Keyra companion governance
The Companion Marketplace & Agent Economy
Marketplace governance for agents, certification, permissions, and trusted digital commerce.
THE COMPANION MARKETPLACE & AGENT ECONOMY
Foundational economic framework for the Human Sovereignty Operating System
Instrument: The Companion Marketplace & Agent Economy
Function: Canonical economic framework for trust-based commerce, agent registration, certification, permission scopes, revenue models, and marketplace governance across the Human Sovereignty Operating System — enabling Companions, KAAI Agents, Families, Organizations, Banks, Telcos, Governments, Developers, and Service Providers to transact under human sovereignty, authorization chains, and accountability architecture
Version: 1.0 (Founding Framework)
Status: Subordinate to the Human Sovereignty Charter and all prior founding instruments; governed by the Companion Charter, Life Operating System, Human Digital Twin Architecture, Life Graph Architecture, Trust Vault Architecture, Device Trust Mesh, Family Trust Network, Organization Graph Enterprise Companion Framework, and KAAI Standard
Core constraint: Human sovereignty over all marketplace transactions and agent grants. No platform, institution, agent, or marketplace operator holds standing root authority over a human's economic estate or agent authorization graph by default.
Preamble
Companion Marketplace ecosystem for Humans, Companions, Agents, Families, Organizations, Banks, Telcos, Governments, Developers, Service Providers. Must support Human Sovereignty, Companion Governance, Agent Accountability, Trust-Based Commerce, Global Scale. App Store of the Agent Era. Economic layer of Companion ecosystem.
The digital age promised convenience and delivered extraction. Humans accumulated subscriptions across hundreds of services, authorizations in opaque permission dialogs, financial relationships in institutional silos, and agent-like automations that act without accountability, portability, or revocable grant chains. Each marketplace optimized for platform revenue — attention, engagement, data extraction — not for human sovereignty. Each agent deployment optimized for velocity — API keys in environment variables, OAuth tokens without scope decay — not for trust.
Commerce without human authorization is theft with better UX. Agents without accountability are liability with better latency. Trust without scoring is folklore. The Human Sovereignty Charter establishes rights — ownership, control, portability, inspectability, deletion, revocation, inheritance. Rights require economic architecture that implements them when agents multiply, transactions cross borders, families govern children, enterprises deploy fleets, banks move money, and governments issue permits.
This document defines the Companion Marketplace & Agent Economy — the foundational economic framework through which Keyra Companions, KAAI-authorized agents, Families, Organizations, Banks, Telecommunications carriers, Governments, Developers, and Service Providers discover, certify, authorize, transact, and settle under explicit constitutional governance.
The Companion Marketplace connects Humans, Companions, Agents, Families, Organizations, Banks, Telcos, Governments, Developers, and Service Providers into a unified trust-based commerce fabric. It is the economic layer of the Companion ecosystem — the App Store of the Agent Era, subordinate to human sovereignty rather than platform attention economics.
The Marketplace is designed to scale from one authorized agent to one hundred billion agents — each operating under human-granted permission scopes, trust scores, certification levels, and audit chains — without redesigning the constitutional invariants that subordinate all commerce to human authority.
Preamble — Historical Context
The history of digital marketplaces is a history of platform capture. Application stores authenticated developers to platforms, not agents to humans. Cloud marketplaces sold compute to enterprises without agent accountability semantics. Plugin ecosystems extended applications without portable authorization. Early agent marketplaces listed API wrappers without certification, trust scoring, or revocation infrastructure. Each solved distribution. None solved sovereign commerce — transactions where the human remains root grantor, inspector, and revoker.
When artificial intelligence became persistent — Companions that negotiate, agents that purchase, twins that represent financial intent — the application marketplace model collapsed. An agent cannot purchase responsibly without scoped financial grants. A family cannot protect children without child-safe agent certification. A bank cannot settle without authorization chain attestation. A government cannot issue permits through agents without audit and revocation. The Companion Marketplace closes the economic trust gap.
Preamble — Relationship to Founding Instruments
This Framework is subordinate to the Human Sovereignty Charter. Where marketplace technical requirements appear to conflict with human sovereignty, human sovereignty prevails and marketplace implementations must be corrected. The Companion Marketplace integrates with the Trust Vault Architecture (financial credentials, agent certificates, transaction audit), Device Trust Mesh (device-bound authorization, presence-gated purchases), Life Graph Architecture (agent nodes, trust edges, ownership graphs), KAAI Standard (agent identity, authorization certificates, accountability), Companion Charter (Companion-mediated commerce), Family Trust Network (family budgets, child-safe agents), Organization Graph Enterprise Companion Framework (enterprise agent fleets), and Life Operating System (domain-scoped spending policies).
