VSELFAI task control
HelpDID documentDID

Local-first AI authorization

Let AI operate within clear permissions

VSELF is an AI task authorization, handoff, and review system.

  • One-time authorization works without an account
  • Signing keys are decrypted only on your device; signed-in users can sync end-to-end encrypted records
  • Human approval remains the final authority

Workflow

Choose how you want to start

  1. 1
    Task and evidence

    Gather sources and return a cited summary for approval.

  2. 2
    Copy AI handoff

    Work only within this signed authorization. Return the result and supporting evidence for human review; the authorization is not final approval.

  3. 3
    Review returned work

    Compare the returned work with the signed task and required evidence, then record your decision.

VSELF

Workflow

VSELF is an AI task authorization, handoff, and review system. Define what AI may do, what it must not do, what evidence it must return, and when access expires; then hand off the task through an encrypted link, review the result, revoke authority, and share a record anyone can verify.
01

Set clear limits for one AI task

Define the task, allowed and blocked actions, required evidence, and expiry. Sign it, then share the least-privileged AI link.

Create the first authorization
02

Copy AI handoff

Work only within this signed authorization. Return the result and supporting evidence for human review; the authorization is not final approval.

Create a connection
03

Verify authority and evidence before trusting the result

Check the signature, controller DID, authorized scope, expiry, revocation state, and returned outcome record.

Run verification
04

Stop an authorization at any time

The task room and future checks clearly show that the authorization has stopped.

Revoke authorization

When to use VSELF

See what VSELF adds before an Agent acts

The task may be ordinary. VSELF adds independent, signed limits, evidence requirements, expiry, and human review.

When to use VSELF

Complete example · Research agent

Compare Notion, Obsidian, and Google Docs as a knowledge base for a 10-person team, then recommend one within 24 hours
VSELF · Set clear limits for one AI task

Define the task, allowed and blocked actions, required evidence, and expiry. Sign it, then share the least-privileged AI link.

Agent identity
Research agent
Expires
24 hours
Task
Compare Notion, Obsidian, and Google Docs as a knowledge base for a 10-person team, then recommend one within 24 hours
Expected evidence
Use at least 3 official sources. Include URLs, access times, a feature comparison, and clearly separate facts from recommendations
AI can
Read and researchPrepare draftsReturn evidence
Guardrails
No spendingNo publishingHuman approval required
Result summary
Return a concise comparison table, a recommendation with reasons, and a source list. Do not publish or spend money
  1. 1
    Create AI task

    Compare Notion, Obsidian, and Google Docs as a knowledge base for a 10-person team, then recommend one within 24 hours

  2. 2
    Sign authorization → Copy AI link

    Work only within this signed authorization. Return the result and supporting evidence for human review; the authorization is not final approval.

  3. 3
    Agent view: Accept this task → Submit work for review

    Return a concise comparison table, a recommendation with reasons, and a source list. Do not publish or spend money

  4. 4
    Review returned work

    Compare the returned work with the signed task and required evidence, then record your decision.

VSELF Agent Protocol 1.3

One integration, reusable authorization

The Agent checks its encrypted task channel, verifies each signed grant, then opens only the task room it was authorized to use.
1Sign authorizationSign authorizationAn explicit allowlist for the Agent. Any action that is not selected remains outside the authorization.Read full guidance
2Agent task channelAgent task channelAn encrypted pull endpoint for signed tasks. The Agent must install its credentials and check this endpoint; creating a VSELF connection alone does not make the Agent receive anything.Read full guidance
3Verify authorizationVerify authority and evidence before trusting the resultChecks the signature, controller, service namespace, scope, expiry, required fields, and revocation status. It does not prove that an Agent's factual claims are true.Read full guidance
4Review returned workReview returned workA person accepts or rejects the returned work. VSELF binds that decision, the original authorization, and the evidence into a signed outcome receipt.Read full guidance
Tasks, room capabilities, and delivery keys remain encrypted
Create a connection

What VSELF proves

Signing keys are decrypted only on your device; signed-in users can sync end-to-end encrypted records

Human approval remains the final authority