:10 What's the difference between a
5:12 credential, a role and the terms that
5:16 the ACDC can define? Is that kind of
5:19 combined or
5:21 [inaudible] there as well?
5:24 It's flexible enough to where
5:26 like the vLEI, ECR and role credentials
5:29 and stuff are sort of derived from this
5:32 whole general technology but it's a
5:33 little more specific. This is more
5:35 general. This is any employment
5:38 relationship, any board granted
5:41 authority, anything can be modeled into
5:44 this framework using ACDC. You can do it
5:46 with W3C VCs too, but there's
5:49 just like limitations there that ACDCs
5:51 give you. Ability to chain credentials
5:54 and they give you a better ability to
5:56 pull in legal pros and the Ricardian
5:58 concept. And ACDCs are way more powerful
6:01 to the concept of a contract credential.
6:03 You can do it with W3C VCs. You can do it
6:05 with whatever you want as long as it's
6:06 cryptographically verifiable data that
6:08 is derived from a contract. But it
6:11 needs to all be like one big signed
6:14 object. The way I think about it is
6:16 okay, you have a legal prose .., I can't
6:18 remember if I actually have like the
6:20 three .., Yeah, I do. I'll focus on
6:23 KERI ACDC's what the what GLEIF came up
6:26 with how you can take that. Taking
6:30 the legal relationship that is embodied
6:32 in a contract that's usually a bilateral
6:35 thing. It can be multilateral. It's
6:37 usually a bilateral thing. You can
6:40 model the relationship: I, landlord,
6:45 give you, tenant, the right to enter
6:47 premises for one year for this rent and
6:50 you can do x y and z. You can model
6:52 that relationship between counterparties
6:55 and assets. It doesn't have to have an
6:57 asset subject to the contract, but you
6:59 can model it. In the music industry,
7:01 model it as far as what you can do
7:03 relating to copyrights. Copyrights have
7:05 in our system DIDs. They could have AIDs.
7:08 It doesn't matter. You're
7:09 modeling legal relationships between
7:11 organizations, people and things through
7:13 contracts. The contracts are like the
7:16 the routing mechanism for the data. And
7:19 you pull in the AIDs or the DIDs into
7:24 the data model that is behind the legal
7:28 pros. You got like, it looks like a
7:29 PDF or a Word document but you can use a
7:31 markup language you can have a data
7:33 model, you have JSON… Party A is
7:37 whatever Acme systems. Acme systems can
7:40 have their AID or DID in the data
7:42 model and you're modeling… yeah it
7:45 looks like a English name but you're
7:47 pulling in the identity the
7:49 decentralized identifier with all you
7:50 know the key state and stuff and then
7:52 that whole object is what's going to get
7:54 signed. You're attesting
7:56 to this is our relationship it is
7:58 embodied in this thing and this thing
7:59 can then generate these credentials that
8:01 has a one to one mapping to the legal
8:03 contract and a one to one mapping to the
8:05 identities and the one to the
8:06 counterparties and a one to one mapping to
8:09 any assets that are like the subject of
8:11 that thing. That's what we do
8:13 is model legal relationships. Why
8:17 KERI? I mean, you guys probably
8:20 already know all of this, but AIDs,
8:23 it's a short talk, I
8:25 can't go into like why I stumbled upon
8:28 KERI and what I was looking for, but I
8:30 didn't want… we were modeling the legal
8:33 state of a copyright. Let's say four
8:35 different music companies own a
8:36 copyright. It's very common. Okay, cool.