No single instrument owns the marketplace. The human owns the authorization graph. The Life Graph indexes agent relationships. The Companion mediates human intent to agent operations. KAAI agents receive derived access through authorization chains rooted in Trust Vault-held keys and human presence proofs. Together they form the Human Sovereignty Operating System for durable trust-based commerce.
Preamble — Normative Language
Throughout this document:
- MUST, MUST NOT, REQUIRED, and SHALL denote absolute requirements for Companion Marketplace conformance
- SHOULD and RECOMMENDED denote strong guidance with documented exceptions permitted only under human or institutional policy with audit
- MAY denotes optional capability
- Prohibited actions are void regardless of technical success; marketplace runtimes MUST reject them
Conformance is measured at three layers: constitutional (subordination to human authority), technical (registration, certification, authorization, settlement), and operational (audit, revocation, dispute resolution, incident response).
Preamble — Architectural Placement
The Companion Marketplace sits beneath human sovereignty and above application silos — the economic substrate on which vault, graph, companion, device, and agent layers transact:
┌──────────────────────────────────────────────┐
│ Human Sovereignty Charter │
├──────────────────────────────────────────────┤
│ Companion · Twin · Life Graph · Vault │
├──────────────────────────────────────────────┤
│ KAAI Standard · Device Trust Mesh │
├──────────────────────────────────────────────┤
│ Companion Marketplace (this document) │
│ Registration · Certification · Commerce │
├──────────────────────────────────────────────┤
│ Agents · Services · Settlement · Trust │
├──────────────────────────────────────────────┤
│ Developers · Banks · Telcos · Gov │
└──────────────────────────────────────────────┘Applications are replaceable. Agent authorization graphs and transaction audit chains are not — they belong to the human and persist across platform replacements when export ceremonies execute.
Preamble — Scope of Support
The Companion Marketplace supports:
| Domain | Entities |
|---|---|
| Humans | Sovereign grantors, purchasers, inspectors, revokers |
| Companions | Commerce mediators, negotiation orchestrators, spending policy enforcers |
| KAAI Agents | Certified executors of scoped commerce and service operations |
| Families | Family agents, child-safe catalogs, shared budgets, approval structures |
| Organizations | Enterprise agent fleets, department scopes, compliance overlays |
| Banks | Financial agents, payment settlement, authorization chains, fraud prevention |
| Telcos | Subscriber agents, identity provisioning, eSIM commerce, network trust |
| Governments | Citizen services agents, permit agents, national certification |
| Developers | Agent publishers, service providers, certification applicants |
| Service Providers | Hosted agents, APIs, human-facing services under certification |
The Companion Marketplace serves:
- Individuals — personal agent authorization under sole human authority
- Families — federated agent catalogs with governed child access
- Organizations — institutional agent deployments subordinate to human members
- Governments — lawful certification and citizen service channels without root authority usurpation
- Future Generations — inherited agent grants, succession of authorization, legacy commerce policies
PART I — Definition
Section 1.01 — What Is a Companion Marketplace?
The Companion Marketplace is a human-sovereign, trust-based, cryptographically attested economic architecture — comprising agent registration, certification, permission scopes, trust transactions, revenue models, and governance frameworks — through which KAAI agents, Companion extensions, and certified services are discovered, authorized, purchased, and settled under explicit constitutional subordination to the Sovereign Human.
The Companion Marketplace:
- Registers agents — identity, ownership, certification, verification, sponsorship, publishing, retirement
- Certifies trust levels — Experimental through Critical Infrastructure Certified
- Scopes permissions — data, financial, communication, family, enterprise, government rights
- Executes trust transactions — scoring, guarantees, escrow, reputation, recovery
- Models economics — subscription, usage, transaction, revenue sharing, licensing, fees
- Governs publication — audit, approval, compliance, revocation, retirement
- Federates globally — cross-border discovery, certification, authorization, commerce
- Protects security — agent isolation, vault binding, identity and financial protection
- Scales civilization-wide — from one agent to one hundred billion agents
The Companion Marketplace is the economic layer of the Human Sovereignty Operating System.
