The agent, and the federation that vouches for it Live · the same agent, two federation interactions

This is the same accounts payable agent you see in the console, shown here through the federation lens. Run the real payment run to watch the actual delegated authority flow (the one the console runs) as a chain of federation interactions: attestation, delegation, per hop token exchange that only narrows, and role enforced resource calls. Or run a cross estate exchange to watch two authorisation servers resolve trust between them live. Both authorisation servers below are reference implementations standing in for Ping and Entra.

The real supplier payment run, federation interactions, live

This is the exact flow the console runs, and every step is a real federation interaction. Press Run the real payment run.
    and a cross estate federation exchange

    Who am I, and who vouches for me

    entity: https://ap-orchestrator.agents.cba.raidiam.io
    identity plane: CommBiz OP (reference implementation, stands in for Ping)
    resolving who vouches for my OP…

    The flow, live

    • attest the instance key (HAIP)
    • mint the subject token at the CommBiz OP
    • exchange at the Workforce OP (federation resolved)
    • call the protected payments ledger

    The trust decision, resolved live rather than hardcoded

    runs when you press play

    Tokens, subject vs exchanged

    subject (CommBiz OP):
    exchanged (Workforce OP, narrowed):

    Ledger result