Skip to main content

Mandaitor Academy

Mandaitor Academy

Learn verifiable authority for agentic systems from first principles.

The Mandaitor Academy is a guided learning layer for users, builders, reviewers, and decision makers. It explains why bounded authority, identity, credentials, mandates, runtime checks, evidence, and governance matter when AI agents can use tools and business systems.

The Mandaitor Academy is not a reference manual. The regular documentation tells you how to integrate the product. The Academy explains why Mandaitor exists, which identity and authorization ideas it builds on, and how those ideas apply when AI agents can act through tools, APIs, workflows, and business systems.

Mandaitor starts from a simple but demanding premise: an agent should not be trusted merely because it can authenticate or because it was instructed in a prompt. It should be able to show bounded, verifiable, auditable authority for the specific action it is about to perform. That premise connects classical access control, decentralized identity, verifiable credentials, agentic AI, runtime policy enforcement, evidence generation, and governance.

The Academy is written for learners who may have no prior background in identity systems, verifiable credentials, authorization models, agentic AI, or compliance evidence. It teaches from first principles and gradually connects those concepts to Mandaitor's platform surfaces.

Guided learning model

Move from first principles to product confidence

The Academy is organized as a learning product: each stage builds a mental model, connects it to a Mandaitor surface, and prepares the learner for a more advanced product or governance decision.

Beginner concepts

Start with authority, not tooling

FoundationsAgentic AIAuthority boundary

Learn why capability and access are not the same as delegated authority, especially when agents can call business tools.

  • Define principal, delegate, verifier, mandate, and evidence.
  • Understand why prompt instructions are not enough for sensitive actions.
Identity path

Add identity and proof

DIDsCredentialsTrust chains

Connect DIDs, credentials, claims, and trust chains to the practical problem of knowing who is acting and why proof should be accepted.

  • Treat agents as identifiable subjects.
  • Separate technical proof validity from business trust decisions.
Authorization architecture

Verify runtime actions

Mandate policiesVerification APIProof-of-Mandate

Translate authority boundaries into policy checks that happen before a tool call, API request, or workflow action executes.

  • Model scopes, constraints, lifecycle states, and escalation paths.
  • Use verification decisions as a control point, not as after-the-fact logging.
Governance + adoption

Review evidence and adopt the product

Evidence packsCompliance dashboardProduct path

Use evidence packs, dashboard signals, and staged product evaluation to improve policy, support reviewers, and plan implementation.

  • Read dashboard signals through their underlying evidence.
  • Move from one bounded use case to a repeatable adoption route.

Choose the route that matches your role

Completely new to all of this? You don't need to choose anything. Take the beginner path — start with Foundations and read the chapters in order; every lesson hands you to the next one.

If you arrive with a specific responsibility — deciding whether Mandaitor is strategically relevant, designing the authority layer, reviewing evidence, or preparing a pilot — pick the one route below that matches it. Each route uses the same chapter library but changes the reading order, the emphasis, and the artifact you end up with.

Strategic evaluation

Founder / Decision-maker

Is verifiable delegated authority strategically important enough to influence product, risk, or go-to-market decisions?

Outcome
A concise authority-boundary narrative that explains why Mandaitor matters for agentic workflows.
Suggested effort
45–70 min
  1. 01
    Foundations of Verifiable DelegationFrame the difference between access, capability, and delegated authority before evaluating product fit.
  2. 02
    Agentic AI from First PrinciplesConnect autonomous tool use to the need for explicit authority boundaries and runtime checks.
  3. 03
    Compliance Dashboard ExplainedUnderstand what executives and reviewers can see when agent actions become inspectable.
  4. 04
    Governance, Risk, and ComplianceTranslate the Mandaitor model into risk, control, and accountability language.
  5. 05
    Capstone Pilot WorkbookComplete the authority-boundary milestone to decide whether a first pilot is worth pursuing.
Artifacts to produce
  • One-sentence pilot thesis
  • Named authority boundary
  • Decision criteria for continuing or pausing evaluation
Start with Foundations
Implementation architecture

Builder / Platform Engineer

How should mandates, policies, verification decisions, and evidence fit into a runtime architecture?

Outcome
A technical route from policy design to evidence-producing authorization checks.
Suggested effort
75–110 min
  1. 01
    Mandate Policies and Policy EnforcementModel principals, delegates, actions, resources, constraints, obligations, and lifecycle states.
  2. 02
    Agentic AuthorizationPlace the verification decision before tool calls, API requests, and workflow actions.
  3. 03
    Trust ChainsSeparate cryptographic validity from local business acceptance and issuer trust.
  4. 04
    Evidence Packs and Audit EventsTurn verification outcomes into reviewable artifacts that support debugging and assurance.
  5. 05
    Capstone Pilot WorkbookComplete the policy and evidence milestones for a bounded implementation scenario.
Artifacts to produce
  • Initial mandate-policy sketch
  • Runtime verification control point
  • Evidence fields required for review
Start with Policies
Oversight and assurance

Reviewer / Compliance Officer

Can I inspect what an agent was allowed to do, why it was allowed, and which evidence supports that decision?

