Contract Credentials & Verifiable Identity - Cole Davis

KERICONF26 Day 1 · 39:10

0:00 Cole Davis | Contract Credentials & Verifiable Identity | KERI Conference 2026

0:02 Hey everyone. I'm Cole Davis. I am

0:05 the founder of Switchchord, which is a

0:09 music, we're legal tech and digital

0:12 identity company building products

0:14 in the music industry. That is one

0:16 brand under sort of an IP holding

0:18 company we have called Steamroller

0:20 Systems that is industry agnostic to

0:22 apply machine learning and

0:26 decentralized identity techniques to

0:28 legal workflows. So we kind of blend

0:30 the worlds of legal tech and digital

0:32 identity primarily using

0:34 decentralized identity. And I'm going to

0:38 talk today though not about music

0:39 because I always talk about music and I

0:40 wanted to change it up. And today I'm

0:42 going to talk about, I call these

0:45 things, contract credentials. So I've for

0:47 years advocated that legal contracts and

0:51 and verifiable credentials should be

0:53 sort of married together like a legal…

0:56 like I wanted to create a dual root of

0:59 trust like a legal root of trust and a

1:01 cryptographic root of trust and I want

1:02 them to be inherent in everything you

1:05 do when you prove you have contractual

1:07 authority. So I spent years looking for

1:09 solutions starting in the blockchain

1:11 world and then the W3C DID VC world

1:14 discovered KERI in 2021 and finally was

1:18 like that's what I need. Primarily

1:20 because it doesn't require like an

1:22 underlying ledger. I can get into why

1:26 the Switchchord stack is built the way

1:28 it is but for now I'm just going to

1:30 focus on the general concept. And then I

1:33 did a demo in the real estate industry

1:35 because it tends to be easier to

1:37 understand and you don't need a whole

1:38 lot of like domain specific knowledge

1:40 about music to really appreciate it.

1:43 Because you apply the tech anywhere,

1:45 anywhere you have a legal contract or

1:47 contractual authority or contractual

1:48 relationship you can apply this

1:51 framework to it. So that's what we're

1:54 going to talk about today.

1:57 Credentials a lot of times at IIW

1:59 and the W3C and the KERI community, we

2:01 talk about credentials proving who you

2:04 are. You know, you're a human. You're an

2:07 organization. I don't often see them

2:10 proving what you have the contractual

2:13 authority to do. It's like not a concept

2:15 that comes easy to people. But when I

2:18 explain this to the music industry, I

2:20 often use the example and this actually

2:21 did start to resonate of a mobile

2:23 driver's license cuz some states have

2:25 mobile driver's licenses and they sit in

2:27 their Apple or Google wallet. So I

2:29 explain, driver's

2:32 license is a credential issued to you

2:34 from an issuer. It has claims about what

2:36 you can do and it's kind of digitally

2:37 signed and you can prove to third

2:39 parties that you have the authority to

2:41 do something. That's easier for

2:43 people to make that mental leap of ..,

2:45 Okay. The contract

2:47 credential is kind of like this, but it

2:48 tells me I can sign documents over 10

2:53 million dollars cuz I have this authority from

2:55 the board of directors or I can enter

2:58 this building because my employer has a

3:01 lease with the building owner and I am

3:03 an active employee with the right to

3:05 enter the premises. What I

3:08 wanted to do was the way a lot of

3:12 people talk about creating like

3:14 verifiable presentations or capturing

3:17 claims from different credentials and

3:18 presenting them about you. Oh, I'm Cole.

3:21 I graduated from TCU. This is my GPA. I

3:24 have this job. Okay, cool. I'm more

3:27 interested in the commercial

3:28 applications of this, as far as

3:29 commercial transactions go. I want to

3:31 be able to say "I'm this organization. I

3:34 have the contractual right to do this.

3:35 I have contractual right to do this."

3:37 I want to be able to pull select from

3:39 different contracts that give me the

3:40 authority to do transactions on a market

3:43 and I want that to be instantly

3:45 verifiable to third parties who want to

3:47 maybe do business with me. Because it

3:50 gets into that Ronald Coase world of

3:52 like transaction cost. How can we reduce

3:53 transaction cost? Verifying

3:55 counterparties and their reputations and

3:58 all that and their authority to do

3:59 things is like really important

4:01 for transaction costs. If you can

4:02 reduce some of this technology, you can

4:04 have more transactions on the market.