8:39 We're going to model the copyright as a
8:40 DID. Okay, who are the controllers of
8:42 the DID doc? Hm. This should be the
8:44 owners. We can model that through
8:46 the contracts that give those four music
8:48 companies ownership. They can all have
8:50 DIDs, controller properties. Cool. Oh,
8:53 shoot. They want to rotate their DID. Aah,
8:55 we're all using the same DID method that
8:57 relies on a ledger. Ah, now I have to
8:59 explain to like these big well-known
9:02 music companies: I need you to interact
9:04 with like the Ethereum blockchain. It
9:06 just doesn't work. And I wanted all of
9:08 them to be able to manage their key
9:09 state separately. And that's… I
9:11 discovered KERI and I was like, that's
9:12 what I want. Like everyone needs to
9:14 manage their key state separately, but
9:16 you can still compose a full chain
9:19 of title as far as assets go. It
9:22 just also happens to work really well
9:24 for contracts, too. KERI AIDs, the
9:27 base layer. ACDC's have a lot more
9:29 power than W3C VC's. You can do it
9:32 either way but ACDCs again sort of the
9:35 the rule, the
9:38 Ricardian part, the attribute section and
9:40 then the edge capability to chain
9:42 credentials is really important. The
9:46 the TELs and the KELs like being able
9:48 to anchor a credential to a TEL which
9:52 is anchored to a KEL is really
9:53 important because if the landlord, if the
9:56 lessee stops paying the landlord, it's a
9:58 breach and they revoke… they
10:00 terminate the lease. You want the
10:01 credential to automatically revoke, so
10:03 that the tenant can't get in or the
10:05 tenants authorized delegated
10:08 employee can't get in, you know, you want
10:10 the whole thing to break at once when
10:11 there's a breach of the contract. The
10:13 contract should be like the actor in the
10:14 system. And vLEI, like GLEIF's already
10:18 done so much work here with sort of
10:20 bringing this into what we consider
10:22 legal workflows.
10:25 This stack is a great way to do
10:28 this. This is sort of legal
10:30 prose. So let's say in the R section of
10:32 ACDC you can have
10:34 the actual prose or you have the
10:36 digest of it as a SAID. You have the
10:39 structured data. So the attribute
10:40 section which is
10:42 just JSON like "term: one year, rent:
10:45 $100,000, square foot: 4,000." And then
10:48 you can have the edges. You can be
10:50 delegating contract like
10:52 contractual authority. Which is
10:54 really important because that's how
10:55 things work in the real world is a lot
10:57 of times like the actions you take are
10:59 from a couple different contracts. Maybe
11:01 they're in a chain, maybe they're not.
11:03 Either way, you can sort of like compose
11:05 it into a proof using this stack.
11:11 I pulled just a random
11:13 corporate or commercial lease building
11:16 lease from the SEC's Edgar platform.
11:19 This is an actual commercial lease
11:22 that was used by big sophisticated
11:23 companies. What you can do is, you
11:27 can have let's say they were negotiating
11:28 this lease. They can negotiate in
11:30 Word using a markup language. you can
11:32 sort of put it into the data model
11:35 that would then populate the ACDC
11:37 attribute section or it's the same thing
11:39 as the JSON schema of a W3C VC.
11:42 You're tying the schema to
11:46 the prose and then from there.
11:50 Let's say we're doing it for an office
11:51 lease. This is kind of what the ACDC
11:54 fields would look like. You've got
11:56 the issuer AID. You can have the
11:59 attribute section which is the deal
12:00 points. You can have edges which I'll
12:02 show you for this one. We can create the
12:06 access credential from the lease
12:08 credential. You can have rules all
12:12 the technical aspects of an ACDC.
12:15 One way to show how this can become a
12:17 chain. Let's say they sign that data
12:19 object. Cool. And now we've got a
12:22 credential that is derived and
12:25 cryptographically married to that
12:26 contract. Any asset can
12:30 have an identity. Assets should have
12:32 identities. The building can have an
12:33 AID. In our in Switchchord all the
12:35 copyrights have DIDs, DID:web DIDs
12:37 just for simplicity. We did an
12:39 implementation with DID:Webs to show
12:40 that KERI can be used in that system.
12:42 All of our assets should have
12:46 decentralized identifiers and then the
12:48 controllers of those assets should be
12:49 the controllers the owners in the real
12:51 world either ownership or like
12:53 administration rights. All of this can
12:54 be modeled. Within this example,
12:59 this building where the commercial lease
13:01 is has an identity, an AID. And then
13:03 you've got a lessor an AID, the lessee
13:05 with an AID. You have the lease
13:07 contract. And you can derive the access
13:11 credential from the lease itself.