Outcome
A review model for dashboard signals, evidence packs, and governance controls.
Suggested effort
60–95 min
  1. 01
    Compliance Dashboard ExplainedRead review queues, risk signals, and evidence status through the product surface.
  2. 02
    Governance, Risk, and ComplianceMap Mandaitor evidence to control ownership, risk treatment, and compliance review.
  3. 03
    Evidence Packs and Audit EventsUnderstand what evidence should be present before accepting an agentic action as reviewable.
  4. 04
    Product Learning PathSee how review expectations connect to adoption planning and staged product evaluation.
  5. 05
    Capstone Pilot WorkbookComplete the dashboard-review milestone and define the first review gate.
Artifacts to produce
  • Minimum evidence checklist
  • Reviewer questions for policy exceptions
  • Dashboard review gate for the pilot
Start with Dashboard Review
Pilot execution

Implementation Lead / Pilot Team

How do we convert Academy concepts into a bounded first pilot with owners, gates, and readiness criteria?

Outcome
A complete workbook-driven pilot plan that aligns product, engineering, security, and governance stakeholders.
Suggested effort
120–180 min
  1. 01
    Product Learning PathUnderstand the adoption route from product evaluation to a bounded implementation path.
  2. 02
    Foundations of Verifiable DelegationAlign the team on the shared authority model before debating implementation details.
  3. 03
    Mandate Policies and Agentic AuthorizationUse the policy and runtime lessons to scope the pilot workflow and control points.
  4. 04
    Evidence, Dashboard, and Governance LessonsConnect operational evidence to reviewer workflows and executive readiness decisions.
  5. 05
    Capstone Pilot WorkbookComplete the full workbook, pilot checklist, ownership model, and expansion gate.
Artifacts to produce
  • Pilot scope and success criteria
  • Named owners across product, engineering, security, and governance
  • Go / no-go gate for expansion beyond the first workflow
Start with Product Adoption

Track your progress

Lesson progress, track badges, your day streak, and — once all five tracks are complete — a downloadable Academy certificate all live locally in your browser; there is nothing to sign up for. The certificate can optionally be minted as a real verifiable credential.

Local progress

Your Academy progress

Progress is saved locally in this browser. The Academy remains public; signing in later can sync learning state across devices and connect it to product onboarding.

0%
Achievements

Badges, streak, and certificate

Earn a badge by completing every lesson in a track. Your streak counts the days you complete at least one lesson. Finish all five tracks to unlock your Academy certificate. Everything is saved locally — no account required.

0days streak
FoundationsAuthority vs. access, and agentic AI from first principles.0/3 lessons
Identity & ProofDIDs, verifiable credentials, and trust chains.0/3 lessons
AuthorizationMandate policies, runtime authorization, and provider interop.0/4 lessons
GovernanceEvidence packs, the compliance dashboard, and GRC.0/3 lessons
AdoptionProduct path, development status, and the pilot capstone.0/2 lessons
0% of the Academy completeComplete all 5 tracks to unlock your certificate.

Academy versus documentation

The Academy and the documentation are complementary. The Academy explains mental models, background standards, and design trade-offs. The documentation remains the source for step-by-step integration guides, API contracts, SDK usage, identity-provider setup, and operational configuration.

SurfaceBest forExample question
AcademyBuilding conceptual understanding before implementation.Why is Proof-of-Mandate different from a generic API token?
ConceptsReading focused explanations of Mandaitor primitives.What is a mandate, constraint, audit event, or verification decision?
GuidesImplementing a concrete workflow.How do I create a mandate and verify an action?
API ReferenceInspecting exact request and response fields.Which fields does the verification endpoint expect?

How Mandaitor fits into the broader technology landscape

Mandaitor does not invent the whole identity or AI-governance universe. It builds on established and emerging ideas. The W3C Verifiable Credentials Data Model defines a three-party model of issuers, holders, and verifiers for exchanging tamper-evident claims.1 W3C DID Core defines decentralized identifiers that can associate a subject with a DID document containing verification methods and services.2 The Model Context Protocol standardizes how LLM applications connect to tools and external context.3 NIST's AI Risk Management Framework frames AI risk as a socio-technical management discipline rather than a one-time technical checklist.4

Mandaitor's contribution is to bring these ideas into a practical authority layer for agentic systems. It gives teams a way to represent delegated authority, verify whether a proposed action fits that authority, and preserve evidence that can later be inspected by humans, systems, or auditors.

References