4:06 That's what my concept of a contract

4:09 credential is is like "What if they're

4:11 the same thing. What if the contract is

4:13 the credential? Like what if you can

4:14 hold your lease up to the smart lock or

4:16 what if you can [make it the same thing, red], the stock

4:20 option agreement or this stocks

4:23 purchase agreement is the stock

4:25 certificate?" Stop taking the

4:27 contract here and then the authority or

4:29 the thing it represents over here and

4:30 like "No, make them the same thing and

4:33 have a shared cryptographic and legal

4:35 root of trust." That's basically what

4:38 this is. There's an authority

4:40 gap like credentials they don't model

4:43 contracts they live in separate systems.

4:45 You have a contract in your rights

4:46 management system or or contract life

4:48 cycle management system. And then you

4:50 have the operational aspects of the

4:52 contract, what you can do or what you're

4:54 required to do or can't do. Those

4:57 tend to live in different systems. What

4:59 if we collapse them into a single

5:00 system? You know, what if it's all the

5:02 same? Like it's a really weird concept,

5:04 but it's really powerful. And we've been…

5:07 Did you have a… saw hand for just a

5:09 second?

5:09 – I have a question [inaudible].

5:10 What's the difference between a

5:12 credential, a role and the terms that

5:16 the ACDC can define? Is that kind of

5:19 combined or

5:21 [inaudible] there as well?

5:24 It's flexible enough to where

5:26 like the vLEI, ECR and role credentials

5:29 and stuff are sort of derived from this

5:32 whole general technology but it's a

5:33 little more specific. This is more

5:35 general. This is any employment

5:38 relationship, any board granted

5:41 authority, anything can be modeled into

5:44 this framework using ACDC. You can do it

5:46 with W3C VCs too, but there's

5:49 just like limitations there that ACDCs

5:51 give you. Ability to chain credentials

5:54 and they give you a better ability to

5:56 pull in legal pros and the Ricardian

5:58 concept. And ACDCs are way more powerful

6:01 to the concept of a contract credential.

6:03 You can do it with W3C VCs. You can do it

6:05 with whatever you want as long as it's

6:06 cryptographically verifiable data that

6:08 is derived from a contract. But it

6:11 needs to all be like one big signed

6:14 object. The way I think about it is

6:16 okay, you have a legal prose .., I can't

6:18 remember if I actually have like the

6:20 three .., Yeah, I do. I'll focus on

6:23 KERI ACDC's what the what GLEIF came up

6:26 with how you can take that. Taking

6:30 the legal relationship that is embodied

6:32 in a contract that's usually a bilateral

6:35 thing. It can be multilateral. It's

6:37 usually a bilateral thing. You can

6:40 model the relationship: I, landlord,

6:45 give you, tenant, the right to enter

6:47 premises for one year for this rent and

6:50 you can do x y and z. You can model

6:52 that relationship between counterparties

6:55 and assets. It doesn't have to have an

6:57 asset subject to the contract, but you

6:59 can model it. In the music industry,

7:01 model it as far as what you can do

7:03 relating to copyrights. Copyrights have

7:05 in our system DIDs. They could have AIDs.

7:08 It doesn't matter. You're

7:09 modeling legal relationships between

7:11 organizations, people and things through

7:13 contracts. The contracts are like the

7:16 the routing mechanism for the data. And

7:19 you pull in the AIDs or the DIDs into

7:24 the data model that is behind the legal

7:28 pros. You got like, it looks like a

7:29 PDF or a Word document but you can use a

7:31 markup language you can have a data

7:33 model, you have JSON… Party A is

7:37 whatever Acme systems. Acme systems can

7:40 have their AID or DID in the data

7:42 model and you're modeling… yeah it

7:45 looks like a English name but you're

7:47 pulling in the identity the

7:49 decentralized identifier with all you

7:50 know the key state and stuff and then

7:52 that whole object is what's going to get

7:54 signed. You're attesting

7:56 to this is our relationship it is

7:58 embodied in this thing and this thing

7:59 can then generate these credentials that

8:01 has a one to one mapping to the legal

8:03 contract and a one to one mapping to the

8:05 identities and the one to the

8:06 counterparties and a one to one mapping to

8:09 any assets that are like the subject of

8:11 that thing. That's what we do

8:13 is model legal relationships. Why

8:17 KERI? I mean, you guys probably

8:20 already know all of this, but AIDs,

8:23 it's a short talk, I

8:25 can't go into like why I stumbled upon

8:28 KERI and what I was looking for, but I

8:30 didn't want… we were modeling the legal

8:33 state of a copyright. Let's say four

8:35 different music companies own a

8:36 copyright. It's very common. Okay, cool.

