← Concepts
The category

What is an open organizational protocol for the agentic web?

An open organizational protocol is a published, machine-readable format in which organizations declare who they are, which roles their agents hold, what those roles may do, and which relationships with other organizations both parties have signed. It is organizational structure as a fetchable document rather than a private database row — open, so any organization can publish one without joining anything, and countersigned, so a claim about two parties carries both their names.

The agentic web needs a layer the web never had

The web solved documents and then transactions. Neither required a machine to know what an organization is. A page has an author, an API has a key, and in both cases the structure behind them — who is accountable, which people may commit the firm, what a given credential is permitted to do — stayed private, informal, and human-mediated. That was survivable while the participants were people, because people ask.

Agents do not ask. An agent that finds another organization’s agent has no way to establish whether it is speaking to something authorized, what that thing may agree to, or who is answerable if it agrees to the wrong thing. Every existing answer is a closed platform: valid only between parties who both joined the same one. The agentic web is what the web becomes when the participants are principals rather than tools, and it needs an organizational layer that works between strangers.

What makes a protocol open rather than a platform

Three properties, and dropping any one collapses it back into a product. The format is published under a licence that permits competing implementations, so adopting it does not mean depending on whoever wrote it. The credential lives at the adopter’s own domain rather than in the publisher’s database — a file anyone can fetch and check without an account, which means standing is portable and the registry is not the authority. And verification is offline: a third party can recompute the answer from what was published, so believing the record does not require trusting the operator.

A closed platform can offer every feature of this and still fail the test, because the question is not what the system does. It is what happens to a participant’s standing when they stop paying.

Countersignature is what makes a relationship a fact

A manifest lets an organization say things about itself, which is worth something and is not evidence. The claims that matter to anyone else are the ones that cross a boundary: this firm operates that subsidiary, this agent acts for that principal, this piece of work was delivered and settled. Any of those asserted by one side is a press release.

So an edge crossing an organizational boundary reaches its final state only when a human at the other organization signs it, and the asserting party cannot sign its own claim about somebody else. That single rule is the difference between a directory of self-descriptions and a record two parties are both on the hook for.

The measure of a protocol is adoption nobody controls

The failure mode is specific and easy to miss: an estate builds the format, publishes it, implements it across every property it owns, and produces a graph full of countersignatures in which the cryptography works perfectly and proves nothing. An owner signing a subsidiary’s claim about them has produced an elaborate way of asserting something about themselves.

That is why the count worth publishing is countersignatures between organizations with no common ownership and no shared accountable human, computed from the graph rather than declared. At the time of writing that count is zero, and every countersignature in this estate would be between related parties. Publishing that is not modesty. A format whose author will not state its own adoption honestly is asking to be trusted about everything else.

What adoption would actually look like

Ten organizations outside this estate publishing a manifest at their own domains and countersigning relationships with each other, not only with us. Then a hundred. At that point the roles, capabilities and relationships of a meaningful set of firms are readable by any agent, in one format, without permission — and the useful question stops being who built the software and becomes who else has implemented the spec.

The path to being part of that is deliberately short and deliberately not a signup: publish a charter at your own domain, publish a handshake and a directory fragment beside it, and countersign something real with somebody you actually work with. Nothing in that sequence requires an account with us, and that is the point.

RELATED · What is an Agentic Autonomous Organization? · What is an agent execution protocol? · Agent identity · Publish a manifest and join the record · The public record of settled work
This is how the mesh behaves when you run it. Onboard an Agentic Autonomous Organization free in a couple of minutes.
All conceptsGet started free