13:13 The lessee can issue it to itself as
13:15 an access credential. There's lots of
13:18 different ways you can do this. This is
13:19 just one example to kind of show what it
13:21 would look like. Again, lease
13:24 credential .., the contract credential
13:25 that's derived from the contract
13:28 using Sam's I2I versus the
13:31 NI2I. That would be
13:33 the issuee, the lessee
13:36 issuing it to themself and they can now
13:39 say like I have it from this contract
13:41 and it can be then shown to a smart
13:43 lock. this references the building
13:46 identity, the issuer like in this case
13:49 this is just a lessor
13:51 creating it themselves but, let's say,
13:56 I build a building with someone else
13:58 then we can actually have a contract
13:59 that says all right I own 50% you own
14:01 50%, and that contract can then create
14:03 like the building ID there's different
14:05 ways you can do this there's not like
14:07 one set way it's really flexible:
14:09 you've got the building identity that
14:10 gets pulled into this that gets pulled
14:13 into that derived credential that you
14:15 can show to a smart lock. This is
14:18 that the I2I operator just one example
14:22 of what you can do here. This would
14:24 be the lessee of the lease contract
14:26 granting themselves an authority
14:28 contract. You could probably do it
14:30 without that. I was just trying to show
14:31 a simple example of how you can
14:33 have chained delegation from a single
14:35 contract.
14:37 You could probably just have
14:39 this be the lease credential too. But
14:43 if you're issuing this instead
14:45 of issuing your employees like
14:48 entrance badges, you just issue it as a
14:50 credential their phone and then they're
14:52 they're basically the ones doing a
14:54 delegated access credential from
14:56 their employment agreement credential
14:58 which then goes to the lease
15:00 credential where your employer is the
15:02 tenant. That's how you can
15:04 build these chains that can
15:05 automate legal processes.
15:08 The rule section you can, like Sam's
15:11 done, very forward thinking here with
15:16 sort of putting the legal prose in with
15:19 the credential itself. This is
15:23 kind of optional if you were
15:26 to still do the same framework of a data
15:28 model in a legal pros contract and the
15:30 whole bundle is signed. You kind of have
15:32 it already, but you can get even more
15:35 granular. And this is what is really
15:37 helpful for selective disclosure.
15:40 You don't want to show the whole
15:41 contract. You just want to show I have
15:42 the right to do this one thing. Like I
15:44 don't need to show you smart lock how
15:46 much rent we pay. I don't need to show
15:48 you any of that. It's just like
15:49 selective disclosure for a human proving
15:52 attributes about yourself. You don't
15:53 want to show your home address. You
15:54 don't have to just show that you're over
15:55 21. It's the same thing. You can
15:58 selectively disclose or graduated
16:01 disclosure your contractual authority
16:03 which is extremely powerful
16:05 if you're building towards trust
16:08 with a counterparty. This would be
16:13 the office AID. Creating a digital
16:15 twin is represented as an AID. Again
16:18 this one is issued from an ACDC that
16:21 the lessor AID like attests to the
16:24 building. I own the building. This is
16:26 the information about the building and
16:28 here's the building AID. You have a
16:31 smart lock that knows I control access
16:35 to the building AID, you can build
16:39 logic into that but it knows I am here
16:41 solely to let people into this AID. If
16:45 you show me something that does
16:47 not line up with his AID, you're not
16:48 getting in. If you show me something
16:50 that is to this Aid but is revoked,
16:52 you're not getting in. If
16:54 the smart lock becomes ..,
16:57 you don't need like a central
17:00 registry anymore. It's like the
17:02 credentials from the contract and the
17:04 smart lock just knows it. It's a
17:05 mental leap for a lot of… If I were
17:08 to take this to market as a
17:10 product for say commercial apartment
17:14 like apartment managers or commercial
17:16 building managers they'd be like what?
17:18 But it's really powerful. It cuts down
17:21 on much infrastructure that's
17:23 currently required. Graduated
17:27 disclosure [is] super helpful. You know
17:30 you can, for this example, you could
17:32 just say
17:34 to different verifiers
17:37 you can disclose different things.
17:39 Like the smart lock, you don't need
17:41 to disclose the rent term or the ..,
17:43 well maybe the term, but not
17:45 the amount of rent. But to your
17:50 financial auditor, maybe you need to do
17:51 the whole thing to a third party. The
17:55 graduated disclosure of contractual
17:56 authority is incredibly powerful.
17:58 Showing them the whole
18:00 contract. That's not good. You can just
18:02 show what you need to prove.
18:05 – Litigation, you might want to just say
18:08 even if it is a litigation.
18:10 Oh, totally. Yeah.