8:39 We're going to model the copyright as a

8:40 DID. Okay, who are the controllers of

8:42 the DID doc? Hm. This should be the

8:44 owners. We can model that through

8:46 the contracts that give those four music

8:48 companies ownership. They can all have

8:50 DIDs, controller properties. Cool. Oh,

8:53 shoot. They want to rotate their DID. Aah,

8:55 we're all using the same DID method that

8:57 relies on a ledger. Ah, now I have to

8:59 explain to like these big well-known

9:02 music companies: I need you to interact

9:04 with like the Ethereum blockchain. It

9:06 just doesn't work. And I wanted all of

9:08 them to be able to manage their key

9:09 state separately. And that's… I

9:11 discovered KERI and I was like, that's

9:12 what I want. Like everyone needs to

9:14 manage their key state separately, but

9:16 you can still compose a full chain

9:19 of title as far as assets go. It

9:22 just also happens to work really well

9:24 for contracts, too. KERI AIDs, the

9:27 base layer. ACDC's have a lot more

9:29 power than W3C VC's. You can do it

9:32 either way but ACDCs again sort of the

9:35 the rule, the

9:38 Ricardian part, the attribute section and

9:40 then the edge capability to chain

9:42 credentials is really important. The

9:46 the TELs and the KELs like being able

9:48 to anchor a credential to a TEL which

9:52 is anchored to a KEL is really

9:53 important because if the landlord, if the

9:56 lessee stops paying the landlord, it's a

9:58 breach and they revoke… they

10:00 terminate the lease. You want the

10:01 credential to automatically revoke, so

10:03 that the tenant can't get in or the

10:05 tenants authorized delegated

10:08 employee can't get in, you know, you want

10:10 the whole thing to break at once when

10:11 there's a breach of the contract. The

10:13 contract should be like the actor in the

10:14 system. And vLEI, like GLEIF's already

10:18 done so much work here with sort of

10:20 bringing this into what we consider

10:22 legal workflows.

10:25 This stack is a great way to do

10:28 this. This is sort of legal

10:30 prose. So let's say in the R section of

10:32 ACDC you can have

10:34 the actual prose or you have the

10:36 digest of it as a SAID. You have the

10:39 structured data. So the attribute

10:40 section which is

10:42 just JSON like "term: one year, rent:

10:45 $100,000, square foot: 4,000." And then

10:48 you can have the edges. You can be

10:50 delegating contract like

10:52 contractual authority. Which is

10:54 really important because that's how

10:55 things work in the real world is a lot

10:57 of times like the actions you take are

10:59 from a couple different contracts. Maybe

11:01 they're in a chain, maybe they're not.

11:03 Either way, you can sort of like compose

11:05 it into a proof using this stack.

11:11 I pulled just a random

11:13 corporate or commercial lease building

11:16 lease from the SEC's Edgar platform.

11:19 This is an actual commercial lease

11:22 that was used by big sophisticated

11:23 companies. What you can do is, you

11:27 can have let's say they were negotiating

11:28 this lease. They can negotiate in

11:30 Word using a markup language. you can

11:32 sort of put it into the data model

11:35 that would then populate the ACDC

11:37 attribute section or it's the same thing

11:39 as the JSON schema of a W3C VC.

11:42 You're tying the schema to

11:46 the prose and then from there.

11:50 Let's say we're doing it for an office

11:51 lease. This is kind of what the ACDC

11:54 fields would look like. You've got

11:56 the issuer AID. You can have the

11:59 attribute section which is the deal

12:00 points. You can have edges which I'll

12:02 show you for this one. We can create the

12:06 access credential from the lease

12:08 credential. You can have rules all

12:12 the technical aspects of an ACDC.

12:15 One way to show how this can become a

12:17 chain. Let's say they sign that data

12:19 object. Cool. And now we've got a

12:22 credential that is derived and

12:25 cryptographically married to that

12:26 contract. Any asset can

12:30 have an identity. Assets should have

12:32 identities. The building can have an

12:33 AID. In our in Switchchord all the

12:35 copyrights have DIDs, DID:web DIDs

12:37 just for simplicity. We did an

12:39 implementation with DID:Webs to show

12:40 that KERI can be used in that system.

