- Resource
- Procurement account 17
- Requested value
- €18,500
- Mandate limit
- €25,000 per order
- Validity
- Until 30 Sep 2026
- Issuer
- Mandate Rail sandbox issuer
- Condition
- No additional approval
receipt:vrf_8F31Verifiable business authority infrastructure
WhoActs turns business authority into verifiable, revocable evidence—so organisations can confirm what a person or software agent may do before accepting an instruction.
Built first for product, security and compliance teams governing software-agent procurement and other high-risk business actions.
receipt:vrf_8F31Interactive product explanation · example data · not a legal decision
The missing control layer
Authentication can establish the actor. It does not answer whether this organisation authorised this action, on this resource, inside these limits, now.
One governed lifecycle
Each transition has an owner, an evidence boundary and a state the verifier can understand.
Describe the representative, permitted act, resource, limits, channels and expiry.
Apply maker–checker governance before authority can move forward.
Record that the human, provider or software agent accepts the mandate.
Create a signed credential through the configured issuer boundary.
Disclose the minimum claims a relying party needs for its decision.
Check signature, issuer, time, status, binding and requested action.
End, suspend, supersede or renew authority as circumstances change.
Built for the decision point
Express actions, limits, resources, jurisdictions, channels, approval conditions and exclusions.
Evaluate current status and exact scope at the point where an action is requested.
Present only the authority evidence the verifier needs for the transaction in front of it.
Suspend, revoke, supersede or renew authority without retrieving paper documents.
Retain receipts that show the inputs, checks, decision and reason codes at that moment.
Integrate qualified or non-qualified providers according to the actual assurance requirement.
Different actors. Different authority.
Switch representative types to see the mandate change—not just the label.
Machine action, accountable authority
Bind an agent to the organisation that appointed it, the action it may perform, the resources it may touch, its limit, expiry and human-control conditions.
Explore this use caseDecision, decomposed
The verifier evaluates integrity, trust, time, status, binding and scope—then returns an explicit result and reason code.
PASSPASSPASSPASSPASSPASSPASSPASSLocal illustrative decision using example data. It does not inspect a live credential and is not legal advice.
European wallet context
The European Digital Identity framework establishes common foundations for digital identity wallets. The proposed European Business Wallet framework extends the conversation towards company identity, secure business interaction and organisational representation.
WhoActs is building an interoperable authority layer for these environments. It is not an EU institution, official wallet, QTSP or certified trust service.
Trust through precision
The product distinguishes local sandbox behaviour, implemented connected-mode controls and work still required before production reliance.
Open the trust centreES256 demo credentials; protected production custody required
Valid, suspended, revoked and superseded mandate handling
Technical evidence and policy checks—not legal advice
For developers
Mandate Rail keeps HTTP translation, authority policy, persistence and providers behind separate typed boundaries. This example mirrors the downloadable illustrative contract; no public endpoint is advertised.
Explore the API{
"credential": "...",
"requestedAction": "place_purchase_order",
"resource": "procurement-account-17",
"jurisdiction": "DE",
"channel": "api",
"amount": 18500,
"currency": "EUR"
}
→ 200
{
"decision": "PERMITTED",
"reasonCodes": ["AUTHORITY_VERIFIED"],
"receiptReference": "vrf_8F31"
}Straight answers
WhoActs is the public brand for Mandate Rail: infrastructure for defining, issuing, presenting, checking and ending evidence of business authority.
It closes the gap between knowing who someone is and knowing whether they may perform a particular act for an organisation.
Identity answers who the actor is. Authority answers who appointed them, what they may do, on which resource, within which limits, through which channel and until when.
A digital mandate is a structured record of an appointment and its policy: principal, representative, actions, resources, limits, jurisdictions, dates, conditions, exclusions and evidence.
Not automatically. A WhoActs mandate is technical evidence. Legal effect depends on governing documents, applicable law and the transaction.
Authority, explained
7 min read · Robert Prime
Why a verified sign-in still leaves the hardest transaction question unanswered.
Read the article8 min read · Robert Prime
A practical authority checklist for agentic procurement, payments and high-risk account actions.
Read the article6 min read · Robert Prime
How to move from scanned evidence and email approvals to precise, revocable policy decisions.
Read the articleFounder-led and accountable
Website and enquiry operations run through Simon and Prime Ltd, company 13180513. Customer proof will be published only when evidence and permission support it.
Design-partner programme