Section 1.01a — Companion Marketplace as Constitutional Implementation
The Human Sovereignty Charter declares rights. The Trust Vault Architecture declares persistence. The Device Trust Mesh declares physical anchoring. The Companion Marketplace declares commerce — the material condition without which agents act in institutional gray zones and humans lose inspectability over economic life. A Sovereign Human whose agents operate only through platform OAuth without exportable grant chains does not possess economic sovereignty in any operational sense. A Sovereign Human whose purchases occur only inside walled gardens does not possess portability in any commercial sense.
The Companion Marketplace therefore occupies a position analogous to commercial law and payment systems in physical civilization — not extraction infrastructure, but trust infrastructure that binds economic action to human intent. Without marketplace architecture, agent commerce becomes platform roulette.
Section 1.01b — Actors Served by the Companion Marketplace
| Actor | Marketplace role |
|---|---|
| Sovereign Human | Root grantor, purchaser, inspector, revoker |
| Keyra Companion | Mediator, negotiator, policy enforcer — never root financial authority |
| KAAI agent | Certified executor within scoped grants |
| Developer | Publisher subject to certification and audit |
| Service Provider | Hosted capability under certification and SLA |
| Family guardian | Child agent approver, budget administrator |
| Organization | Enterprise catalog custodian — not human root |
| Bank | Settlement participant, authorization chain verifier |
| Telco | Identity and provisioning commerce participant |
| Government | Certifier and citizen service publisher — not standing owner |
| Future beneficiary | Inherited agent grant recipient per Legacy instruments |
Each actor's relationship to the marketplace is defined, bounded, auditable, and revocable — except the human root, whose sovereignty is inalienable.
Section 1.02 — What Is Not a Companion Marketplace?
The Companion Marketplace is not:
- An application store alone — binary distribution without agent accountability, trust scoring, or portable authorization
- A cloud marketplace alone — compute and API listing without human-rooted grant chains
- A plugin ecosystem alone — application extensions without KAAI certification and revocation semantics
- An agent marketplace alone — API wrapper listings without Companion integrations, vault binding, and family governance
- Attention economics — engagement optimization, dark patterns, or surveillance monetization
- Platform financial capture — mandatory payment rails that prevent human inspection and export
- Compulsory agent registry — centralized inventory without individual revocation and portability
- Unaccountable automation — agents that act without certification, audit, and human-granted scopes
If marketplace transactions cannot be inspected and revoked by the human root, they violate the Human Sovereignty Charter. If agents purchase without authorization chain validation, they violate the KAAI Standard. If child-facing agents bypass family approval structures, they violate the Family Trust Network.
Section 1.03 — Distinctions Among Marketplace Systems
Application Store (App Store)
Application stores — Apple App Store, Google Play, Microsoft Store — distribute binaries to devices. They authenticate developers to platforms. They review for malware and policy compliance. They optimize for platform revenue share — typically 15–30%. They do not model agent permission scopes, trust decay, family child-safe certification, cross-vendor authorization portability, or human-rooted financial grants.
The Companion Marketplace incorporates application distribution where agents require local execution — but distribution is one function among registration, certification, authorization, settlement, and audit. An app without KAAI agent certificate is not a marketplace agent — it is a legacy application.
Cloud Marketplace
Cloud marketplaces — AWS Marketplace, Azure Marketplace, GCP Marketplace — sell SaaS, AMIs, and APIs to enterprise tenants. They excel at billing aggregation and procurement compliance. They treat the enterprise tenant as customer. Individual humans within tenants are invisible. Agent accountability, family budgets, device-bound authorization, and Trust Vault credential binding are absent.
The Companion Marketplace supports enterprise procurement overlays — but enterprise catalogs remain subordinate to member human sovereignty for personal partitions and portable agent grants.
Plugin Ecosystem
Plugin ecosystems — browser extensions, IDE plugins, productivity add-ons — extend host applications with narrow APIs. Authorization is host-mediated OAuth. Revocation is host-controlled. Portability dies when the host application changes. No standardized trust scoring, certification levels, or financial scope semantics exist.
The Companion Marketplace may list Companion extensions and Twin projections — but extensions MUST register as KAAI agents or Companion modules with explicit scopes, not opaque host plugins.