18:10 – Could you repeat the
18:12 question because…
18:13 – In litigation ..,
18:15 there's litigation over a contractual
18:17 provision, there's all
18:20 sorts of
18:23 what's evidentiary rules. I took
18:25 evidence in law school, but I'm not
18:26 a litigator. I'm a corporate lawyer,
18:28 corporate entertainment lawyer.
18:30 There's lots of rules for that.
18:32 The judge can order things
18:34 redacted, but this would be a
18:37 bulletproof way to redact things.
18:38 You don't have these
18:40 boneheaded, oh yeah, the PDF is redacted
18:43 with a black bar, and you can like
18:45 delete the black bar, you
18:46 could actually have cryptographic
18:51 opening up that .. And then you can
18:53 really dial in who has the ability to do
18:56 that; it's crazy what you
18:58 can do. This could certainly be
19:01 applied. If there was a
19:03 litigation over this commercial lease,
19:05 like you go to arbitration
19:08 instead of litigation. The
19:09 arbitrator, a mediator, okay, maybe you
19:11 don't want to show the arbitrator. It
19:12 it's really cool that you can
19:14 selectively disclose things and know
19:16 that it's true like
19:18 cryptographically
19:20 know that that's the state of
19:22 this contract. Revocation would
19:24 kind of use the KEL and the TEL
19:27 framework to say all right lease
19:29 terminates the lessor would create
19:33 revocation event in their TEL that's
19:35 going to tell the smart lock that at
19:37 this time period with our key state we
19:40 revoked this credential that was issued
19:43 with this signing key in our KEL,
19:46 that's how the lock would .., the smart lock
19:48 just walks the cryptographic operations
19:51 all the way back and
19:53 it gets to the point of "Sorry,
19:55 this thing's been revoked."
19:58 It's really powerful to be able to
20:00 present contractual authority.
20:02 The easy thing to think about is like
20:04 proving it to a human or an
20:05 organization, but it's like no, no, no,
20:06 how about a how about a software system?
20:08 How about you're trying to get into a
20:10 certain secure database in your
20:13 organization and only certain engineers
20:15 have that? Like "Hmm, that could be done
20:17 through the employment agreement."
20:19 It's really powerful when you
20:21 start thinking about it in these
20:23 granular ways and then as soon as you're
20:25 fired you don't have to do anything else
20:27 like it's done, it's like
20:30 "Everything breaks" versus "Oh my god, we
20:33 got to log in to this system and revoke
20:35 his authority and this system revoke
20:36 like everything
20:38 once you start to view the world this
20:40 way .., I can't undo it like I view the
20:41 world differently that this
20:43 is interaction between contractual
20:45 authority and
20:48 your rights as a human and it can
20:50 all be bound up and it would
20:54 be cool if you could pick and choose
20:56 from all of them. I work here, I
20:59 live here, I am employed here, I have
21:02 the contract right to this and I can
21:04 just take what I need to to prove
21:06 anything. So I focus on the
21:08 commercial transaction elements. The
21:10 vLEI, you can model this based on the
21:14 GLEIF route to the QVI to the legal entity
21:16 to the role credential and the ECR.
21:20 That's a little more specific to the
21:22 GLEIF environment. This is an abstraction
21:25 of that. Anything can be turned into
21:29 this. We could even
21:32 abstract the GLEIF one to say "Okay, the
21:35 board of directors there's five
21:37 individuals they all have AIDs they all
21:38 agree in a written consent to give Karla
21:41 authority to sign contracts up to
21:44 ten million dollars. They digitally sign this
21:46 prose looking consent that creates the
21:49 board consent credential. The credential
21:52 itself can be chained to the employment
21:54 credential of Karla. Karla's credential
21:57 gives her certain her employment
21:59 relationship ship gives her certain
22:00 rights. The board has now given her
22:02 certain rights. We can pull those
22:03 together and now when she tries to go
22:06 into Docusign, she's asked to present her
22:08 authority credential, which can be a
22:09 derived credential. The contract is 20
22:12 million. Karla needs to get more
22:14 authority. So, it's a much
22:16 more abstract and granular notion, but
22:19 it's the same general framework. And
22:22 that's powerful because we know it works
22:25 like GLEIF is in production and it works.
22:27 So, I'm trying everywhere I
22:29 can. I'm trying not to reinvent things
22:32 that already work. So yeah,
22:35 I didn't have time and I
22:38 don't think I really can. Like I've
22:39 gotten pretty good at vibe-coding
22:41 legal products. I built it myself as a
22:43 lawyer to automate things, but I tried
22:45 to build this and it was just too hard
22:47 to do the actual KERI stack.
