Verifiable business authority infrastructure

Know who can act. Prove it before they do.

WhoActs turns business authority into verifiable, revocable evidence—so organisations can confirm what a person or software agent may do before accepting an instruction.

Built first for product, security and compliance teams governing software-agent procurement and other high-risk business actions.

Scope before action Current status Explainable decision
AUTHORITY RECEIPTWA-8842 · NOW
PRINCIPALNorthstar Components
ACTING PARTYProcurement Agent X
REQUESTED ACTIONPlace purchase order
Resource
Procurement account 17
Requested value
€18,500
Mandate limit
€25,000 per order
Validity
Until 30 Sep 2026
Issuer
Mandate Rail sandbox issuer
Condition
No additional approval
ILLUSTRATIVE POLICY RESULTPERMITTEDreceipt:vrf_8F31

Interactive product explanation · example data · not a legal decision

The missing control layer

A verified identity is not verified authority.

Authentication can establish the actor. It does not answer whether this organisation authorised this action, on this resource, inside these limits, now.

  1. 01Who appointed them?
  2. 02Which company do they represent?
  3. 03What action may they perform?
  4. 04On which account or resource?
  5. 05Up to what limit?
  6. 06Through which channel?
  7. 07Until when?
  8. 08Can they delegate?
  9. 09Has the authority been revoked?
  10. 10Was human approval required?

One governed lifecycle

Authority that can be defined, checked and ended.

Each transition has an owner, an evidence boundary and a state the verifier can understand.

  1. 01

    Define

    Describe the representative, permitted act, resource, limits, channels and expiry.

  2. 02

    Approve

    Apply maker–checker governance before authority can move forward.

  3. 03

    Accept

    Record that the human, provider or software agent accepts the mandate.

  4. 04

    Issue

    Create a signed credential through the configured issuer boundary.

  5. 05

    Present

    Disclose the minimum claims a relying party needs for its decision.

  6. 06

    Verify

    Check signature, issuer, time, status, binding and requested action.

  7. 07

    Revoke or renew

    End, suspend, supersede or renew authority as circumstances change.

Follow the full lifecycle

Built for the decision point

Evidence the relying party can actually use.

01

Precise authority

Express actions, limits, resources, jurisdictions, channels, approval conditions and exclusions.

02

Live verification

Evaluate current status and exact scope at the point where an action is requested.

03

Minimum disclosure

Present only the authority evidence the verifier needs for the transaction in front of it.

04

Revocable by design

Suspend, revoke, supersede or renew authority without retrieving paper documents.

05

Auditable evidence

Retain receipts that show the inputs, checks, decision and reason codes at that moment.

06

Issuer-neutral boundaries

Integrate qualified or non-qualified providers according to the actual assurance requirement.

Different actors. Different authority.

One model, shaped around the appointment.

Switch representative types to see the mandate change—not just the label.

Machine action, accountable authority

Let software act without letting scope drift.

Bind an agent to the organisation that appointed it, the action it may perform, the resources it may touch, its limit, expiry and human-control conditions.

Explore this use case
MANDATE EXAMPLEPermitted
Principal
Northstar Components GmbH
Representative
Procurement Agent X
Permitted action
Place purchase order
Resource
Procurement account 17
Limit
€25,000 per order
Condition
Human approval above €20,000

Decision, decomposed

A green tick is not an explanation.

The verifier evaluates integrity, trust, time, status, binding and scope—then returns an explicit result and reason code.

REQUEST TO VERIFY

May Agent X place a purchase order for Organisation Y, using Account Z, for18,500 today?

Credential signatureES256 signature intact
PASS
Trusted issuerIssuer allowed by verifier policy
PASS
Validity periodActive at requested time
PASS
Revocation statusCurrent mandate is valid
PASS
Principal and representativeExact signed binding
PASS
Action and resourcePO · procurement account 17
PASS
Monetary limit€18,500 of €25,000
PASS
Human approval conditionNot required
PASS

Local illustrative decision using example data. It does not inspect a live credential and is not legal advice.

Explore the verifier demo

European wallet context

An authority layer for interoperable business interactions.

The European Digital Identity framework establishes common foundations for digital identity wallets. The proposed European Business Wallet framework extends the conversation towards company identity, secure business interaction and organisational representation.

WhoActs is building an interoperable authority layer for these environments. It is not an EU institution, official wallet, QTSP or certified trust service.

Trust through precision

Every claim has a boundary.

The product distinguishes local sandbox behaviour, implemented connected-mode controls and work still required before production reliance.

Open the trust centre

Signed evidence

ES256 demo credentials; protected production custody required

Current state

Valid, suspended, revoked and superseded mandate handling

Legal boundary

Technical evidence and policy checks—not legal advice

For developers

Ask one explicit question. Get one inspectable answer.

Mandate Rail keeps HTTP translation, authority policy, persistence and providers behind separate typed boundaries. This example mirrors the downloadable illustrative contract; no public endpoint is advertised.

Explore the API
POST /api/v1/verifications
{
  "credential": "...",
  "requestedAction": "place_purchase_order",
  "resource": "procurement-account-17",
  "jurisdiction": "DE",
  "channel": "api",
  "amount": 18500,
  "currency": "EUR"
}

→ 200
{
  "decision": "PERMITTED",
  "reasonCodes": ["AUTHORITY_VERIFIED"],
  "receiptReference": "vrf_8F31"
}

Straight answers

Before you rely on authority evidence, interrogate it.

What is WhoActs?

WhoActs is the public brand for Mandate Rail: infrastructure for defining, issuing, presenting, checking and ending evidence of business authority.

What problem does it solve?

It closes the gap between knowing who someone is and knowing whether they may perform a particular act for an organisation.

How is authority different from identity?

Identity answers who the actor is. Authority answers who appointed them, what they may do, on which resource, within which limits, through which channel and until when.

What is a digital mandate?

A digital mandate is a structured record of an appointment and its policy: principal, representative, actions, resources, limits, jurisdictions, dates, conditions, exclusions and evidence.

Is a mandate a legal power of attorney?

Not automatically. A WhoActs mandate is technical evidence. Legal effect depends on governing documents, applicable law and the transaction.

Read all 35 questions

Authority, explained

Build the category before selling the platform.

01

7 min read · Robert Prime

Identity is not authority: the missing layer in business wallets

Why a verified sign-in still leaves the hardest transaction question unanswered.

Read the article
02

8 min read · Robert Prime

What must an AI agent prove before it acts for a company?

A practical authority checklist for agentic procurement, payments and high-risk account actions.

Read the article
03

6 min read · Robert Prime

From paper mandates to verifiable business authority

How to move from scanned evidence and email approvals to precise, revocable policy decisions.

Read the article
View all insights

Founder-led and accountable

WhoActs is led by Robert Prime.

Website and enquiry operations run through Simon and Prime Ltd, company 13180513. Customer proof will be published only when evidence and permission support it.

Meet Robert

Design-partner programme

Before an action is accepted, know who authorised it.