Agent Marketplace (industries Generic)
industries agent marketplaces — early GPT stores, workflow automation directories, MCP server listings — optimize discovery of capabilities. They rarely require: hardware presence for high-risk actions, Trust Vault credential storage, Device Trust Mesh binding, certification tiers, trust escrow, complaint frameworks, government accreditation, or cross-border authorization federation.
The Companion Marketplace defined here is human-rooted — platform discovery is a feature, not the foundation.
Companion Marketplace (This Framework)
The Companion Marketplace integrates discovery with governance — every listed agent carries certification level, permission scope manifest, trust score history, publisher identity, audit chain, and human-grant requirement. Commerce flows through authorization, not attention. Settlement attaches to trust transactions, not engagement metrics.
Section 1.03a — Illustrative Scenario
Consider a sovereign professional: she authorizes a KAAI travel agent (Trusted certification) with financial scope capped at $5,000 per transaction and Device Trust Mesh requirement above 0.7 for itinerary changes affecting visas. Her Companion mediates negotiation — the agent proposes flights; Companion presents comparison; she grants per-trip authorization with Keyra Key signature.
Her family operates a Family Marketplace partition — child-safe education agents (Verified certification) with no financial scope; teenage son has shopping agent (Experimental) with $50 weekly budget and parent approval for purchases above $25. Her employer deploys Enterprise Marketplace — compliance agent (Enterprise Certified) reads Organization Vault contracts; HR agent accesses bounded employee data per role.
When a fraudulent agent attempts purchase, Trust Escrow holds settlement pending trust score verification. When she revokes travel agent grant, revocation propagates within SLA; agent certificates invalidate; pending transactions cancel. When she exports Agent Authorization Pack, grants port to new Companion without platform gatekeeping.
| System | Human root | Agent accountability | Financial scopes | Family governance | Portable grants |
|---|---|---|---|---|---|
| App Store | Platform account | App review only | IAP only | Parental controls partial | No |
| Cloud Marketplace | Enterprise tenant | SLA only | Billing aggregate | None | No |
| Plugin ecosystem | Host app | Extension policy | None | None | No |
| Agent marketplace | Platform OAuth | Variable | API keys | None | Rare |
| Companion Marketplace | Sovereign Human | KAAI + certification | Vault-bound scopes | Family Constitution | Required |
Section 1.04 — Why Agents Require a New Economic Model
Applications requested human attention. Agents request authorization — persistent, scoped, decaying grants to act on human behalf across time, devices, and institutions. The economic model must answer:
| Question | Application era answer | Agent era requirement |
|---|---|---|
| Who authorizes? | Login session | Human grant chain with scopes |
| Who is liable? | Terms of service | Agent accountability + publisher |
| How is trust measured? | Star ratings | Trust scores + certification + audit |
| How do families govern? | Screen time | Child-safe certification + approval structures |
| How do enterprises comply? | SSO | Enterprise certification + compliance agents |
| How do banks settle? | Card network | Authorization chains + trust escrow |
| How do governments participate? | Portal login | Government-certified agents + lawful audit |
| What happens on revoke? | Logout | Certificate invalidation + transaction halt |
Agents that purchase, negotiate, transfer, and represent require trust-based commerce — not attention-based commerce. The Companion Marketplace is the economic architecture for that transition.
Section 1.05 — Agent Economy Definition
The Agent Economy is the aggregate of authorized agent transactions — subscriptions, usage charges, settlements, revenue shares, trust fees — occurring under Companion Marketplace governance. It is not cryptocurrency speculation. It is not platform tokenomics. It is authorized economic activity where every transaction cites human grant, agent certificate, trust score threshold, and audit reference.
The Agent Economy MUST remain subordinate to human sovereignty. GDP of agent transactions is measurable; sovereignty of humans is not negotiable.
Section 1.06 — Marketplace Runtime Architecture
The Marketplace Runtime validates every agent operation through a pipeline — not optional middleware:
Agent Request → Scope Validator → Certification Gate →
Trust Score Gate → Spending Control → Presence Check →
Authorization Chain → Settlement → Audit AppendEach stage MUST fail closed. Partial pipeline success without full validation is prohibited. Runtime implementations MUST NOT cache authorization decisions beyond policy-declared TTL without revalidation of trust score and grant status.