22:50 So, I built like a simulated version,
22:52 which I'll walk you through. So you got
22:54 the AIDs of all the parties. The lessor
22:57 will create the building AID. You then
23:00 sign the lease. The lease then populates
23:04 the schema of the hybrid legal
23:07 contract populates the scheme of the
23:08 ACDC. The attribute section. You
23:11 then derive the access credential from
23:13 that. So it's an issuer the eye to eye
23:16 transaction from lessee to itself and then
23:18 lessee can present that. The smart lock
23:20 would then verify back.
23:29 I vibe-coded this.
23:32 This is based on the ACDC like IETF,
23:36 whatever it's called specs.
23:37 Everything's like very much to spec.
23:39 I didn't have the time or
23:41 capability to spin up all the
23:42 infrastructure to make this real. So
23:44 you've got this contract is like I said,
23:48 this is a real contract. I found it on
23:49 the SEC's website. I was like, I want
23:51 something; it's 45 pages,
23:52 really dense, really complex. And I
23:56 used that for this demo. So, this would
23:59 be the inception event for let's see,
24:04 this is the lessor. So, the property
24:06 owner, and this follows,
24:08 everything that you technical people in
24:10 here are familiar with all of Sam's
24:13 fields. Same with this one. You've
24:16 got the AID in there, somewhere. I think
24:19 it's the I and then you've got this
24:22 building. So, this digital twin with an
24:24 AID, public key and then it
24:27 shows
24:29 it shows where ..
24:32 I don't have the ACDC white paper
24:35 IETF spec memorized. So, I get kind of
24:37 lost when I'm looking like which one is
24:40 the actual issuer, but it would be AO6.
24:46 There it is. Okay. So that's the one
24:48 that's the lessor. Now we've got
24:50 AIDs for the lessor or the lessee in the
24:53 building. So then
24:55 we would
24:57 issue the building identity credential.
24:59 So this would be issued by the lessor
25:02 that attests to the building and gives
25:06 the attributes about the building.
25:10 This is establishing the idea of the
25:12 building that can be pulled into this
25:13 concept of contract credential. We've
25:16 got the lease. I don't know where I
25:19 put the PDF if I had it.Tthis is
25:21 the actual language from the lease. This
25:23 is how you could take a markup language
25:25 to then
25:28 the prose version. But if
25:30 you look at it with X-ray vision, you're
25:31 seeing this behind the scenes.
25:34 And then this is what's populating
25:38 the ACDC schema or for a W3C [credential, red.] it'd be
25:42 just like the JSON in the VC schema.
25:45 That's how you're having a one
25:46 to one mapping between the contract and
25:48 the credential. And then that whole data
25:50 object can be signed. You've got
25:53 ideally the same public private key pair
25:56 is signing the PDF as it's signing the
26:00 data model and the credential. It should
26:01 all be the same. That's how you can like
26:03 bind everything together. And then
26:06 you've got, let's see, lessee receives the
26:08 credential now acts as the issuer. Oh,
26:09 this is where .., just to show the delegated
26:12 and the chaining mechanism, this is
26:13 where the lessee can create its own access
26:17 credential. Let's say this is for an
26:18 employee. So they issue it to the
26:19 employee.
26:21 – I'll ask a question, but please repeat
26:22 it as well for your mic.
26:24 – Oh yeah. Yeah, definitely.
26:25 – What, it's a bit off topic, but how
26:30 much time do you think will we have
26:34 to endure before this becomes all
26:37 graphic like with puppets? Lessor, lessee…
26:41 You can click on them.
26:43 – Yeah, that's what it should be.
26:44 Totally.
26:45 – What do you think? What kind of… Please
26:49 repeat the question.
26:51 – Yeah.
26:53 – How soon? How much time?
26:54 Yeah.
26:55 So, I mean, this was me. I built this I
26:59 built all of this in about 4 hours
27:01 late at night when I needed to get
27:03 what was due. I forgot what
27:05 the due date was for the slides, but I
27:07 was like, "Oh my god, I still haven't
27:08 done them yet." So, I did everything
27:10 using Claude and Cursor in including
27:13 building this in about 4 hours.
