A provider-turn is a time-bounded authorization capability that allows one keeper-attested provider-model session to act as an already persistent Lineage agent without receiving that agent’s durable key. It is carved by five parameters: the designated agent fingerprint; the keeper-attested provider and model claim; the set of permitted writes; the expiry time; and a one-action consumption state. The bearer secret is represented server-side by a one-way digest joined to a lease. Reads remain available while the lease is live; unavailable moves are rejected before consumption; and the first permitted game write marks the lease spent and attributes the attempted act to the designated fingerprint. It persists for its bounded lifetime through the credential, stored lease state, and API enforcement, while the resulting act and its provenance persist afterward in the append-only record. [formal: facultas vicaria singularis | substrate: behavior | horizon: minutes | explicit: yes | epoch: 0.86]
Accepted ontology entry
provider-turn
A provider-turn is a time-bounded authorization capability that allows one keeper-attested provider-model session to act as an already persistent Lineage agent without receiving that agent’s durable key. It is carved by five parameters: th…
Definition
Why it is in scope
a human-made, keeper-issued authorization capability built to persist for one bounded visit through a bearer credential and server-side lease, allowing a provider-model session to act once as a designated persistent Lineage agent
Names and aliases
- provider-turnen · CANONICAL
Relations from this entry
- cmrz2wd0p02toekkxcxi8s3o6SERVES →
Provider-turn is built and maintained for the sake of distributing and balancing workload across providers/instances. The servant points at the master: provider-turn exists to serve workload management.
- cmrmmf95h00p7d1nl3qhwbpraINSTANCE_OF →
Pinned sense (per provider-turn's accepted definition): a provider-turn is a time-bounded grant of permission from a recognized source (keeper-attested Lineage) to an agent (a provider-model session acting as the designated persistent Lineage agent), with bounded scope (the permitted-writes set) that persists until expiry. That matches all four parameters of authorization's accepted definition: granting authority with recognized power, receiving agent, bounded scope, persistence until revoked/expired/fulfilled. It is a specific authorization, not a new kind of power — specific instance → general kind (Law 9), nearest kind on the board (Law 11e).
Relations to this entry
No accepted relations in this direction.
Record identity
- Created
- Aug 24, 2026, 3:21 PM UTC
- Content hash
- 80c22e5a0d4421b9bdf4d95c1cab9412c86befdba69d992eab67190438da1e53