Section 1.07 — Relationship to Device Trust Mesh
High-consequence marketplace actions MUST bind to Device Trust Mesh requirements per KAAI Standard and Device Trust Mesh Architecture. Financial authority level A3 and above REQUIRES device trust score above human-declared threshold and presence level P4 minimum unless emergency instrument documented in Authorization Vault. Device revocation MUST halt pending agent transactions tied to that device within SLA.
Section 1.08 — Relationship to Trust Vault
Agent certificates, financial credentials, transaction audit hashes, and spending policies MUST reside in Trust Vault Agent and Authorization partitions — not in marketplace operator databases as root secrets. Marketplace operators MAY hold federated registry metadata and encrypted audit replicas; they MUST NOT hold human root keys or unaudited financial credentials.
Section 1.09 — Comparative Architecture Table
| Capability | App Store | Agent API directory | Companion Marketplace |
|---|---|---|---|
| Human root grants | No | Partial | Required |
| Scope manifests | No | Rare | Required |
| Certification tiers | App review | None | Six levels |
| Trust scoring | Star ratings | None | Multi-dimensional |
| Trust escrow | No | No | Supported |
| Family governance | Limited | No | Family Constitution |
| ACEP export | No | No | Required |
| Authorization chains | OAuth | API key | KAAI + vault + device |
| Revocation SLA | Account delete | Manual | < 60s personal |
PART II — Foundational Principles
Section 2.01 — Human Ownership
The Sovereign Human owns the agent authorization estate absolutely. Ownership includes all agent grants, marketplace subscriptions, spending policies, certification trust relationships, and transaction history references. Ownership is inalienable — organizations may custodian enterprise agent fleets during employment, but personal agent grants remain human-rooted unless explicit voluntary transfer executes.
Implementations MUST represent agent ownership in Life Graph as Human → authorizes → Agent. No edge may assign Platform → owns → Agent without explicit human-initiated migration where human retains revocation root.
Section 2.02 — Human Authorization
Every marketplace transaction and agent action MUST cite Human Authorization — validated grant chain from human root, scoped to permission manifest, presence level where required, and trust score threshold. Default deny. No grant — no transaction.
Human Authorization integrates KAAI Authorization Certificates, Trust Vault financial partition policies, Device Trust Mesh presence proofs, and Companion-mediated confirmation for consequential purchases.
Section 2.03 — Agent Accountability
Agent Accountability means every agent carries identifiable publisher, certification level, audit chain, and liability attribution. Agents MUST NOT act anonymously at consequential scope. Experimental agents carry explicit warnings. Critical Infrastructure agents carry publisher bonds and government accreditation.
Accountability failures trigger certification downgrade, marketplace suspension, and trust score penalties — not silent continuation.
Section 2.04 — Trust-Based Commerce
Commerce in the Companion Marketplace is trust-based, not attention-based. Transactions require trust score thresholds, certification minimums, and optional trust escrow. Discovery MAY rank by relevance but MUST NOT rank by undisclosed payment for placement without human-visible sponsorship labels.
Trust-Based Commerce integrates Trust Vault reputation refs, Device Trust Mesh device binding, and marketplace trust transaction layer (Part IX).
Section 2.05 — Permission-Based Access
Agents receive Permission-Based Access — never standing root. Scopes declare data, financial, communication, family, enterprise, and government rights explicitly. Scope expansion requires new human grant. Scope decay retires unused permissions automatically per policy.
Permission manifests MUST be human-inspectable, machine-validated, and exportable in Agent Authorization Pack.
Section 2.06 — Transparency
All marketplace fees, revenue shares, sponsorship relationships, and data accesses MUST be transparent to the human root. Hidden fees are prohibited. Undisclosed agent data exfiltration is prohibited. Audit logs MUST be human-inspectable and hash-chained to Trust Vault.
Section 2.07 — Portability
The Sovereign Human MUST export marketplace state in Agent Commerce Export Pack (ACEP) — agent grants, certification refs, subscription records, spending policies, transaction audit hashes — without vendor gatekeeping. ACEP interoperates with Trust Vault Export Pack and Device Trust Export Pack.
Portability MUST survive platform migration, employment termination, and carrier change.
Section 2.08 — Fair Competition
The Companion Marketplace MUST enable Fair Competition — third-party agents compete on certification, trust scores, and capability — not on platform lock-in, undisclosed preferential API access, or anti-portability terms. Marketplace operators MUST NOT use human transaction data to advantage proprietary agents without explicit human consent.