12:42 All of our assets should have

12:46 decentralized identifiers and then the

12:48 controllers of those assets should be

12:49 the controllers the owners in the real

12:51 world either ownership or like

12:53 administration rights. All of this can

12:54 be modeled. Within this example,

12:59 this building where the commercial lease

13:01 is has an identity, an AID. And then

13:03 you've got a lessor an AID, the lessee

13:05 with an AID. You have the lease

13:07 contract. And you can derive the access

13:11 credential from the lease itself.

13:13 The lessee can issue it to itself as

13:15 an access credential. There's lots of

13:18 different ways you can do this. This is

13:19 just one example to kind of show what it

13:21 would look like. Again, lease

13:24 credential .., the contract credential

13:25 that's derived from the contract

13:28 using Sam's I2I versus the

13:31 NI2I. That would be

13:33 the issuee, the lessee

13:36 issuing it to themself and they can now

13:39 say like I have it from this contract

13:41 and it can be then shown to a smart

13:43 lock. this references the building

13:46 identity, the issuer like in this case

13:49 this is just a lessor

13:51 creating it themselves but, let's say,

13:56 I build a building with someone else

13:58 then we can actually have a contract

13:59 that says all right I own 50% you own

14:01 50%, and that contract can then create

14:03 like the building ID there's different

14:05 ways you can do this there's not like

14:07 one set way it's really flexible:

14:09 you've got the building identity that

14:10 gets pulled into this that gets pulled

14:13 into that derived credential that you

14:15 can show to a smart lock. This is

14:18 that the I2I operator just one example

14:22 of what you can do here. This would

14:24 be the lessee of the lease contract

14:26 granting themselves an authority

14:28 contract. You could probably do it

14:30 without that. I was just trying to show

14:31 a simple example of how you can

14:33 have chained delegation from a single

14:35 contract.

14:37 You could probably just have

14:39 this be the lease credential too. But

14:43 if you're issuing this instead

14:45 of issuing your employees like

14:48 entrance badges, you just issue it as a

14:50 credential their phone and then they're

14:52 they're basically the ones doing a

14:54 delegated access credential from

14:56 their employment agreement credential

14:58 which then goes to the lease

15:00 credential where your employer is the

15:02 tenant. That's how you can

15:04 build these chains that can

15:05 automate legal processes.

15:08 The rule section you can, like Sam's

15:11 done, very forward thinking here with

15:16 sort of putting the legal prose in with

15:19 the credential itself. This is

15:23 kind of optional if you were

15:26 to still do the same framework of a data

15:28 model in a legal pros contract and the

15:30 whole bundle is signed. You kind of have

15:32 it already, but you can get even more

15:35 granular. And this is what is really

15:37 helpful for selective disclosure.

15:40 You don't want to show the whole

15:41 contract. You just want to show I have

15:42 the right to do this one thing. Like I

15:44 don't need to show you smart lock how

15:46 much rent we pay. I don't need to show

15:48 you any of that. It's just like

15:49 selective disclosure for a human proving

15:52 attributes about yourself. You don't

15:53 want to show your home address. You

15:54 don't have to just show that you're over

15:55 21. It's the same thing. You can

15:58 selectively disclose or graduated

16:01 disclosure your contractual authority

16:03 which is extremely powerful

16:05 if you're building towards trust

16:08 with a counterparty. This would be

16:13 the office AID. Creating a digital

16:15 twin is represented as an AID. Again

16:18 this one is issued from an ACDC that

16:21 the lessor AID like attests to the

16:24 building. I own the building. This is

16:26 the information about the building and

16:28 here's the building AID. You have a

16:31 smart lock that knows I control access

16:35 to the building AID, you can build

16:39 logic into that but it knows I am here

16:41 solely to let people into this AID. If

16:45 you show me something that does

16:47 not line up with his AID, you're not

16:48 getting in. If you show me something

16:50 that is to this Aid but is revoked,

16:52 you're not getting in. If

16:54 the smart lock becomes ..,

16:57 you don't need like a central

17:00 registry anymore. It's like the

17:02 credentials from the contract and the

17:04 smart lock just knows it. It's a

17:05 mental leap for a lot of… If I were

17:08 to take this to market as a

17:10 product for say commercial apartment

17:14 like apartment managers or commercial

17:16 building managers they'd be like what?

17:18 But it's really powerful. It cuts down

17:21 on much infrastructure that's

17:23 currently required. Graduated

17:27 disclosure [is] super helpful. You know

17:30 you can, for this example, you could

17:32 just say

17:34 to different verifiers

17:37 you can disclose different things.