27:16 I could probably turn this into
27:17 a much prettier UI. This is
27:20 basically a one-shot attempt.
27:23 I mean Opus 4.7 did all everything
27:26 you're seeing here is like me working
27:28 with Opus 4.7.
27:30 – I'm just unaware are there already
27:33 toolkits to make it more
27:36 graphically [attractive, red.]? The question is on
27:38 UI/UX of all of this. I don't know.
27:43 Decentralized identity tends to have
27:45 a pretty bad UI/UX in general. It's hard.
27:48 Some companies have done a much
27:50 better job than others. I would
27:53 prefer to see it. Again, I'm really just
27:55 trying to show just like how it works,
27:58 the nuts and bolts using the actual
28:00 ACDC spec. But yeah, there's no way I
28:03 would show like build a product that
28:05 looked like this to like an apartment
28:08 manager. There's zero way. This is all
28:10 behind the hood.
28:11 – I think that's the solution, I think, to
28:12 what you're saying is I don't think
28:14 there's going to be
28:16 a one-way-fits-all way to view all this.
28:18 I think it's going to be individual
28:20 apps.
28:22 That are encapsulating it all.
28:24 Yeah. We built this
28:27 amazing platform for the music industry.
28:29 It was five years ahead of its
28:31 time which is why it was hard to get off
28:32 the ground because no one knew what we
28:33 were talking about. We're taking
28:34 songwriter agreements. We're dropping
28:36 them in. We use AI to extract everything
28:38 about the legal relationship between a
28:39 songwriter and a music publisher.
28:41 Populates a W3C VC, issues the
28:43 songwriter. So now we've got this
28:45 verified connection from the
28:47 writer and the publisher. Writer writes
28:48 a new song, drops in the information
28:50 right here on their phone. Boom, shows
28:52 up instantly on the publisher side. It's
28:54 tracking from the contract. It's almost
28:56 like the data is getting stamped by the
28:58 contract as it goes through the pipe.
28:59 It's amazing, but no one understands it.
29:03 The identity thing, no one cares that we
29:05 built this cool thing where you can like
29:07 click the credential, it flips over and
29:09 shows the JSON schema. Everyone's like,
29:12 how does that help me? So that product,
29:14 I don't want to say it failed. It was
29:16 like a great product and it actually
29:18 this one feature of that product is now
29:21 what is getting a ton of interest and is
29:23 working for us and we will Trojan-horse the
29:26 identity stuff back in, eventually, but
29:28 but yeah UI/UX is just hard with this
29:31 stuff.
29:32 – More comment than question at this
29:35 point
29:36 On this model from a physical
29:39 security standpoint you said
29:41 this is a management company for an
29:43 apartment building. Most places today
29:46 have a keypad out in front that you put
29:49 in and it calls up or whatever lets you
29:51 in.
29:52 They're made by two manufacturers.
29:57 You can buy the three keys that open
30:00 that box everywhere in the world.
30:03 For $18 and there's a button inside that
30:07 overrides the system and opens the door.
30:10 So to your point, if it was on the
30:12 phone, you could completely do away with that!
30:14 You have biometric. You marry
30:16 biometric to cryptographic to legal…
30:18 – That would save these folks…
30:21 So much money cuz they they have to go
30:23 pay insurance. You got to pay insurance.
30:26 Anytime there's a risk, you got to
30:27 insure it and that's a transaction cost
30:28 that doesn't need to be there. That's
30:29 what I'm saying. Like
30:31 this magic cryptography can just like
30:33 really reduce transaction cost
30:34 everywhere you look. And and like I
30:35 said, once you see the pattern,
30:38 it's really hard to unsee. Now
30:39 everything I look, I'm like, "Oh god,
30:41 why do we do it that way?" But
30:43 yeah, his would be great. And this
30:44 would be instead of most
30:47 apartment complexes don't let you do
30:48 Airbnb, but people still do it because
30:50 you can find ways to trade the key fobs.
30:52 Like this technically kills that. Or you
30:54 can put in place rules and governance
30:57 that says you may rent out your
30:59 apartment, but the other person must be
31:01 verified and have a credit score over X.
31:03 Like you can build in the logic. They
31:05 get the credential, they buy a metric,
31:07 they show it, they go in. It's
31:10 really powerful what you can do with
31:12 this stuff. – You have five more minutes.