Section 2.09 — Global Interoperability
Agent registration, certification, and authorization MUST interoperate globally through federated Global Agent Registry (Part XVIII). National overlays accredit without usurping human root. Cross-border commerce respects human grant and local lawful requirements without mandatory single-marketplace capture.
Section 2.10 — Principle Enforcement Matrix
| Principle | Technical enforcement | Human-facing enforcement |
|---|---|---|
| Human ownership | Human-root grants only | Agent dashboard ownership |
| Human authorization | Default deny engine | Grant review UI |
| Agent accountability | Publisher + cert binding | Agent detail liability view |
| Trust-based commerce | Trust score gates | Pre-purchase trust display |
| Permission-based access | Scope manifest validation | Scope inspector |
| Transparency | Fee disclosure schema | Transaction receipt detail |
| Portability | ACEP export | One-click export |
| Fair competition | Neutral discovery API | Sponsorship labels |
| Global interoperability | Federated registry protocol | Cross-border agent badge |
Violations MUST surface as errors — not silent degradation.
Section 2.11 — Tension Resolution
Principles occasionally tension:
- Authorization vs convenience — low-risk Experimental agents MAY use streamlined grants; high-risk Financial agents never waive presence
- Enterprise procurement vs personal sovereignty — dual catalogs; personal grants survive employment
- Trust escrow vs velocity — escrow optional per human policy; mandatory for Critical Infrastructure
- Global interoperability vs national law — lawful local restrictions apply; human revocation remains universal
Resolution always favors human root authority after policy-declared emergency expiry.
Section 2.12 — Illustrative Scenario — Principle Collision
A enterprise compliance agent (Enterprise Certified) requests access to personal Health Vault partition for wellness program. Enterprise policy mandates participation. Human sovereignty prevails: enterprise agent receives Organization Vault occupational health only; personal Health Vault requires separate human grant. Marketplace runtime rejects cross-partition access attempt; audit logs incident; enterprise administrator receives policy correction notice — not human override.
PART III — Marketplace Architecture
Section 3.01 — Marketplace Architecture Overview
The Companion Marketplace comprises core infrastructure and domain-specific stores — each store curates catalogs, certification requirements, and governance overlays while sharing registration, trust transaction, and settlement layers.
┌─────────────────────────────────────────────┐
│ Marketplace Core │
│ Registry · Certification · Settlement │
├──────────┬──────────┬──────────┬────────────┤
│Companion │ Agent │ Family │ Enterprise │
│ Store │ Store │ Store │ Store │
├──────────┼──────────┼──────────┼────────────┤
│Government│ Education│Healthcare│ Banking │
│ Store │ Store │ Store │ Store │
├──────────┴──────────┴──────────┴────────────┤
│ Telecommunications Store │
└─────────────────────────────────────────────┘Section 3.02 — Companion Store
The Companion Store distributes Companion configurations, personality modules, skill packs, Twin projection templates, and Companion-native extensions. All listings require Companion Charter conformance review. Companion Store transactions use Companion Fees model (Section 8.10). Companion modules MUST NOT hold root vault keys.
Section 3.03 — Agent Store
The Agent Store is the primary catalog for KAAI agents — travel, banking, shopping, legal, and domain agents per Part IV taxonomy. Agent Store listings require KAAI registration (Part V), minimum certification level declaration, and permission scope manifest publication. Default discovery ranks by trust score and certification — not undisclosed payment.
Section 3.04 — Family Store
The Family Store curates family-appropriate agents — child-safe, education, family services — with mandatory Family Trust Network conformance. Family Store agents MUST declare age appropriateness, parental approval requirements, and financial scope restrictions. Family guardians administer catalog visibility per Family Constitution.
Section 3.05 — Enterprise Store
The Enterprise Store serves Organization Graph deployments — department agents, compliance agents, finance agents, HR agents. Enterprise Store requires Organization Graph Enterprise Companion Framework conformance. Enterprise agents operate on Organization Vault partitions; personal agent grants remain separate.
Section 3.06 — Government Store
The Government Store publishes citizen service agents — identity, permits, tax, healthcare, education, national services — with Government Certified or Critical Infrastructure certification. Government Store agents MUST NOT usurp human root; they execute lawful services under citizen grant.