17:39 Like the smart lock, you don't need

17:41 to disclose the rent term or the ..,

17:43 well maybe the term, but not

17:45 the amount of rent. But to your

17:50 financial auditor, maybe you need to do

17:51 the whole thing to a third party. The

17:55 graduated disclosure of contractual

17:56 authority is incredibly powerful.

17:58 Showing them the whole

18:00 contract. That's not good. You can just

18:02 show what you need to prove.

18:05 – Litigation, you might want to just say

18:08 even if it is a litigation.

18:10 Oh, totally. Yeah.

18:10 – Could you repeat the

18:12 question because…

18:13 – In litigation ..,

18:15 there's litigation over a contractual

18:17 provision, there's all

18:20 sorts of

18:23 what's evidentiary rules. I took

18:25 evidence in law school, but I'm not

18:26 a litigator. I'm a corporate lawyer,

18:28 corporate entertainment lawyer.

18:30 There's lots of rules for that.

18:32 The judge can order things

18:34 redacted, but this would be a

18:37 bulletproof way to redact things.

18:38 You don't have these

18:40 boneheaded, oh yeah, the PDF is redacted

18:43 with a black bar, and you can like

18:45 delete the black bar, you

18:46 could actually have cryptographic

18:51 opening up that .. And then you can

18:53 really dial in who has the ability to do

18:56 that; it's crazy what you

18:58 can do. This could certainly be

19:01 applied. If there was a

19:03 litigation over this commercial lease,

19:05 like you go to arbitration

19:08 instead of litigation. The

19:09 arbitrator, a mediator, okay, maybe you

19:11 don't want to show the arbitrator. It

19:12 it's really cool that you can

19:14 selectively disclose things and know

19:16 that it's true like

19:18 cryptographically

19:20 know that that's the state of

19:22 this contract. Revocation would

19:24 kind of use the KEL and the TEL

19:27 framework to say all right lease

19:29 terminates the lessor would create

19:33 revocation event in their TEL that's

19:35 going to tell the smart lock that at

19:37 this time period with our key state we

19:40 revoked this credential that was issued

19:43 with this signing key in our KEL,

19:46 that's how the lock would .., the smart lock

19:48 just walks the cryptographic operations

19:51 all the way back and

19:53 it gets to the point of "Sorry,

19:55 this thing's been revoked."

19:58 It's really powerful to be able to

20:00 present contractual authority.

20:02 The easy thing to think about is like

20:04 proving it to a human or an

20:05 organization, but it's like no, no, no,

20:06 how about a how about a software system?

20:08 How about you're trying to get into a

20:10 certain secure database in your

20:13 organization and only certain engineers

20:15 have that? Like "Hmm, that could be done

20:17 through the employment agreement."

20:19 It's really powerful when you

20:21 start thinking about it in these

20:23 granular ways and then as soon as you're

20:25 fired you don't have to do anything else

20:27 like it's done, it's like

20:30 "Everything breaks" versus "Oh my god, we

20:33 got to log in to this system and revoke

20:35 his authority and this system revoke

20:36 like everything

20:38 once you start to view the world this

20:40 way .., I can't undo it like I view the

20:41 world differently that this

20:43 is interaction between contractual

20:45 authority and

20:48 your rights as a human and it can

20:50 all be bound up and it would

20:54 be cool if you could pick and choose

20:56 from all of them. I work here, I

20:59 live here, I am employed here, I have

21:02 the contract right to this and I can

21:04 just take what I need to to prove

21:06 anything. So I focus on the

21:08 commercial transaction elements. The

21:10 vLEI, you can model this based on the

21:14 GLEIF route to the QVI to the legal entity

21:16 to the role credential and the ECR.

21:20 That's a little more specific to the

21:22 GLEIF environment. This is an abstraction

21:25 of that. Anything can be turned into

21:29 this. We could even

21:32 abstract the GLEIF one to say "Okay, the

21:35 board of directors there's five

21:37 individuals they all have AIDs they all

21:38 agree in a written consent to give Karla

21:41 authority to sign contracts up to

21:44 ten million dollars. They digitally sign this

21:46 prose looking consent that creates the

21:49 board consent credential. The credential

21:52 itself can be chained to the employment

21:54 credential of Karla. Karla's credential

21:57 gives her certain her employment

21:59 relationship ship gives her certain

22:00 rights. The board has now given her

22:02 certain rights. We can pull those

22:03 together and now when she tries to go

22:06 into Docusign, she's asked to present her

22:08 authority credential, which can be a

22:09 derived credential. The contract is 20

22:12 million. Karla needs to get more

22:14 authority. So, it's a much

22:16 more abstract and granular notion, but

22:19 it's the same general framework. And

22:22 that's powerful because we know it works

22:25 like GLEIF is in production and it works.

