Company Capability Passport
The Company Capability Passport is a reusable collection of still-valid, scoped capabilities derived from committed RunOnProof decisions. It helps agents avoid repeating work that remains trustworthy for the same purpose.
A helpful analogy
A physical passport does not say a person may do everything. It identifies the holder and contains documents with issuers, dates, and limits. The RunOnProof Passport works similarly: each capability has a subject, source, policy, scope, observation time, validity, conditions, and revocation state.
What can appear in a Passport
Examples include a resolved legal identity, a status claim, a supplier authorization under a named buyer policy, or another capability produced by a completed workflow. Inclusion depends on the source decision and its reuse rules.
What the Passport is not
It is not a universal trust badge, a permanent certificate, a reputation score, a credit score, a substitute for live evidence, or permission for every agent to act. It does not hide uncertainty and does not convert one customer's approval into another customer's policy.
Anatomy of a capability
| Field | Meaning |
|---|---|
| Subject | The exact legal company |
| Capability | The narrow fact or authorization |
| Policy | The rule under which it was produced |
| Jurisdiction | Where the claim applies |
| Evidence references | What supported it |
| Observation and validity | When evidence was read and until when reuse is allowed |
| Conditions | Requirements that remain attached |
| Revocation state | Whether later information has invalidated reuse |
Reuse decision
Before reusing a capability, the planner asks whether the company identity still matches, the policy and purpose are compatible, the evidence is fresh enough, no required source or risk event forces refresh, and the capability has not expired or been revoked.
If any answer is uncertain, the system refreshes the necessary evidence or returns REVIEW. Reuse must be explainable; “Passport says yes” is not enough.
Example
A supplier was approved for Buyer A under policy version 3, for office supplies, until 30 September. A later agent wants to release a high-value construction payment. The Passport can reuse legal identity if still valid, but the supplier authorization does not cover a different buyer, category, policy, or payment action. New evidence and authorization are required.
Relationship to solutions
Solutions create decisions; the Passport preserves reusable capabilities from those decisions. The Passport does not replace Company Check, Supplier Approval, Invoice & Payee Verification, Payment Authorization, or continuous authorization. It reduces unnecessary repeated work while respecting their boundaries.
Expiry and revocation
Capabilities can expire because time passes, policy changes, a source changes, a company changes status, or a later outcome creates a new risk. Revocation should be traceable to a reason and must stop future reuse without rewriting the historical decision.
Safe display
Show each capability separately with its scope and expiry. Avoid one Passport-level green light. A user should be able to tell what remains valid, what needs refresh, and what was never checked.