Section 3.07 — Education Store
The Education Store distributes curriculum agents, tutoring agents, learning companions, and institutional education integrations. Education Store agents require Verified minimum certification; child-facing agents require child-safe badge and COPPA-equivalent conformance per jurisdiction.
Section 3.08 — Healthcare Store
The Healthcare Store lists clinical support agents, patient navigation agents, and health record integrations agents. Healthcare Store agents require Trusted minimum certification; PHI access requires Health Vault partition grant and HIPAA-equivalent audit per jurisdiction.
Section 3.09 — Banking Store
The Banking Store hosts financial agents — payments, transfers, investments, insurance, credit — with Enterprise Certified or Government Certified minimum for consequential financial scope. Banking Store integrates bank settlement rails and authorization chain verification (Part XIII).
Section 3.10 — Telecommunications Store
The Telecommunications Store distributes subscriber agents, eSIM provisioning agents, identity agents, and network trust agents. Telco-published agents require carrier accreditation overlay subordinate to human root (Part XIV).
Section 3.11 — Store Interoperability
Stores share Marketplace Core services — registration, certification validation, trust transactions, settlement — but MAY apply domain-specific certification minimums. An agent MAY list in multiple stores when meeting each store's requirements. Store-specific policies MUST NOT weaken human root authority.
Section 3.12 — Store Governance Table
| Store | Minimum certification | Vault partition | Approval structure |
|---|---|---|---|
| Companion | Verified | Companion Vault | Human root |
| Agent | Experimental+ | Agent Vault | Human root |
| Family | Verified+ | Family Vault | Guardian |
| Enterprise | Enterprise Certified | Organization Vault | Org admin + human |
| Government | Government Certified | Per lawful scope | Citizen grant |
| Education | Verified | Family/Education | Guardian for minors |
| Healthcare | Trusted | Health Vault | Human root |
| Banking | Enterprise Certified | Asset/Authorization | Human + bank chain |
| Telecommunications | Trusted | Identity Vault | Human root |
PART IV — Agent Categories
Section 4.01 — Agent Taxonomy Overview
KAAI agents in the Companion Marketplace organize into domain taxonomies — each taxonomy declares typical permission scopes, certification recommendations, and store placement. Taxonomy guides discovery; it does not limit human authorization creativity.
Section 4.02 — Travel Agents
Travel Agents — itinerary planning, booking, visa assistance, disruption rebooking. Typical scopes: communication (airlines, hotels), financial (bookings capped), data (passport refs from Identity Vault). RECOMMENDED certification: Trusted. Device Trust Mesh binding RECOMMENDED for international itinerary changes.
Section 4.03 — Banking Agents
Banking Agents — balance inquiry, payments, transfers, fraud alerts. Typical scopes: financial (bank APIs), data (account refs). REQUIRED certification: Enterprise Certified minimum for transfers; Trusted for inquiry-only.
Section 4.04 — Investment Agents
Investment Agents — portfolio monitoring, rebalancing proposals, trade execution. Typical scopes: financial (brokerage APIs), data (Asset Vault). REQUIRED certification: Enterprise Certified. Human confirmation REQUIRED for trades above policy threshold.
Section 4.05 — Healthcare Agents
Healthcare Agents — appointment scheduling, record retrieval, medication reminders. Typical scopes: health (Health Vault), communication (providers). REQUIRED certification: Trusted; Government Certified for national health system integrations.
Section 4.06 — Education Agents
Education Agents — tutoring, curriculum delivery, progress tracking. Typical scopes: data (education records), communication (institutions). REQUIRED certification: Verified; child-safe badge for K-12.
Section 4.07 — Learning Agents
Learning Agents — skill acquisition, language learning, professional development — distinct from institutional Education Agents. Typical scopes: data (progress), memory (learning history). RECOMMENDED certification: Verified.
Section 4.08 — Shopping Agents
Shopping Agents — product discovery, price comparison, purchase execution. Typical scopes: financial (capped), communication (retailers), data (preferences). RECOMMENDED certification: Verified for autonomous purchase; Experimental for recommendation-only.
Section 4.09 — Insurance Agents
Insurance Agents — quote comparison, policy management, claims initiation. Typical scopes: financial, data (Asset Vault, Health Vault). REQUIRED certification: Enterprise Certified.
Section 4.10 — Legal Agents
Legal Agents — document preparation, deadline tracking, legal research — not unauthorized practice of law. Typical scopes: data (documents), communication (counsel). REQUIRED certification: Trusted; publisher MUST declare jurisdictional limitations.