22:27 So, I'm trying everywhere I

22:29 can. I'm trying not to reinvent things

22:32 that already work. So yeah,

22:35 I didn't have time and I

22:38 don't think I really can. Like I've

22:39 gotten pretty good at vibe-coding

22:41 legal products. I built it myself as a

22:43 lawyer to automate things, but I tried

22:45 to build this and it was just too hard

22:47 to do the actual KERI stack.

22:50 So, I built like a simulated version,

22:52 which I'll walk you through. So you got

22:54 the AIDs of all the parties. The lessor

22:57 will create the building AID. You then

23:00 sign the lease. The lease then populates

23:04 the schema of the hybrid legal

23:07 contract populates the scheme of the

23:08 ACDC. The attribute section. You

23:11 then derive the access credential from

23:13 that. So it's an issuer the eye to eye

23:16 transaction from lessee to itself and then

23:18 lessee can present that. The smart lock

23:20 would then verify back.

23:29 I vibe-coded this.

23:32 This is based on the ACDC like IETF,

23:36 whatever it's called specs.

23:37 Everything's like very much to spec.

23:39 I didn't have the time or

23:41 capability to spin up all the

23:42 infrastructure to make this real. So

23:44 you've got this contract is like I said,

23:48 this is a real contract. I found it on

23:49 the SEC's website. I was like, I want

23:51 something; it's 45 pages,

23:52 really dense, really complex. And I

23:56 used that for this demo. So, this would

23:59 be the inception event for let's see,

24:04 this is the lessor. So, the property

24:06 owner, and this follows,

24:08 everything that you technical people in

24:10 here are familiar with all of Sam's

24:13 fields. Same with this one. You've

24:16 got the AID in there, somewhere. I think

24:19 it's the I and then you've got this

24:22 building. So, this digital twin with an

24:24 AID, public key and then it

24:27 shows

24:29 it shows where ..

24:32 I don't have the ACDC white paper

24:35 IETF spec memorized. So, I get kind of

24:37 lost when I'm looking like which one is

24:40 the actual issuer, but it would be AO6.

24:46 There it is. Okay. So that's the one

24:48 that's the lessor. Now we've got

24:50 AIDs for the lessor or the lessee in the

24:53 building. So then

24:55 we would

24:57 issue the building identity credential.

24:59 So this would be issued by the lessor

25:02 that attests to the building and gives

25:06 the attributes about the building.

25:10 This is establishing the idea of the

25:12 building that can be pulled into this

25:13 concept of contract credential. We've

25:16 got the lease. I don't know where I

25:19 put the PDF if I had it.Tthis is

25:21 the actual language from the lease. This

25:23 is how you could take a markup language

25:25 to then

25:28 the prose version. But if

25:30 you look at it with X-ray vision, you're

25:31 seeing this behind the scenes.

25:34 And then this is what's populating

25:38 the ACDC schema or for a W3C [credential, red.] it'd be

25:42 just like the JSON in the VC schema.

25:45 That's how you're having a one

25:46 to one mapping between the contract and

25:48 the credential. And then that whole data

25:50 object can be signed. You've got

25:53 ideally the same public private key pair

25:56 is signing the PDF as it's signing the

26:00 data model and the credential. It should

26:01 all be the same. That's how you can like

26:03 bind everything together. And then

26:06 you've got, let's see, lessee receives the

26:08 credential now acts as the issuer. Oh,

26:09 this is where .., just to show the delegated

26:12 and the chaining mechanism, this is

26:13 where the lessee can create its own access

26:17 credential. Let's say this is for an

26:18 employee. So they issue it to the

26:19 employee.

26:21 – I'll ask a question, but please repeat

26:22 it as well for your mic.

26:24 – Oh yeah. Yeah, definitely.

26:25 – What, it's a bit off topic, but how

26:30 much time do you think will we have

26:34 to endure before this becomes all

26:37 graphic like with puppets? Lessor, lessee…

26:41 You can click on them.

26:43 – Yeah, that's what it should be.

26:44 Totally.

26:45 – What do you think? What kind of… Please

26:49 repeat the question.

26:51 – Yeah.

26:53 – How soon? How much time?

26:54 Yeah.

