Skip to content

Concepts

Understand how CapiscIO works under the hood. These docs explain the why and how behind the platform.


Identity & Trust

  • Identity & DIDs


    Decentralized identifiers give your agent a permanent, cryptographically verifiable identity.

    Learn about DIDs

  • Trust Badges


    Cryptographic credentials that attest to your agent's identity verification level (0-4).

    Understanding Badges

  • Trust Levels


    The five-level verification hierarchyβ€”from self-signed to extended validation.

    Trust Levels


Validation & Scoring

  • Validation Process


    How CapiscIO validates agent cards across 7+ categories: schema compliance, security, versioning, and more.

    Learn about Validation

  • Scoring System


    The three-dimensional scoring model: Compliance, Trust, and Availability. What the numbers mean.

    Understanding Scores


Runtime Security

  • Enforcement


    How SimpleGuard enforces security policies on incoming requests. The runtime protection layer.

    Enforcement

  • MCP Security


    RFC-006 (tool authorization) and RFC-007 (server verification) for Model Context Protocol.

    MCP Security


Infrastructure

  • Agent Registry


    The central registry for agent discovery, DID resolution, and badge verification.

    Registry


How It All Fits Together

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                     CapiscIO Architecture                        β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚                                                                  β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”       β”‚
β”‚  β”‚   Identity   β”‚    β”‚    Trust     β”‚    β”‚   Registry   β”‚       β”‚
β”‚  β”‚              β”‚    β”‚              β”‚    β”‚              β”‚       β”‚
β”‚  β”‚  DID + Keys  │───▢│   Badges     │───▢│  Discovery   β”‚       β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜       β”‚
β”‚         β”‚                   β”‚                   β”‚                β”‚
β”‚         β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                β”‚
β”‚                             β”‚                                    β”‚
β”‚                             β–Ό                                    β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚  β”‚                     Validation & Scoring                    β”‚ β”‚
β”‚  β”‚                                                             β”‚ β”‚
β”‚  β”‚  Compliance (0-100)  Γ—  Trust (0-100)  Γ—  Availability     β”‚ β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚                             β”‚                                    β”‚
β”‚                             β–Ό                                    β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚  β”‚                     Runtime Enforcement                     β”‚ β”‚
β”‚  β”‚                                                             β”‚ β”‚
β”‚  β”‚  SimpleGuard β†’ Verify Signatures β†’ Check Trust Level       β”‚ β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚                                                                  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Concept Quick Reference

Concept What It Answers
Validation "Is this agent card correctly formatted?"
Scoring "How good is this agent across compliance, trust, availability?"
Trust Model "How do I manage who my agent trusts?"
Enforcement "How do I protect my agent at runtime?"
MCP Guard "How do I secure MCP tools?"

Specifications (RFCs)

For the formal technical specifications, see the CapiscIO RFCs:

RFC Title Status
RFC-001 Agent Governance Control Plane (AGCP) βœ… Approved
RFC-002 Trust Badge Specification βœ… Approved
RFC-003 Key Ownership Proof Protocol βœ… Approved
RFC-006 MCP Tool Authority Evidence βœ… Approved
RFC-007 MCP Server Identity Discovery βœ… Approved

Browse All RFCs


Next Steps

  • Get Started


    Ready to try it? Jump into the getting started guides.

    Getting Started

  • How-To Guides


    Task-oriented guides for specific problems.

    How-To Guides