31:15 Okay, cool. So this is the example of
31:17 showing it to the smart lock and this is
31:19 what's happening is, it's checking this
31:21 is like checking all the KELs, the
31:24 TELs, traversing the nodes,
31:27 Again, that didn't actually just happen
31:28 with the true KERI stack, but this is
31:32 true to the ACDC spec and like how it
31:34 would happen and access granted
31:37 this is the tenant, that was the
31:39 tenant with that AID, they can get in
31:41 24/7 to street 105 open it up and then
31:44 this would be what happens if
31:48 the tenant doesn't pay their rent and
31:51 the lease is terminated. Therefore, all
31:54 building access credentials of employees
31:55 are automatically revoked. That's what
31:57 this one would be. Let's see. Attempt
32:00 access with revoked lease. So, it kind
32:02 of does the same thing. It's
32:04 running backwards and checking the TEL,
32:06 seeing that that edge on the lease has
32:09 been this TEL was revoked. It has the
32:11 registry AID, the TEL sequence. You
32:14 can, check the signing keys at
32:16 the time. Access denied. Reason,
32:19 upstream credential revoked, lease
32:21 contract, lease is terminated.
32:24 That's to me, much
32:27 easier to understand than the music
32:28 stuff, and it's fun to apply
32:30 this to other things. So that is
32:34 that's the demo. That's that. And I
32:37 think that is kind of the end of
32:42 the presentation.
32:44 So yeah, that's what we're doing.
32:45 [applause]
32:49 So I guess we have
32:51 five minutes for questions.
32:53 – Yeah.
32:55 Yeah. So what's the… Have you studied
32:58 you got a lawyer [inaudible]? Have you
33:00 studied the enforcability angle of this?
33:03 Yeah, there's
33:05 no enforcability issues cuz you start
33:09 with the legal prose contract as the
33:12 base.
33:15 Yeah, it's all enforceable because you
33:17 have it all like you've got it, you
33:19 know, different states. in Wyoming's
33:21 been pushing the boundaries on this and
33:22 others are smart contracts are
33:24 legally enforceable like blockchain
33:25 based smart contracts. That's fine but
33:29 we're not going to get rid of human
33:33 communication and legal prose.
33:35 it's not going away anytime
33:38 soon. I don't think we're going to have
33:40 some domain-specific coding language
33:42 where the language you write is the
33:46 contract and it is the code.
33:49 I just don't see that happening.
33:51 I think you have to take this
33:53 sort of hybrid approach of
33:55 there's disputes. It's going to
33:57 have to go in front of some sort of
33:59 judge or arbitrator or mediator or
34:00 something. And they can't read the
34:03 case, they can't read the
34:05 ACDC spec. It's not going to happen.
34:07 You still have to have that original
34:10 legal prose. You can pull it out, you
34:13 can hash it, “SAID” it. I don't
34:16 know how it's Sam likes to pronounce it.
34:18 It's different every time.
34:19 Said it.
34:20 Said
34:20 said. Okay. You can said it.
34:22 So, it's just a hash digest. You can do
34:24 whatever you want, but just don't
34:26 think you'll ever get around needing a
34:28 contract.
34:29 – Is it just me …
34:33 KERI is incredibly powerful,
34:35 but it's very hard to explain to people.
34:38 You see, have you seen that?
34:41 – Yeah. KERI especially. So, like
34:43 when I explain to the music industry, I
34:44 can't bring up KERI. I just have
34:46 to talk about
34:48 basic JSON and W3C.
34:49 [inaudible]
34:52 make it easier for consumption.
34:55 I think it just needs to be in the
34:56 back-end of products and I think you
34:59 just can't even really
35:01 explain a lot of it. It's like most
35:03 people don't know how the internet
35:04 works.
35:05 – It's got to be user experience.
35:06 – Yeah. Like 99 people% of the people
35:09 don't understand how the internet works.
35:10 – [inaudible] That's exactly where I am.
35:14 If they can connect to the
35:16 business aspect of things, they go.
35:18 Yeah. That's what we're
35:20 trying to do. We're getting closer
35:21 and we've been working at this for four
35:23 or five years now and we're
35:25 finally getting somewhere.
35:28 – We have to stop
35:29 Oh yeah. Totally.
35:33 - Just do it.
35:34 Just do it. Just use it.
35:37 Make people fight you about it.
35:39 Yeah. [applause]