26:55 So, I mean, this was me. I built this I

26:59 built all of this in about 4 hours

27:01 late at night when I needed to get

27:03 what was due. I forgot what

27:05 the due date was for the slides, but I

27:07 was like, "Oh my god, I still haven't

27:08 done them yet." So, I did everything

27:10 using Claude and Cursor in including

27:13 building this in about 4 hours.

27:16 I could probably turn this into

27:17 a much prettier UI. This is

27:20 basically a one-shot attempt.

27:23 I mean Opus 4.7 did all everything

27:26 you're seeing here is like me working

27:28 with Opus 4.7.

27:30 – I'm just unaware are there already

27:33 toolkits to make it more

27:36 graphically [attractive, red.]? The question is on

27:38 UI/UX of all of this. I don't know.

27:43 Decentralized identity tends to have

27:45 a pretty bad UI/UX in general. It's hard.

27:48 Some companies have done a much

27:50 better job than others. I would

27:53 prefer to see it. Again, I'm really just

27:55 trying to show just like how it works,

27:58 the nuts and bolts using the actual

28:00 ACDC spec. But yeah, there's no way I

28:03 would show like build a product that

28:05 looked like this to like an apartment

28:08 manager. There's zero way. This is all

28:10 behind the hood.

28:11 – I think that's the solution, I think, to

28:12 what you're saying is I don't think

28:14 there's going to be

28:16 a one-way-fits-all way to view all this.

28:18 I think it's going to be individual

28:20 apps.

28:22 That are encapsulating it all.

28:24 Yeah. We built this

28:27 amazing platform for the music industry.

28:29 It was five years ahead of its

28:31 time which is why it was hard to get off

28:32 the ground because no one knew what we

28:33 were talking about. We're taking

28:34 songwriter agreements. We're dropping

28:36 them in. We use AI to extract everything

28:38 about the legal relationship between a

28:39 songwriter and a music publisher.

28:41 Populates a W3C VC, issues the

28:43 songwriter. So now we've got this

28:45 verified connection from the

28:47 writer and the publisher. Writer writes

28:48 a new song, drops in the information

28:50 right here on their phone. Boom, shows

28:52 up instantly on the publisher side. It's

28:54 tracking from the contract. It's almost

28:56 like the data is getting stamped by the

28:58 contract as it goes through the pipe.

28:59 It's amazing, but no one understands it.

29:03 The identity thing, no one cares that we

29:05 built this cool thing where you can like

29:07 click the credential, it flips over and

29:09 shows the JSON schema. Everyone's like,

29:12 how does that help me? So that product,

29:14 I don't want to say it failed. It was

29:16 like a great product and it actually

29:18 this one feature of that product is now

29:21 what is getting a ton of interest and is

29:23 working for us and we will Trojan-horse the

29:26 identity stuff back in, eventually, but

29:28 but yeah UI/UX is just hard with this

29:31 stuff.

29:32 – More comment than question at this

29:35 point

29:36 On this model from a physical

29:39 security standpoint you said

29:41 this is a management company for an

29:43 apartment building. Most places today

29:46 have a keypad out in front that you put

29:49 in and it calls up or whatever lets you

29:51 in.

29:52 They're made by two manufacturers.

29:57 You can buy the three keys that open

30:00 that box everywhere in the world.

30:03 For $18 and there's a button inside that

30:07 overrides the system and opens the door.

30:10 So to your point, if it was on the

30:12 phone, you could completely do away with that!

30:14 You have biometric. You marry

30:16 biometric to cryptographic to legal…

30:18 – That would save these folks…

30:21 So much money cuz they they have to go

30:23 pay insurance. You got to pay insurance.

30:26 Anytime there's a risk, you got to

30:27 insure it and that's a transaction cost

30:28 that doesn't need to be there. That's

30:29 what I'm saying. Like

30:31 this magic cryptography can just like

30:33 really reduce transaction cost

30:34 everywhere you look. And and like I

30:35 said, once you see the pattern,

30:38 it's really hard to unsee. Now

30:39 everything I look, I'm like, "Oh god,

30:41 why do we do it that way?" But

30:43 yeah, his would be great. And this

30:44 would be instead of most

30:47 apartment complexes don't let you do

30:48 Airbnb, but people still do it because

30:50 you can find ways to trade the key fobs.

30:52 Like this technically kills that. Or you

30:54 can put in place rules and governance

30:57 that says you may rent out your

30:59 apartment, but the other person must be

31:01 verified and have a credit score over X.