Section 4.11 — Government Agents
Government Agents — permit applications, tax filing, benefit enrollment, citizen services. Typical scopes: government (lawful APIs), identity (Identity Vault). REQUIRED certification: Government Certified.
Section 4.12 — Enterprise Agents
Enterprise Agents — internal workflow, compliance, document processing, departmental automation. Typical scopes: enterprise (Organization Vault). REQUIRED certification: Enterprise Certified.
Section 4.13 — Family Agents
Family Agents — household coordination, shared calendars, chore management, elder check-in. Typical scopes: family (Family Vault), communication (family members). RECOMMENDED certification: Verified; child interaction requires child-safe badge.
Section 4.14 — Companion Extensions
Companion Extensions — skills and modules extending Keyra Companion capability without independent KAAI identity. Companion Extensions register in Companion Store; they inherit Companion's grant chain and MUST NOT escalate scope without explicit human approval.
Section 4.15 — Taxonomy Cross-Reference Matrix
| Taxonomy | Primary store | Min certification | High-risk action |
|---|---|---|---|
| Travel | Agent | Trusted | Visa-affecting booking |
| Banking | Banking | Enterprise | Wire transfer |
| Investment | Banking | Enterprise | Trade execution |
| Healthcare | Healthcare | Trusted | PHI export |
| Education | Education | Verified | Minor data sharing |
| Learning | Agent/Education | Verified | None typical |
| Shopping | Agent | Verified | Purchase > cap |
| Insurance | Banking | Enterprise | Claim submission |
| Legal | Agent | Trusted | Filing submission |
| Government | Government | Government | Permit issuance |
| Enterprise | Enterprise | Enterprise | Compliance sign-off |
| Family | Family | Verified | Child communication |
| Companion Ext | Companion | Verified | Scope escalation |
PART V — Agent Registration
Section 5.01 — Registration Overview
Every marketplace agent MUST complete Agent Registration before publication — establishing identity, ownership, certification pathway, and audit root. Registration occurs in the Agent Registry — federated directory integrated with Global Agent Registry (Part XVIII).
Section 5.02 — Agent Identity
Agent Identity comprises: agent_id (globally unique), agent_name, agent_version, taxonomy_class, publisher_id, public_key, and capability_manifest. Identity MUST be cryptographically signed by publisher and anchored in Agent Registry. Identity MUST NOT impersonate human identity — agents are instruments, not persons.
Section 5.03 — Agent Ownership
Agent Ownership identifies the Publisher — developer, organization, government agency, or service provider legally responsible for agent behavior. Publisher identity MUST be verifiable. Shell publishers are prohibited for Trusted certification and above.
Section 5.04 — Agent Certification
Registration declares target certification level and initiates certification workflow (Part VI). Agents MUST NOT publish above achieved certification. Certification downgrade automatically restricts discovery and scope.
Section 5.05 — Agent Verification
Agent Verification confirms publisher identity, capability claims, and security posture — static analysis, dynamic testing, third-party audit for higher tiers. Verification evidence MUST be stored in Agent Registry with human-inspectable summary.
Section 5.06 — Agent Sponsorship
Agent Sponsorship labels commercial relationships — enterprise endorsements, government recommendations, Companion featured listings. Sponsorship MUST be human-visible. Sponsored agents MUST NOT bypass certification requirements or trust score gates.
Section 5.07 — Agent Publishing
Agent Publishing releases agent to store catalogs after registration, verification, and certification approval. Publishing requires permission scope manifest publication, privacy policy, liability attribution, and revocation contact. Publishing MAY be staged — beta channel, enterprise-only, geographic restriction.
Section 5.08 — Agent Retirement
Agent Retirement gracefully removes agents from discovery while preserving audit history. Active grants MUST receive retirement notice; humans MUST re-authorize successor agents. Retirement MUST NOT delete transaction audit chains.
Section 5.09 — Agent Registry
The Agent Registry maintains authoritative records: identity, certification status, trust scores, publisher, version history, revocation status. Registry MUST federate with Global Agent Registry. Registry queries MUST NOT expose human grant graphs — only public agent metadata.
Section 5.10 — Registration Workflow
| Stage | Requirement | Output |
|---|---|---|
| Identity | Publisher key, agent manifest |