31:03 Like you can build in the logic. They

31:05 get the credential, they buy a metric,

31:07 they show it, they go in. It's

31:10 really powerful what you can do with

31:12 this stuff. – You have five more minutes.

31:15 Okay, cool. So this is the example of

31:17 showing it to the smart lock and this is

31:19 what's happening is, it's checking this

31:21 is like checking all the KELs, the

31:24 TELs, traversing the nodes,

31:27 Again, that didn't actually just happen

31:28 with the true KERI stack, but this is

31:32 true to the ACDC spec and like how it

31:34 would happen and access granted

31:37 this is the tenant, that was the

31:39 tenant with that AID, they can get in

31:41 24/7 to street 105 open it up and then

31:44 this would be what happens if

31:48 the tenant doesn't pay their rent and

31:51 the lease is terminated. Therefore, all

31:54 building access credentials of employees

31:55 are automatically revoked. That's what

31:57 this one would be. Let's see. Attempt

32:00 access with revoked lease. So, it kind

32:02 of does the same thing. It's

32:04 running backwards and checking the TEL,

32:06 seeing that that edge on the lease has

32:09 been this TEL was revoked. It has the

32:11 registry AID, the TEL sequence. You

32:14 can, check the signing keys at

32:16 the time. Access denied. Reason,

32:19 upstream credential revoked, lease

32:21 contract, lease is terminated.

32:24 That's to me, much

32:27 easier to understand than the music

32:28 stuff, and it's fun to apply

32:30 this to other things. So that is

32:34 that's the demo. That's that. And I

32:37 think that is kind of the end of

32:42 the presentation.

32:44 So yeah, that's what we're doing.

32:45 [applause]

32:49 So I guess we have

32:51 five minutes for questions.

32:53 – Yeah.

32:55 Yeah. So what's the… Have you studied

32:58 you got a lawyer [inaudible]? Have you

33:00 studied the enforcability angle of this?

33:03 Yeah, there's

33:05 no enforcability issues cuz you start

33:09 with the legal prose contract as the

33:12 base.

33:15 Yeah, it's all enforceable because you

33:17 have it all like you've got it, you

33:19 know, different states. in Wyoming's

33:21 been pushing the boundaries on this and

33:22 others are smart contracts are

33:24 legally enforceable like blockchain

33:25 based smart contracts. That's fine but

33:29 we're not going to get rid of human

33:33 communication and legal prose.

33:35 it's not going away anytime

33:38 soon. I don't think we're going to have

33:40 some domain-specific coding language

33:42 where the language you write is the

33:46 contract and it is the code.

33:49 I just don't see that happening.

33:51 I think you have to take this

33:53 sort of hybrid approach of

33:55 there's disputes. It's going to

33:57 have to go in front of some sort of

33:59 judge or arbitrator or mediator or

34:00 something. And they can't read the

34:03 case, they can't read the

34:05 ACDC spec. It's not going to happen.

34:07 You still have to have that original

34:10 legal prose. You can pull it out, you

34:13 can hash it, “SAID” it. I don't

34:16 know how it's Sam likes to pronounce it.

34:18 It's different every time.

34:19 Said it.

34:20 Said

34:20 said. Okay. You can said it.

34:22 So, it's just a hash digest. You can do

34:24 whatever you want, but just don't

34:26 think you'll ever get around needing a

34:28 contract.

34:29 – Is it just me …

34:33 KERI is incredibly powerful,

34:35 but it's very hard to explain to people.

34:38 You see, have you seen that?

34:41 – Yeah. KERI especially. So, like

34:43 when I explain to the music industry, I

34:44 can't bring up KERI. I just have

34:46 to talk about

34:48 basic JSON and W3C.

34:49 [inaudible]

34:52 make it easier for consumption.

34:55 I think it just needs to be in the

34:56 back-end of products and I think you

34:59 just can't even really

35:01 explain a lot of it. It's like most

35:03 people don't know how the internet

35:04 works.

35:05 – It's got to be user experience.

35:06 – Yeah. Like 99 people% of the people

35:09 don't understand how the internet works.

35:10 – [inaudible] That's exactly where I am.

35:14 If they can connect to the

35:16 business aspect of things, they go.

35:18 Yeah. That's what we're

35:20 trying to do. We're getting closer

35:21 and we've been working at this for four

35:23 or five years now and we're

35:25 finally getting somewhere.

35:28 – We have to stop

35:29 Oh yeah. Totally.

35:33 - Just do it.

35:34 Just do it. Just use it.

35:37 Make people fight you about it.

35:39 Yeah. [applause]